• bitcoinBitcoin (BTC) $ 68,648.00
  • ethereumEthereum (ETH) $ 2,105.60
  • tetherTether (USDT) $ 0.999950
  • bnbBNB (BNB) $ 599.74
  • xrpXRP (XRP) $ 1.31
  • usd-coinUSDC (USDC) $ 0.999912
  • solanaSolana (SOL) $ 79.93
  • tronTRON (TRX) $ 0.316197
  • staked-etherLido Staked Ether (STETH) $ 2,265.05
  • figure-helocFigure Heloc (FIGR_HELOC) $ 1.02
  • dogecoinDogecoin (DOGE) $ 0.090675
  • usdsUSDS (USDS) $ 0.999908
  • whitebitWhiteBIT Coin (WBT) $ 51.58
  • leo-tokenLEO Token (LEO) $ 10.11
  • cardanoCardano (ADA) $ 0.243380
  • wrapped-stethWrapped stETH (WSTETH) $ 2,779.67
  • hyperliquidHyperliquid (HYPE) $ 36.25
  • bitcoin-cashBitcoin Cash (BCH) $ 431.34
  • wrapped-bitcoinWrapped Bitcoin (WBTC) $ 76,243.00
  • chainlinkChainlink (LINK) $ 8.78
  • binance-bridged-usdt-bnb-smart-chainBinance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 0.998762
  • moneroMonero (XMR) $ 331.39
  • wrapped-beacon-ethWrapped Beacon ETH (WBETH) $ 2,466.93
  • ethena-usdeEthena USDe (USDE) $ 0.999793
  • canton-networkCanton (CC) $ 0.147555
  • stellarStellar (XLM) $ 0.155773
  • wrapped-eethWrapped eETH (WEETH) $ 2,465.31
  • memecoreMemeCore (M) $ 2.65
  • daiDai (DAI) $ 0.999404
  • susdssUSDS (SUSDS) $ 1.08
  • usd1-wlfiUSD1 (USD1) $ 1.00
  • zcashZcash (ZEC) $ 263.65
  • litecoinLitecoin (LTC) $ 53.36
  • coinbase-wrapped-btcCoinbase Wrapped BTC (CBBTC) $ 76,366.00
  • paypal-usdPayPal USD (PYUSD) $ 1.00
  • hedera-hashgraphHedera (HBAR) $ 0.086733
  • avalanche-2Avalanche (AVAX) $ 8.66
  • wethWETH (WETH) $ 2,268.37
  • suiSui (SUI) $ 0.874448
  • shiba-inuShiba Inu (SHIB) $ 0.000006
  • the-open-networkToncoin (TON) $ 1.23
  • usdt0USDT0 (USDT0) $ 0.998824
  • world-liberty-financialWorld Liberty Financial (WLFI) $ 0.098317
  • rainRain (RAIN) $ 0.006300
  • bittensorBittensor (TAO) $ 311.87
  • crypto-com-chainCronos (CRO) $ 0.069451
  • hashnote-usycCircle USYC (USYC) $ 1.12
  • tether-goldTether Gold (XAUT) $ 4,620.75
  • pax-goldPAX Gold (PAXG) $ 4,633.26
  • ethena-staked-usdeEthena Staked USDe (SUSDE) $ 1.22
  • blackrock-usd-institutional-digital-liquidity-fundBlackRock USD Institutional Digital Liquidity Fund (BUIDL) $ 1.00
  • mantleMantle (MNT) $ 0.653290
  • polkadotPolkadot (DOT) $ 1.24
  • uniswapUniswap (UNI) $ 3.08
  • global-dollarGlobal Dollar (USDG) $ 1.00
  • skySky (SKY) $ 0.076012
  • falcon-financeFalcon USD (USDF) $ 0.997619
  • okbOKB (OKB) $ 82.69
  • pi-networkPi Network (PI) $ 0.169620
  • aster-2Aster (ASTER) $ 0.668742
  • little-pepe-5Little Pepe (LILPEPE) $ 2.16
  • nearNEAR Protocol (NEAR) $ 1.24
  • syrupusdcsyrupUSDC (SYRUPUSDC) $ 1.15
  • htx-daoHTX DAO (HTX) $ 0.000002
  • usddUSDD (USDD) $ 0.999915
  • pepePepe (PEPE) $ 0.000003
  • aaveAave (AAVE) $ 91.79
  • ripple-usdRipple USD (RLUSD) $ 0.999860
  • bfusdBFUSD (BFUSD) $ 0.999499
  • ondo-us-dollar-yieldOndo US Dollar Yield (USDY) $ 1.13
  • bitget-tokenBitget Token (BGB) $ 1.84
  • ethereum-classicEthereum Classic (ETC) $ 8.20
