Updated DragonForce ransomware infected a managed service provider, and its customers, after attackers exploited security flaws in remote monitoring and management tool SimpleHelp. In addition to deploying DragonForce ransomware across "multiple" endpoints, the criminals also stole sensitive data and used double-extortion tactics to pressure victims into paying the ransom, according to security shop Sophos. The company’s researchers didn't identify the managed service provider (MSP) nor how many customers were affected. We've asked both Sophos and SimpleHelp for more details and will update this article if we hear back. DragonForce is a new-ish ransomware-as-a-service gang that gained notoriety in April after cybercrime “cartel” Scattered Spider used its ransomware to infect major retailers in the UK and US, then began offering a service that allows other crooks to use DragonForce's infrastructure and tools to deploy any type of ransomware. MSPs are always a hot target for criminals because they offer a one-to-many attack: infecting a single MSP creates the chance to gain access to all of its customers' networks. In this case, exploiting SimpleHelp's software provides an even bigger bang for the buck - it's a legitimate remote monitoring and management (RMM) product that has thousands of customers, theoretically allowing the crooks to push the malware to multiple IT environments as if it were a legit software update. When DragonForce exploited SimpleHelp's vulnerabilities, th...
DragonForce used MSP's RMM software to distribute ransomware
The Register
·Jessica Lyons
·Published May 28, 2025
·Updated
Affected Software
2 affected components
SimpleHelp=5.5.7
SimpleHelp
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses the DragonForce ransomware gang exploiting vulnerabilities in SimpleHelp RMM software to infect a managed service provider and its clients.
2
What security implications are discussed in the article?
The article highlights the risks associated with security flaws in remote monitoring and management tools, which can lead to widespread ransomware infections.
3
What products or software are affected by the DragonForce ransomware attack?
The affected software mentioned in the article is SimpleHelp, specifically version 5.5.7.
4
How did the DragonForce ransomware gain access to the systems?
The ransomware was able to spread after attackers exploited security vulnerabilities in the SimpleHelp RMM software.
5
What actions should organizations take in response to this incident?
Organizations should prioritize updating and patching their remote monitoring and management tools to mitigate vulnerabilities that could be exploited by ransomware gangs.