ZeroHour
Infosecurity Magazinepublished ()ingested James Coker

Ransomware Gang Exploits SimpleHelp RMM to Compromise Utility Billing

criticalRansomware exploited in the wildimportance 60CVE-2024-57727CVE-2024-57728CVE-2024-57726

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2024-57726
+2 in the same advisory: …57727 …57728
Missing-Authorization Privilege Escalation in SimpleHelp Remote Support <= 5.5.7

SimpleHelp remote support software versions 5.5.7 and earlier contain a missing-authorization flaw (CWE-862) that lets low-privileged technicians create API keys with excessive permissions. A network attacker holding only a technician-level account can mint such an over-privileged API key and use it to escalate to the SimpleHelp server admin role, with no user interaction required (CVSS 3.1 score 9.9, scope changed). Successful exploitation yields full administrative control of the SimpleHelp server, the remote-access/RMM platform support staff use to reach endpoints, which can also expose downstream customer environments when the server is run by an MSP. Any organization running SimpleHelp 5.5.7 or earlier is affected, with MSPs at particular risk given their downstream reach. The flaw is confirmed exploited in the wild: it was added to CISA KEV on 2026-04-24 with known ransomware use, carries a 66.6% EPSS score (99th percentile), and public reporting describes ransomware operators chaining SimpleHelp flaws in double-extortion attacks against an MSP and its customers.

Do: Upgrade SimpleHelp to the latest vendor release newer than 5.5.7 and apply vendor mitigation guidance; federal agencies must meet BOD 22-01 requirements or discontinue use. Audit existing API keys (especially those created by technician accounts) for excessive permissions, review audit logs for unexpected key creation or admin activity, and restrict internet exposure of SimpleHelp servers. Organizations whose MSP uses SimpleHelp should confirm the MSP's instance is patched before trusting remote sessions.

9.9
group max
67% KEV ransomware
  • SimpleHelp remote support software 5.5.7 and earlier
moderatelow thousands of exposed self-hosted SimpleHelp server deployments (est.), amplified to many downstream endpoints where instances are run by MSPs
Full article550 words · extracted from infosecurity-magazine.com · click to collapse

Ransomware actors have compromised customers of a utility software billing software provider after exploiting a vulnerability in the SimpleHelp Remote Monitoring and Management (RMM) tool.

A new advisory from the Cybersecurity and Infrastructure Security Agency (CISA) warned that the incident reflects a broader pattern of ransomware actors targeting organizations through unpatched versions of SimpleHelp RMM since January 2025.

SimpleHelp versions 5.5.7 and earlier contain several vulnerabilities, including a path traversal vulnerability CVE-2024-57727.

“Ransomware actors likely leveraged CVE-2024-57727 to access downstream customers’ unpatched SimpleHelp RMM for disruption of services in double extortion compromises,” CISA wrote.

All software vendors, downstream customers and end users have been urged to immediately determine if they have been compromised via the SimpleHelp flaw and apply mitigations.

SimpleHelp Flaws Exploited by DragonForce

The path transversal vulnerability CVE-2024-57727 was published in January 2025, and added to CISA’s Known Exploited Vulnerabilities (KEV) Catalog on February 13, 2025.

This flaw can allow unauthenticated remote attackers to download arbitrary files from the SimpleHelp host via crafted HTTP requests. These files include server configuration files containing various secrets and hashed user passwords.

In May, Sophos researchers observed DragonForce ransomware being deployed across several client networks by exploiting CVE-2024-57727 in combination with two other vulnerabilities also disclosed in January:

  • CVE-2024-57728: A high severity flaw enabling admin users to upload arbitrary files anywhere on the file system by uploading a crafted zip file
  • CVE-2024-57726: A critical level vulnerability that allows low-privileges technicians to create API keys with excessive permissions

Following encryption, the attackers adopted a double extortion strategy, demanding ransom while threatening to leak stolen data.

CISA did not disclose the ransomware group responsible for the attack on the utility software provider.

How to Protect Against SimpleHelp Compromise

CISA issued recommendations for software vendors, downstream customers and end users to determine if they are impacted by vulnerable SimpleHelp versions and how to mitigate the risks.

Software Vendors

If SimpleHelp is embedded in vendor-owned software or if a third-party service provider leverages SimpleHelp on a downstream customer’s network, these companies should identify the SimpleHelp server version at the top of the file.

If they discover version 5.5.7 or prior has been used since January 2025, vendors should take the following actions:

  • Isolate the SimpleHelp server instance from the internet or stop the server process
  • Immediately upgrade to the latest SimpleHelp version to patch the flaws
  • Contact all downstream customers and direct them to take actions to secure their endpoints and undertake threat hunting actions on their network

Downstream Customers and End Users

Downstream customers should immediately determine if their system is running an unpatched version of SimpleHelp RMM either directly or embedded in third-party software.

This can be done by checking the following paths according to the specific operating system.

  • Windows: %APPDATA%\JWrapper-Remote Access
  • Linux: /opt/JWrapper-Remote Access
  • MacOs: /Library/Application Support/JWrapper-Remote Access

If SimpleHelp is identified in any endpoints, the software version can be determined by performing an HTTP query against it.

If SimpleHelp version 5.5.7 or earlier is confirmed on a system, organizations should conduct threat hunting actions for evidence of compromise and continuously monitor for unusual inbound and outbound traffic from the SimpleHelp server.

If there is no evidence of compromise, users should immediately upgrade to the latest SimpleHelp version, or apply appropriate workarounds if it is not possible to fix straight away.

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.infosecurity-magazine.com/news/ransomware-simplehelp-compromise/