ZeroHour
Infosecurity Magazinepublished ()ingested Alessandro Mascellino

DragonForce Ransomware Leveraged in MSP Attack Using RMM Tool

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2024-57726
+2 in the same advisory: …57727 …57728
Missing-Authorization Privilege Escalation in SimpleHelp Remote Support <= 5.5.7

SimpleHelp remote support software versions 5.5.7 and earlier contain a missing-authorization flaw (CWE-862) that lets low-privileged technicians create API keys with excessive permissions. A network attacker holding only a technician-level account can mint such an over-privileged API key and use it to escalate to the SimpleHelp server admin role, with no user interaction required (CVSS 3.1 score 9.9, scope changed). Successful exploitation yields full administrative control of the SimpleHelp server, the remote-access/RMM platform support staff use to reach endpoints, which can also expose downstream customer environments when the server is run by an MSP. Any organization running SimpleHelp 5.5.7 or earlier is affected, with MSPs at particular risk given their downstream reach. The flaw is confirmed exploited in the wild: it was added to CISA KEV on 2026-04-24 with known ransomware use, carries a 66.6% EPSS score (99th percentile), and public reporting describes ransomware operators chaining SimpleHelp flaws in double-extortion attacks against an MSP and its customers.

Do: Upgrade SimpleHelp to the latest vendor release newer than 5.5.7 and apply vendor mitigation guidance; federal agencies must meet BOD 22-01 requirements or discontinue use. Audit existing API keys (especially those created by technician accounts) for excessive permissions, review audit logs for unexpected key creation or admin activity, and restrict internet exposure of SimpleHelp servers. Organizations whose MSP uses SimpleHelp should confirm the MSP's instance is patched before trusting remote sessions.

9.9
group max
67% KEV ransomware
  • SimpleHelp remote support software 5.5.7 and earlier
moderatelow thousands of exposed self-hosted SimpleHelp server deployments (est.), amplified to many downstream endpoints where instances are run by MSPs
Full article342 words · extracted from infosecurity-magazine.com · click to collapse

A targeted cyber-attack exploiting a managed service provider’s (MSP) remote monitoring and management tool has resulted in ransomware deployment and data theft across several client networks.

The incident, identified and partly contained by Sophos Managed Detection and Response (MDR), involved the DragonForce ransomware-as-a-service (RaaS) operation.

The attack began when a threat actor accessed the MSP’s SimpleHelp remote monitoring and management (RMM) tool. From there, they pushed a malicious installer to multiple endpoints, gaining control of several client systems.

Sophos researchers believe with medium confidence that the attacker exploited a combination of three vulnerabilities disclosed earlier this year:

  • CVE-2024-57727: Path traversal vulnerabilities
  • CVE-2024-57728: Arbitrary file upload flaw
  • CVE-2024-57726: Privilege escalation issue

Once inside, the attackers exfiltrated sensitive client data and used DragonForce ransomware to encrypt systems. The group adopted a double extortion strategy, demanding ransom while threatening to leak stolen data.

Read more on ransomware-as-a-service trends: Malware-as-a-Service Now the Top Threat to Organizations

The breach was first detected through an anomalous SimpleHelp installer. 

Sophos said it traced the activity back to the MSP’s RMM instance and found the attacker had gathered detailed information across multiple customer environments, including device names, user data and network configurations.

One client, protected by Sophos XDR and enrolled in MDR services, avoided the ransomware attack entirely. According to the security firm, behavioral detection and swift incident response actions neutralized the threat before damage occurred.

However, other clients without MDR coverage were affected by both data loss and ransomware encryption.

Sophos Rapid Response has since been engaged to assist the MSP with forensics and containment.

A Rising Threat Actor

DragonForce, which surfaced in mid-2023, has recently shifted to a distributed affiliate model and branded itself as a “cartel.” This rebranding aligns with its efforts to broaden its affiliate base. 

The group recently claimed to have taken over RansomHub infrastructure, a move that’s drawn significant attention within the cyber-threat community.

Reports suggest well-known ransomware affiliates, including Scattered Spider (UNC3944), have adopted DragonForce in recent attacks. These campaigns have targeted well-known retail businesses in both the UK and the US.

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.infosecurity-magazine.com/news/dragonforce-ransomware-msp-attack/