Cyber Security News

Hackers Exploit SimpleHelp RMM Tool to Deploy DragonForce Ransomware

Cybercriminals leveraged critical vulnerabilities in remote monitoring software to breach a managed service provider and attack multiple customers.

Cybersecurity researchers at Sophos have revealed details of a sophisticated attack where threat actors exploited vulnerabilities in SimpleHelp remote monitoring and management (RMM) software to deploy DragonForce ransomware across multiple organizations through a managed service provider (MSP).

The attack represents a significant supply chain compromise, where hackers gained access to an MSP’s SimpleHelp RMM platform and used it as a launching pad to target the provider’s downstream customers.

Sophos MDR investigators believe the attackers exploited a chain of three critical vulnerabilities disclosed in January 2025: CVE-2024-57727 (multiple path traversal vulnerabilities), CVE-2024-57728 (arbitrary file upload vulnerability), and CVE-2024-57726 (privilege escalation vulnerability).

“The attacker also used their access through the MSP’s RMM instance to gather information on multiple customer estates managed by the MSP, including collecting device names and configuration, users, and network connections,” according to the Sophos investigation.

DragonForce Emerges as Major Threat

DragonForce ransomware has rapidly evolved since its emergence in mid-2023, transforming from a traditional ransomware-as-a-service (RaaS) operation into what the group calls a “cartel” model.

This new approach allows affiliates to create their own brands while leveraging DragonForce‘s infrastructure and tools, making it more attractive to a broader range of cybercriminals.

The group gained significant notoriety in recent months for claiming responsibility for attacks against major UK retailers, including Marks & Spencer, Co-op, and Harrods.

Security researchers believe these high-profile attacks involved collaboration with Scattered Spider, a sophisticated threat group formerly associated with RansomHub ransomware operations.

In the MSP incident, Sophos MDR was first alerted when suspicious SimpleHelp installer files were detected being pushed through the legitimate RMM platform.

The attackers conducted extensive reconnaissance, gathering detailed information about the MSP’s customer environments before deploying their ransomware payload.

One customer protected by Sophos XDR endpoint protection successfully blocked the ransomware deployment, demonstrating the effectiveness of advanced endpoint detection and response capabilities.

However, other MSP clients without adequate protection fell victim to both data encryption and exfiltration in a double-extortion scheme designed to maximize pressure on victims to pay ransoms.

Vulnerabilities Enable Remote Compromise

The SimpleHelp vulnerabilities exploited in this attack are particularly dangerous because they can be chained together for complete system compromise.

  • CVE-2024-57727 allows unauthenticated attackers to download arbitrary files from SimpleHelp hosts, including server configuration files containing secrets and hashed passwords.
  • CVE-2024-57726 enables low-privilege technicians to escalate to administrator roles with excessive permissions.
  • CVE-2024-57728 permits authenticated administrators to upload malicious files anywhere on the system, potentially leading to remote code execution.

The US Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2024-57727 to its Known Exploited Vulnerabilities Catalog, acknowledging active exploitation and requiring federal agencies to patch by March 6, 2025.

MSPs represent attractive targets for ransomware operators because compromising a single provider can provide access to dozens or hundreds of customer networks.

Organizations using SimpleHelp are strongly advised to upgrade to version 5.5.8 or apply available patches, change administrator passwords, and implement IP address restrictions for remote access.

Security experts emphasize the importance of robust endpoint protection and managed detection and response services, particularly for MSPs whose compromise can have cascading effects across multiple organizations.

Try in-depth sandbox malware analysis for your SOC team. Get ANY.RUN special offer only until May 31 -> Try Here

Kaaviya

Kaaviya is a Security Editor and fellow reporter with Cyber Security News. She is covering various cyber security incidents happening in the Cyber Space.

Recent Posts

Microsoft Releases Emergency Windows 11 Update Following Patch Tuesday Bugs

Microsoft has pushed out an emergency, out-of-band Windows 11 update after its September Patch Tuesday…

53 seconds ago

Top 10 Best Cloud Detection & Response (CDR) Solutions in 2026

CDR is the runtime, real-time half of cloud security: while CSPM tells you what’s misconfigured,…

5 minutes ago

Top 10 Best SaaS Security Posture Management (SSPM) Tools in 2026

Your SaaS estate M365, Salesforce, Workday, Slack, hundreds of others is a sprawl of misconfigurations,…

11 minutes ago

Top 10 Best Data Security Posture Management (DSPM) Tools in 2026

DSPM finds sensitive data you didn’t know you had, classifies it, maps who can reach…

17 minutes ago

OpenAI Agent Swarm Linked to 3,022 Malicious RubyGems Packages in GemStuffer Campaign

Open-source packages are meant to save developers time. In the GemStuffer campaign, that trust became…

28 minutes ago

Google Chrome 153 Update Fixes 42 Security Flaws, Including 3 Critical Ones

Google has released an important Chrome 153 security update that fixes 42 vulnerabilities across the…

5 hours ago