  • internet-computerInternet Computer (ICP) $ 2.31
  • janus-henderson-anemoy-treasury-fundJanus Henderson Anemoy Treasury Fund (JTRSY) $ 1.10
  • ondo-financeOndo (ONDO) $ 0.252790
  • gatechain-tokenGate (GT) $ 6.49
  • kucoin-sharesKuCoin (KCS) $ 8.16
  • quant-networkQuant (QNT) $ 72.21
  • jupiter-perpetuals-liquidity-provider-tokenJupiter Perpetuals Liquidity Provider Token (JLP) $ 4.00
  • superstate-short-duration-us-government-securities-fund-ustbSuperstate Short Duration U.S. Government Securities Fund (USTB) (USTB) $ 11.04
  • algorandAlgorand (ALGO) $ 0.113426
  • pump-funPump.fun (PUMP) $ 0.001708
  • render-tokenRender (RENDER) $ 1.89
  • polygon-ecosystem-tokenPOL (ex-MATIC) (POL) $ 0.090751
  • jito-staked-solJito Staked SOL (JITOSOL) $ 124.46
  • eutblSpiko EU T-Bills Money Market Fund (EUTBL) $ 1.21
  • morphoMorpho (MORPHO) $ 1.60
  • kelp-dao-restaked-ethKelp DAO Restaked ETH (RSETH) $ 2,404.69
  • usdtbUSDtb (USDTB) $ 0.999832
  • kaspaKaspa (KAS) $ 0.031386
  • binance-peg-wethBinance-Peg WETH (WETH) $ 2,262.26
  • cosmosCosmos Hub (ATOM) $ 1.69
  • rocket-pool-ethRocket Pool ETH (RETH) $ 2,631.35
  • nexoNEXO (NEXO) $ 0.846449
  • worldcoin-wldWorldcoin (WLD) $ 0.245233
  • binance-bridged-usdc-bnb-smart-chainBinance Bridged USDC (BNB Smart Chain) (USDC) $ 0.999945
  • ethenaEthena (ENA) $ 0.081086
  • midnight-3Midnight (NIGHT) $ 0.040724
  • wbnbWrapped BNB (WBNB) $ 759.61
  • ousgOUSG (OUSG) $ 114.83
  • ignition-fbtcFunction FBTC (FBTC) $ 76,389.00
  • aptosAptos (APT) $ 0.835656
  • filecoinFilecoin (FIL) $ 0.861661
  • official-trumpOfficial Trump (TRUMP) $ 2.82
  • xdce-crowd-saleXDC Network (XDC) $ 0.031960
  • flare-networksFlare (FLR) $ 0.007359
  • syrupusdtsyrupUSDT (SYRUPUSDT) $ 1.11
  • hash-2Provenance Blockchain (HASH) $ 0.010997
  • yldsYLDS (YLDS) $ 0.999951
  • beldexBeldex (BDX) $ 0.079950
  • binance-staked-solBinance Staked SOL (BNSOL) $ 108.24
  • vechainVeChain (VET) $ 0.007107
  • ghoGHO (GHO) $ 0.999533
  • arbitrumArbitrum (ARB) $ 0.095005
  • justJUST (JST) $ 0.064527
  • jupiter-exchange-solanaJupiter (JUP) $ 0.158628
  • usual-usdUsual USD (USD0) $ 0.996754
  • new-x-ceo-is-backNEW X CEO IS BACK (XFLOKI) $ 0.506041
  • bridged-usdc-polygon-pos-bridgePolygon Bridged USDC (Polygon PoS) (USDC.E) $ 0.999720
  • stable-2​​Stable (STABLE) $ 0.025766
  • solv-btcSolv Protocol BTC (SOLVBTC) $ 76,461.00
  • fetch-aiArtificial Superintelligence Alliance (FET) $ 0.232527
  • lombard-staked-btcLombard Staked BTC (LBTC) $ 76,491.00
  • bonkBonk (BONK) $ 0.000006
  • true-usdTrueUSD (TUSD) $ 0.999195
  • a7a5A7A5 (A7A5) $ 0.012370
  • clbtcclBTC (CLBTC) $ 76,920.00
  • pancakeswap-tokenPancakeSwap (CAKE) $ 1.42
  • layerzeroLayerZero (ZRO) $ 1.78
  • siren-2Siren (SIREN) $ 0.599709
  • euro-coinEURC (EURC) $ 1.16
  • virtual-protocolVirtuals Protocol (VIRTUAL) $ 0.632221
  • dexeDeXe (DEXE) $ 8.76
  • stakewise-v3-osethStakeWise Staked ETH (OSETH) $ 2,419.84
  • blockstackStacks (STX) $ 0.216293
