ZeroHour
Help Net Securitypublished ()ingested @zeljkazorz

Attackers hit MSP, use its RMM software to deliver ransomware to clients

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2024-57726
+2 in the same advisory: …57727 …57728
Missing-Authorization Privilege Escalation in SimpleHelp Remote Support <= 5.5.7

SimpleHelp remote support software versions 5.5.7 and earlier contain a missing-authorization flaw (CWE-862) that lets low-privileged technicians create API keys with excessive permissions. A network attacker holding only a technician-level account can mint such an over-privileged API key and use it to escalate to the SimpleHelp server admin role, with no user interaction required (CVSS 3.1 score 9.9, scope changed). Successful exploitation yields full administrative control of the SimpleHelp server, the remote-access/RMM platform support staff use to reach endpoints, which can also expose downstream customer environments when the server is run by an MSP. Any organization running SimpleHelp 5.5.7 or earlier is affected, with MSPs at particular risk given their downstream reach. The flaw is confirmed exploited in the wild: it was added to CISA KEV on 2026-04-24 with known ransomware use, carries a 66.6% EPSS score (99th percentile), and public reporting describes ransomware operators chaining SimpleHelp flaws in double-extortion attacks against an MSP and its customers.

Do: Upgrade SimpleHelp to the latest vendor release newer than 5.5.7 and apply vendor mitigation guidance; federal agencies must meet BOD 22-01 requirements or discontinue use. Audit existing API keys (especially those created by technician accounts) for excessive permissions, review audit logs for unexpected key creation or admin activity, and restrict internet exposure of SimpleHelp servers. Organizations whose MSP uses SimpleHelp should confirm the MSP's instance is patched before trusting remote sessions.

9.9
group max
67% KEV ransomware
  • SimpleHelp remote support software 5.5.7 and earlier
moderatelow thousands of exposed self-hosted SimpleHelp server deployments (est.), amplified to many downstream endpoints where instances are run by MSPs
Full article408 words · extracted from helpnetsecurity.com · click to collapse

A threat actor wielding the DragonForce ransomware has compromised an unnamed managed service provider (MSP) and pushed the malware onto its client organizations via SimpleHelp, a legitimate remote monitoring and management (RMM) tool.

MSP SimpleHelp ransomware

“Sophos MDR has medium confidence the threat actor exploited a chain of vulnerabilities that were released in January 2025,” the company’s incident responders shared on Tuesday.

The vulnerabilities in question are CVE-2024-57727, CVE-2024-57728 and CVE-2024-57726, which can be used to compromise SimpleHelp server instances and, through them, push malicious payloads to machines with the client software installed.

Earlier this year, the vulnerabilities have been exploited by ransomware attackers to target healthcare organizations.

Spotting the attack

“Sophos MDR was alerted to the incident by detection of a suspicious installation of a SimpleHelp installer file. The installer was pushed via a legitimate SimpleHelp RMM [server] instance, hosted and operated by the MSP for their clients,” the incident responders said.

“The attacker also used their access through the MSP’s RMM instance to gather information on multiple customer estates managed by the MSP, including collecting device names and configuration, users, and network connections.”

One of the MSP’s clients is also a Sophos client, and the company’s software and detection and response professionals shut down the attackers’ access to the client’s network before they were able to deploy the ransomware.

“The MSP engaged Sophos Rapid Response to provide digital forensics and incident response on their environment,” they added, and shared indicators of compromise related to this attack.

Who are DragonForce?

In the wake of the recent destructive attacks against UK retailers, DragonForce has become a familiar name.

DragonForce is a Ransomware-as-a-Service “cartel” that provides its affiliates with the DragonForce ransomware, and the infrastructure, tools and services needed to deploy it, but also allows them to use their own ransomware.

This setup makes attack attribution harder than it used to be. In the aforementioned attacks against UK retailers, for example, the attackers used social engineering tactics made infamous by the Scattered Spider group/collective but used the DragonForce ransomware and name.

The advent of the RaaS model has led to most ransomware attacks effectively involving the main RaaS group and its affiliate, though the involvement of the former can be minimal or substantial, depending on the services they provide to affiliates (e.g., help with ransomware deployment or ransom negotiation).

Subscribe to our breaking news e-mail alert to never miss out on the latest breaches, vulnerabilities and cybersecurity threats. Subscribe here!

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2025/05/28/attackers-hit-msp-use-its-rmm-software-to-deliver-ransomware-to-clients/