Hackers are targeting vulnerable SimpleHelp RMM clients to create administrator accounts, drop backdoors, and potentially lay the groundwork for ransomware attacks. The flaws are tracked as CVE-2024-57726, CVE-2024-57727, and CVE-2024-57728 and were reported as potentially actively exploited by Arctic Wolf last week. However, the cybersecurity firm could not confirm for sure if the flaws were used. Cybersecurity firm Field Effect has confirmed to BleepingComputer that the flaws are being exploited in recent attacks and released a report that sheds light on the post-exploitation activity. Additionally, the cybersecurity researchers mention that the observed activity has signs of Akira ransomware attacks, though they do not hold enough evidence to make a high-confidence attribution. The attack started with the threat actors exploiting the vulnerabilities in the SimpleHelp RMM client to establish an unauthorized connection to a target endpoint. The attackers connected from the IP 194.76.227[.]171, an Estonian-based server running a SimpleHelp instance on port 80. Once connected via RMM, the attackers quickly executed a series of discovery commands to learn more about the target environment, including system and network details, users and privileges, scheduled tasks and services, and domain controller information. Field Effect also observed a command that searched for the CrowdStrike Falcon security suite, likely a bypass attempt bypass. Leveraging their access and knowledge, th...
Hackers exploit SimpleHelp RMM flaws to deploy Sliver malware
BleepingComputer
·Bill Toulas
·Published Feb 6, 2025
·Updated
Affected Software
2 affected components
SimpleHelp RMM client
SimpleHelp RMM
Frequently Asked Questions
1
What vulnerabilities are being exploited in the SimpleHelp RMM software?
The vulnerabilities exploited are tracked as CVE-2024-57726, CVE-2024-57727, and related issues.
2
What type of malware are hackers deploying through these vulnerabilities?
Hackers are deploying Sliver malware to take control of affected systems.
3
What security risks do the vulnerabilities in SimpleHelp RMM pose?
The vulnerabilities allow attackers to create administrator accounts, deploy backdoors, and set the stage for potential ransomware attacks.
4
Who is affected by the SimpleHelp RMM flaws?
The affected parties are users of the SimpleHelp RMM client and its associated software.
5
What should users of SimpleHelp RMM do to protect themselves?
Users should update their software to the latest version to mitigate these vulnerabilities.