Executive Summary
Since at least April 2025, the threat cluster STAC6405 (also known as VENOMOUS#HELPER) has targeted over 80 organizations, primarily in the United States. The campaign leverages a sophisticated Social Security Administration (SSA) impersonation lure to trick victims into downloading a JWrapper-packaged executable. This initial payload deploys a dual-channel remote access architecture using two independent Remote Monitoring and Management (RMM) tools: a self-hosted SimpleHelp instance and a ConnectWise ScreenConnect relay.
Technically, the campaign is notable for its high degree of operational redundancy and evasion. By utilizing legitimately signed vendor software, the attackers bypass traditional signature-based security controls. The malware establishes persistence as a Windows service capable of surviving Safe Mode reboots and features an automated surveillance loop that monitors security software and user presence every 15-67 seconds. Securonix assesses this activity as likely being the work of a financially motivated Initial Access Broker (IAB) or a precursor to ransomware operations targeting Western infrastructure.
