VENOMOUS#HELPER Dual-RMM Phishing Campaign Analysis
Score: 10/10

VENOMOUS#HELPER Dual-RMM Phishing Campaign Analysis

The threat actor STAC6405 is conducting an ongoing phishing campaign targeting U.S. organizations with a dual-RMM architecture using SimpleHelp and ScreenConnect for persistent, silent access.

Executive Summary

Since at least April 2025, the threat cluster STAC6405 (also known as VENOMOUS#HELPER) has targeted over 80 organizations, primarily in the United States. The campaign leverages a sophisticated Social Security Administration (SSA) impersonation lure to trick victims into downloading a JWrapper-packaged executable. This initial payload deploys a dual-channel remote access architecture using two independent Remote Monitoring and Management (RMM) tools: a self-hosted SimpleHelp instance and a ConnectWise ScreenConnect relay.

Technically, the campaign is notable for its high degree of operational redundancy and evasion. By utilizing legitimately signed vendor software, the attackers bypass traditional signature-based security controls. The malware establishes persistence as a Windows service capable of surviving Safe Mode reboots and features an automated surveillance loop that monitors security software and user presence every 15-67 seconds. Securonix assesses this activity as likely being the work of a financially motivated Initial Access Broker (IAB) or a precursor to ransomware operations targeting Western infrastructure.

Key Details

Threat Name

VENOMOUS#HELPER (STAC6405)

Affects

—

Adversary

STAC6405

Malware/Tools

SimpleHelp, ScreenConnect, JWrapper

Report Score

10out of 10
Quality Score
Excellent
IOC Quality10
TTP Details10
Detection Guidance9
Enterprise Relevance9
Clarity & Structure10
Technical Depth10

Sources