DragonForce Exploits SimpleHelp Flaws to Deploy Ransomware Across Customer Endpoints
Using the SimpleHelp remote monitoring and management (RMM) service from an unidentified Managed Service Provider (MSP), the threat actors behind the DragonForce ransomware were able to exfiltrate data and drop the locker on numerous endpoints.
According to a Sophos study, the attackers used three security holes in SimpleHelp (CVE-2024-57727, CVE-2024-57728, and CVE-2024-57726) that were made public in January 2025 to gain access to the MSP's SimpleHelp deployment.
A suspicious installation of a SimpleHelp installer file, pushed via a genuine SimpleHelp RMM instance that is hosted and run by the MSP for their clients, prompted the cybersecurity firm to report the incident.
It has also been discovered that the threat actors exploit their access to the MSP's RMM instance to gather ...

