Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
phishing-campaign-intelligenceinitial-access-methodremote-access-implantcredential-stealer-activity

Invitation-Themed Phishing Installs Legitimate RMM Tools for Persistent Access

Updated 29d agoFirst seen May 23, 20263 sources

Sophos X-Ops reported that a phishing campaign tracked as STAC6405 used invitation-themed lures to trick targets into installing legitimate remote monitoring and management tools, including LogMeIn Resolve and ScreenConnect, giving attackers unattended remote access. The activity was first observed in April 2025, peaked in October and November 2025, and affected more than 80 organizations, primarily in the United States. Sophos said some phishing links were still active at the time of reporting, indicating the campaign may still be ongoing.

In most intrusions, the attackers stopped after establishing remote access, suggesting the operation may support initial access brokerage or maintain dormant persistence for later use. In two cases, however, the compromise advanced to second-stage activity: one intrusion deployed a HeartCrypt-packed infostealer that hid the mouse cursor, injected into csc.exe, contacted 45[.]56.162.138, and stole browser, wallet, and system data; another used a ScreenConnect-based payload bundled with Java components and a likely SimpleHelp-related remote access binary to obtain interactive access before defenders contained the incident.

Share:
Invitation-Themed Phishing Installs Legitimate RMM Tools for Persistent Access
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

5 events from the most recent confirmed update back to the earliest known activity.

5 EVENTS
Mar 30, 20263mo ago

Sophos reports campaign remains potentially ongoing

At the time of Sophos reporting, some phishing links tied to STAC6405 were still active, indicating the campaign may still have been ongoing. In most observed cases, the attackers stopped after establishing remote access, suggesting possible initial access brokerage or dormant persistence.

Oct 1, 20259mo ago

STAC6405 campaign reaches peak activity

The phishing campaign was most active during October and November 2025. Sophos said the activity ultimately affected more than 80 organizations, primarily in the United States.

Apr 1, 20251y ago

Another intrusion uses ScreenConnect-based payload for interactive access

In a separate incident, the attackers used a ScreenConnect-based payload bundled with Java components and a likely SimpleHelp-related remote access binary to gain interactive access. The customer contained the intrusion before further activity was described.

Attackers deploy HeartCrypt-packed infostealer in one follow-on intrusion

In one incident following initial remote access, the attackers quickly moved to second-stage activity by deploying a HeartCrypt-packed infostealer. The malware hid the mouse cursor, injected into csc.exe, contacted 45.56.162.138, and stole browser, wallet, and system data.

STAC6405 phishing campaign first observed

Sophos X-Ops first saw evidence of the invitation-themed phishing campaign tracked as STAC6405 in April 2025. The lures were used to trick targets into installing legitimate remote monitoring and management tools for attacker-controlled unattended access.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

17 LINKEDOpen in app
Threat actors
1 linked
Affected products
5 linked
SimplehelpWindowsScreenconnectAndroidJava Runtime Environment
Organizations
8 linked
AvastRed CanaryConnectwiseMicrosoft CorporationSimpleHelpLogmeinSophosPunchbowl
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.