Hackers are targeting vulnerable SimpleHelp RMM clients to create administrator accounts, drop backdoors, and potentially lay the groundwork for ransomware attacks. The flaws are tracked as CVE-2024-57726, CVE-2024-57727, and CVE-2024-57728 and were reported as potentially actively exploited by Arctic Wolf last week. However, the cybersecurity firm could not confirm for sure if the flaws were used. Cybersecurity firm Field Effect has confirmed to BleepingComputer that the flaws are being exploited in recent attacks and released a report that sheds light on the post-exploitation activity. Additionally, the cybersecurity researchers mention that the observed activity has signs of Akira ransomware attacks, though they do not hold enough evidence to make a high-confidence attribution. The attack started with the threat actors exploiting the vulnerabilities in the SimpleHelp RMM client to establish an unauthorized connection to a target endpoint. The attackers connected from the IP 194.76.227[.]171, an Estonian-based server running a SimpleHelp instance on port 80. Once connected via RMM, the attackers quickly executed a series of discovery commands to learn more about the target environment, including system and network details, users and privileges, scheduled tasks and services, and domain controller information. Field Effect also observed a command that searched for the CrowdStrike Falcon security suite, likely a bypass attempt bypass. Leveraging their access and knowledge, th...
SimpleHelp RMM flaws exploited to breach corporate networks
BleepingComputer
·Bill Toulas
·Published Feb 6, 2025
·Updated
Affected Software
2 affected components
SimpleHelp RMM
SimpleHelp RMM
Frequently Asked Questions
1
What vulnerabilities are reported in the article?
The article reports vulnerabilities tracked as CVE-2024-57726, CVE-2024-57727, and CVE-2024-57728 in SimpleHelp RMM.
2
How are hackers exploiting these vulnerabilities?
Hackers are exploiting these vulnerabilities to create administrator accounts and drop backdoors into corporate networks.
3
What are the potential consequences of these exploits?
The consequences include the potential for ransomware attacks and unauthorized access to sensitive information.
4
Which product is specifically mentioned as being affected?
The affected product mentioned is SimpleHelp RMM.
5
What type of organizations are at risk according to the article?
Organizations using vulnerable SimpleHelp RMM clients are at risk of being breached.