
VENOMOUS#HELPER Phishing Campaign Targets 80+ U.S. Organizations Using RMM Tools
PhishingCybersecurityRemote AccessThreat CampaignsRMMSimpleHelpScreenConnectVENOMOUS#HELPER
An active phishing campaign, tracked as VENOMOUS#HELPER, has targeted over 80 organizations primarily in the U.S. since at least April 2025, leveraging legitimate Remote Monitoring and Management (RMM) tools—SimpleHelp and ScreenConnect—to gain persistent remote access to compromised systems. The attack exploits these tools to maintain unauthorized control over affected hosts. No specific CVE IDs or additional technical indicators were disclosed in the reported findings. The campaign overlaps with previously identified threat clusters, though further attribution details were not provided.