The DragonForce ransomware operation successfully breached a managed service provider and used its SimpleHelp remote monitoring and management (RMM) platform to steal data and deploy encryptors on downstream customers' systems. Sophos was brought in to investigate the attack and believe the threat actors exploited a chain of older SimpleHelp vulnerabilities tracked as CVE-2024-57727, CVE-2024-57728, and CVE-2024-57726 to breach the system. SimpleHelp is a commercial remote support and access tool commonly used by MSPs to manage systems and deploy software across customer networks. The report by Sophos says that the threat actors first used SimpleHelp to perform reconnaissance on customer systems, such as collecting information about the MSP's customers, including device names and configuration, users, and network connections. The threat actors then attempted to steal data and deploy decryptors on customer networks, which were blocked on one of the networks using Sophos endpoint protection. However, the other customers were not so lucky, with devices encrypted and data stolen for double-extortion attacks. Sophos has shared IOCs related to this attack to help organizations better defend their networks. MSPs have long been a valuable target for ransomware gangs, as a single breach can lead to attacks on multiple companies. Some ransomware affiliates have specialized in tools commonly used by MSPs, such as SimpleHelp, ConnectWise ScreenConnect, and Kaseya. This has led to devast...
DragonForce ransomware abuses MSP’s SimpleHelp RMM to encrypt customers
BleepingComputer
·Lawrence Abrams
·Published May 27, 2025
·Updated
Affected Software
1 affected component
SimpleHelp SimpleHelp Remote Monitoring and Management Platform
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses the DragonForce ransomware exploiting the SimpleHelp RMM platform to attack managed service providers and their customers.
2
What security implications are discussed?
The implications include significant data breaches and the potential for widespread encryption of customer systems through compromised remote management tools.
3
What products or software are affected?
The SimpleHelp Remote Monitoring and Management platform is specifically mentioned as being exploited by the ransomware.
4
Who is targeted by the DragonForce ransomware attack?
The attack primarily targets managed service providers and their downstream customers.
5
How does the DragonForce ransomware operate within the SimpleHelp platform?
The ransomware breaches the managed service provider and uses the SimpleHelp platform to deploy encryption tools on clients' systems.