NEWS

DragonForce Ransomware Exploits SimpleHelp Vulnerabilities, Targeting MSPs and Clients

Cybercriminals exploit vulnerabilities in SimpleHelp software, breaching a managed service provider and impacting its clients. This incident highlights the urgent need for timely software updates and robust cybersecurity measures amidst evolving threats.

By
LNGFRM Team
Published May 27, 2025

In an unsettling development that underscores the persistent threat posed by cybercriminals, DragonForce ransomware operators have exploited vulnerabilities in SimpleHelp software to target a managed service provider (MSP) and its clients.

This alarming breach was brought to light by the cybersecurity firm Sophos, which detailed how the attackers chained together three specific vulnerabilities in the remote monitoring and management (RMM) platform SimpleHelp.

The vulnerabilities, identified as CVE-2024-57727, CVE-2024-57728, and CVE-2024-57726, allow malicious actors to retrieve sensitive logs, access configuration files, and extract credentials.

Furthermore, these flaws enable hackers to log in with elevated privileges, upload malicious files, execute arbitrary code, and escalate their privileges to administrative levels.

Such a comprehensive compromise of the system underscores the critical nature of these vulnerabilities.

SimpleHelp had released patches for these security flaws in mid-January, but cybercriminals were quick to exploit unpatched systems.

Within two weeks of the patch release, threat actors began targeting unpatched internet-facing instances of SimpleHelp, demonstrating their agility and the importance of prompt patch management in cybersecurity practices.

Sophos reports that the chain of vulnerabilities was likely used to breach an unnamed MSP’s SimpleHelp deployment.

This deployment was integral to the MSP’s operations and was used to manage customer data and services.

The attackers were able to gather extensive information, including device names, configurations, user data, and network connections, from the MSP’s system.

This trove of information was not only exfiltrated but also used to deploy the DragonForce ransomware, impacting both the MSP and its clientele.

The DragonForce group, which has been in the cybersecurity spotlight recently, has gained notoriety for its aggressive tactics and choice of high-profile targets.

The group has been active since mid-2023 and operates as a ransomware-as-a-service (RaaS) entity.

This model allows various affiliates to use the ransomware infrastructure to launch attacks, thereby broadening the scope and frequency of incidents.

Recent attacks attributed to DragonForce have included prominent UK retailers such as Marks & Spencer, Co-op, and Harrods.

Furthermore, a Google warning indicated a shift in DragonForce’s focus towards US retailers, signaling a potential escalation in their operations.

The group is known to have taken over the infrastructure of RansomHub, another notorious ransomware gang, indicating a consolidation of cybercriminal resources that could lead to more sophisticated and widespread attacks.

The involvement of Scattered Spider, also known as UNC3944, adds another layer to this complex web of cybercrime.

As an affiliate of RansomHub, Scattered Spider has been implicated in using DragonForce for recent attacks.

The US government’s response to this group was swift, with charges filed against five members in November 2024.

This action followed the arrest of the group’s suspected leader and another member in the UK, highlighting international cooperation in the fight against cybercrime.

This incident serves as a stark reminder of the relentless evolution of cyber threats and the importance of robust cybersecurity measures.

It is crucial for organizations to implement timely software updates and maintain vigilant security protocols to protect against such vulnerabilities.

The DragonForce attack underscores a broader issue within the cybersecurity landscape: the need for constant vigilance, collaboration, and innovation to stay ahead of increasingly sophisticated cyber threats.

As ransomware groups like DragonForce continue to adapt and expand their operations, the importance of cybersecurity cannot be overstated.

Organizations must remain proactive in their defenses, ensuring that systems are not only patched but also monitored for unusual activity.

The DragonForce saga is a testament to the fact that in the world of cybersecurity, complacency is not an option.

It is a call to action for all stakeholders to remain engaged and committed to safeguarding their digital assets against the ever-present threat of cybercrime.

Author

  • LNGFRM Team

    Frank DiBernardo handles LNGFRM's Foodie and Miscellaneous writing tasks. He's always getting ideas from users, so don't be afraid to send an email to the editor.

Daily Newsletter
Subscribe to our Newletter!
You May Also Like
© 2026 LNGFRM. All rights reserved.