• News/
  • https://www.bleepingcomputer.com/news/security/simplehelp-rmm-flaws-exploited-to-breach-corporate-networks/

SimpleHelp RMM flaws exploited to breach corporate networks

BleepingComputer
·
Bill Toulas
·
Published Feb 6, 2025
·
Updated

Hackers are targeting vulnerable SimpleHelp RMM clients to create administrator accounts, drop backdoors, and potentially lay the groundwork for ransomware attacks. The flaws are tracked as CVE-2024-57726, CVE-2024-57727, and CVE-2024-57728 and were reported as potentially actively exploited by Arctic Wolf last week. However, the cybersecurity firm could not confirm for sure if the flaws were used. Cybersecurity firm Field Effect has confirmed to BleepingComputer that the flaws are being exploited in recent attacks and released a report that sheds light on the post-exploitation activity. Additionally, the cybersecurity researchers mention that the observed activity has signs of Akira ransomware attacks, though they do not hold enough evidence to make a high-confidence attribution. The attack started with the threat actors exploiting the vulnerabilities in the SimpleHelp RMM client to establish an unauthorized connection to a target endpoint. The attackers connected from the IP 194.76.227[.]171, an Estonian-based server running a SimpleHelp instance on port 80. Once connected via RMM, the attackers quickly executed a series of discovery commands to learn more about the target environment, including system and network details, users and privileges, scheduled tasks and services, and domain controller information. Field Effect also observed a command that searched for the CrowdStrike Falcon security suite, likely a bypass attempt bypass. Leveraging their access and knowledge, th...

Read full article

Affected Software

2 affected components
SimpleHelp RMM
SimpleHelp RMM
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What vulnerabilities are reported in the article?

The article reports vulnerabilities tracked as CVE-2024-57726, CVE-2024-57727, and CVE-2024-57728 in SimpleHelp RMM.

2

How are hackers exploiting these vulnerabilities?

Hackers are exploiting these vulnerabilities to create administrator accounts and drop backdoors into corporate networks.

3

What are the potential consequences of these exploits?

The consequences include the potential for ransomware attacks and unauthorized access to sensitive information.

4

Which product is specifically mentioned as being affected?

The affected product mentioned is SimpleHelp RMM.

5

What type of organizations are at risk according to the article?

Organizations using vulnerable SimpleHelp RMM clients are at risk of being breached.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203
SimpleHelp RMM flaws exploited to breach corporate networks - SecAlerts