• News/
  • https://www.theregister.com/2025/05/28/dragonforce_ransomware_gang_sets_fire/

DragonForce used MSP's RMM software to distribute ransomware

The Register
·
Jessica Lyons
·
Published May 28, 2025
·
Updated

Updated DragonForce ransomware infected a managed service provider, and its customers, after attackers exploited security flaws in remote monitoring and management tool SimpleHelp. In addition to deploying DragonForce ransomware across "multiple" endpoints, the criminals also stole sensitive data and used double-extortion tactics to pressure victims into paying the ransom, according to security shop Sophos. The company’s researchers didn't identify the managed service provider (MSP) nor how many customers were affected. We've asked both Sophos and SimpleHelp for more details and will update this article if we hear back. DragonForce is a new-ish ransomware-as-a-service gang that gained notoriety in April after cybercrime “cartel” Scattered Spider used its ransomware to infect major retailers in the UK and US, then began offering a service that allows other crooks to use DragonForce's infrastructure and tools to deploy any type of ransomware. MSPs are always a hot target for criminals because they offer a one-to-many attack: infecting a single MSP creates the chance to gain access to all of its customers' networks. In this case, exploiting SimpleHelp's software provides an even bigger bang for the buck - it's a legitimate remote monitoring and management (RMM) product that has thousands of customers, theoretically allowing the crooks to push the malware to multiple IT environments as if it were a legit software update. When DragonForce exploited SimpleHelp's vulnerabilities, th...

Read full article

Affected Software

2 affected components
SimpleHelp=5.5.7
SimpleHelp
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses the DragonForce ransomware gang exploiting vulnerabilities in SimpleHelp RMM software to infect a managed service provider and its clients.

2

What security implications are discussed in the article?

The article highlights the risks associated with security flaws in remote monitoring and management tools, which can lead to widespread ransomware infections.

3

What products or software are affected by the DragonForce ransomware attack?

The affected software mentioned in the article is SimpleHelp, specifically version 5.5.7.

4

How did the DragonForce ransomware gain access to the systems?

The ransomware was able to spread after attackers exploited security vulnerabilities in the SimpleHelp RMM software.

5

What actions should organizations take in response to this incident?

Organizations should prioritize updating and patching their remote monitoring and management tools to mitigate vulnerabilities that could be exploited by ransomware gangs.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203