  • janus-henderson-anemoy-aaa-clo-fundJanus Henderson Anemoy AAA CLO Fund (JAAA) $ 1.03
  • kinetic-staked-hypeKinetiq Staked HYPE (KHYPE) $ 33.97
  • tbtctBTC (TBTC) $ 70,942.00
  • pudgy-penguinsPudgy Penguins (PENGU) $ 0.006310
  • first-digital-usdFirst Digital USD (FDUSD) $ 0.999580
  • wrappedm-by-m0WrappedM by M0 (WM) $ 1.00
  • chilizChiliz (CHZ) $ 0.037694
  • dashDash (DASH) $ 30.48
  • tezosTezos (XTZ) $ 0.342224
  • hastra-primePRIME (PRIME) $ 1.04
  • adi-tokenADI (ADI) $ 4.48
  • c8ntinuumc8ntinuum (CTM) $ 0.087592
  • kinesis-goldKinesis Gold (KAU) $ 149.60
  • usxUSX (USX) $ 0.999981
  • mantle-staked-etherMantle Staked Ether (METH) $ 2,455.82
  • sei-networkSei (SEI) $ 0.052675
  • ether-fiEther.fi (ETHFI) $ 0.443210
  • polygon-pos-bridged-dai-polygon-posPolygon PoS Bridged DAI (Polygon POS) (DAI) $ 0.999983
  • decredDecred (DCR) $ 19.84
  • resolv-wstusrResolv wstUSR (WSTUSR) $ 1.13
  • edgexedgeX (EDGE) $ 0.963795
  • cocaCOCA (COCA) $ 1.30
  • sun-tokenSun Token (SUN) $ 0.017311
  • apenftAINFT (NFT) $ 0.00000033
  • doge-strategyDoge Strategy (DOGESTR) $ 0.288297
  • liquid-staked-ethereumLiquid Staked ETH (LSETH) $ 2,406.26
  • bitcoin-svBitcoin SV (BSV) $ 15.95
  • arbitrum-bridged-wbtc-arbitrum-oneArbitrum Bridged WBTC (Arbitrum One) (WBTC) $ 76,200.00
  • gnosisGnosis (GNO) $ 120.41
  • curve-dao-tokenCurve DAO (CRV) $ 0.208703
  • bittorrentBitTorrent (BTT) $ 0.00000031
  • venice-tokenVenice Token (VVV) $ 6.76
  • wrapped-flareWrapped Flare (WFLR) $ 0.009961
  • doublezeroDoubleZero (2Z) $ 0.086803
  • monadMonad (MON) $ 0.027123
  • l2-standard-bridged-weth-baseL2 Standard Bridged WETH (Base) (WETH) $ 2,266.86
  • aerodrome-financeAerodrome Finance (AERO) $ 0.313434
  • steakhouse-usdc-morpho-vaultSteakhouse USDC Morpho Vault (STEAKUSDC) $ 1.12
  • injective-protocolInjective (INJ) $ 2.87
  • plasmaPlasma (XPL) $ 0.120710
  • kite-2Kite (KITE) $ 0.152928
  • kaiaKaia (KAIA) $ 0.046969
  • fraxLegacy Frax Dollar (FRAX) $ 0.994134
  • binance-peg-xrpBinance-Peg XRP (XRP) $ 1.59
  • official-foOfficial FO (FO) $ 0.268923
  • ether-fi-liquid-ethEther.Fi Liquid ETH (LIQUIDETH) $ 2,443.47
  • kinesis-silverKinesis Silver (KAG) $ 70.87
  • renzo-restaked-ethRenzo Restaked ETH (EZETH) $ 2,421.84
  • lighterLighter (LIT) $ 1.07
  • spx6900SPX6900 (SPX) $ 0.285394
  • noonNoon (NOON) $ 0.751949
  • sbtc-2sBTC (SBTC) $ 77,039.00
  • crvusdcrvUSD (CRVUSD) $ 0.999312
  • lido-daoLido DAO (LDO) $ 0.311661
  • conflux-tokenConflux (CFX) $ 0.050000
  • jupiter-staked-solJupiter Staked SOL (JUPSOL) $ 115.56
  • celestiaCelestia (TIA) $ 0.288190
  • savings-usddSavings USDD (SUSDD) $ 1.03
  • flokiFLOKI (FLOKI) $ 0.000027
  • jasmycoinJasmyCoin (JASMY) $ 0.005156
  • the-graphThe Graph (GRT) $ 0.023681
  • msolMarinade Staked SOL (MSOL) $ 133.18
  • syrupMaple Finance (SYRUP) $ 0.218282
  • arbitrum-bridged-weth-arbitrum-oneArbitrum Bridged WETH (Arbitrum One) (WETH) $ 2,265.06
  • ape-and-pepeApe and Pepe (APEPE) $ 0.000001

