The DragonForce ransomware operation successfully breached a managed service provider and used its SimpleHelp remote monitoring and management (RMM) platform to steal data and deploy encryptors on downstream customers' systems. Sophos was brought in to investigate the attack and believe the threat actors exploited a chain of older SimpleHelp vulnerabilities tracked as CVE-2024-57727, CVE-2024-57728, and CVE-2024-57726 to breach the system. SimpleHelp is a commercial remote support and access tool commonly used by MSPs to manage systems and deploy software across customer networks. The report by Sophos says that the threat actors first used SimpleHelp to perform reconnaissance on customer systems, such as collecting information about the MSP's customers, including device names and configuration, users, and network connections. The threat actors then attempted to steal data and deploy decryptors on customer networks, which were blocked on one of the networks using Sophos endpoint protection. However, the other customers were not so lucky, with devices encrypted and data stolen for double-extortion attacks. Sophos has shared IOCs related to this attack to help organizations better defend their networks. MSPs have long been a valuable target for ransomware gangs, as a single breach can lead to attacks on multiple companies. Some ransomware affiliates have specialized in tools commonly used by MSPs, such as SimpleHelp, ConnectWise ScreenConnect, and Kaseya. This has led to devast...
DragonForce ransomware abuses SimpleHelp in MSP supply chain attack
BleepingComputer
·Lawrence Abrams
·Published May 27, 2025
·Updated
Affected Software
1 affected component
SimpleHelp
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses the DragonForce ransomware operation breaching a managed service provider using SimpleHelp remote management software.
2
What security implications are discussed in relation to DragonForce ransomware?
The article highlights the significant threat posed by ransomware using legitimate remote management tools to target downstream customers of managed service providers.
3
What products or software are affected by the DragonForce ransomware attack?
The SimpleHelp software used in the managed service provider was directly affected by the DragonForce ransomware attack.
4
How did DragonForce leverage SimpleHelp in their attack?
DragonForce exploited the SimpleHelp platform to steal data and deploy ransomware on clients' systems.
5
Who were the targets of the DragonForce ransomware operation?
The targets were downstream customers of the breached managed service provider that utilized the SimpleHelp platform.