Ransomware Hackers Targeting Employee Monitoring Software To Access Computers

0 2


A popular workforce monitoring tool is being targeted by hackers and used as a foothold for ransomware attacks, according to a new report from cybersecurity firm Huntress.

In late January and early February 2026, Huntress’ Tactical Response team investigated two break-ins in which attackers combined Net Monitor for Employees Professional with SimpleHelp, a remote access tool used by IT departments.

TL;DR 📌 Cybercriminals turned employee monitoring software into a RAT, paired it with SimpleHelp, hunted crypto, and tried to drop Crazy ransomware.

The ethical badasses behind this write-up: @RussianPanda9xx, @sudo_Rem, @Purp1eW0lf, + @Antonlovesdnb

— Huntress (@HuntressLabs) February 13, 2026

According to the report, the hackers used the employee monitoring software to get into company systems and SimpleHelp to make sure they could stay there even if one access point was shut down. The activity eventually led to an attempted deployment of Crazy ransomware.

“These cases highlight a growing trend of threat actors leveraging legitimate, commercially available software to blend into enterprise environments,” Huntress researchers wrote.

“Net Monitor for Employees Professional, while marketed as a workforce monitoring tool, provides capabilities that rival traditional remote access trojans: reverse connections over common ports, process and service name masquerading, built-in shell execution, and the ability to silently deploy via standard Windows installation mechanisms. When paired with SimpleHelp as a secondary access channel … the result is a resilient, dual-tool foothold that is difficult to distinguish from legitimate administrative software.”

The company added that while the tools may be novel, the root cause remains exposed perimeters and weak identity hygiene, including compromised VPN accounts.

The rise of “bossware”

Use of so-called “bossware” varies globally but is widespread. Around a third of UK firms use employee monitoring software, according to a report last year, while in the U.S. the figure is estimated at roughly 60%.

The software is commonly deployed to track productivity, log activity and capture screenshots of workers’ screens. But its use is controversial, as are claims about whether it truly captures employee productivity or instead assesses based on arbitrary criteria such as mouse clicks or emails sent.

Nevertheless, their popularity makes such tools an attractive vector for attackers. Net Monitor for Employees Professional, developed by NetworkLookout, is marketed for employee productivity tracking but offers capabilities beyond passive screen monitoring, including reverse shell connections, remote desktop control, file management and the ability to customize service and process names during installation.

Those features, designed for legitimate administrative use, can allow threat actors to blend into enterprise environments without deploying traditional malware.

In the first case detailed by Huntress, investigators were alerted by suspicious account manipulation on a host, including efforts to disable the system Guest account and enable the built-in Administrator account. Multiple “net” commands were executed to enumerate users, reset passwords and create additional accounts.

Analysts traced the activity to a binary tied to Net Monitor for Employees, which had spawned a pseudo-terminal application allowing command execution. The tool pulled down a SimpleHelp binary from an external IP address, after which the attacker attempted to tamper with Windows Defender and deploy multiple versions of Crazy ransomware, part of the VoidCrypt family.

In the second intrusion, observed in early February, the attackers gained entry through a compromised vendor’s SSL VPN account and connected via Remote Desktop Protocol to a domain controller. From there, they installed the Net Monitor agent directly from the vendor’s website. The attackers customized service and process names to mimic legitimate Windows components, disguising the service as OneDrive-related and renaming the running process.

They then installed SimpleHelp as an additional persistent channel and configured keyword-based monitoring triggers targeting cryptocurrency wallets, exchanges and payment platforms, as well as other remote access tools. Huntress said the activity showed clear signs of financial motivation and deliberate defense evasion.

Network LookOut, the company behind Net Monitor for Employee, told Decrypt the agent can be installed only by a user who already has administrative privileges on the computer where the agent is to be installed. “Without administrative privileges, installation isn’t possible,” it said via email.

“So, if you don’t want our software installed on a computer, please ensure that administrative access is not granted to unauthorized users, since Administrative access allows installation of any software.”

It’s not the first time hackers have attempted to deploy ransomware or steal information via bossware. In April 2025, researchers revealed that WorkComposer, a workplace surveillance app used by more than 200,000 people, had left more than 21 million real-time screenshots exposed in an unsecured cloud storage bucket, potentially leaking sensitive business data, credentials and internal communications.



Source link

Leave A Reply

Your email address will not be published.