DragonForce actors target SimpleHelp vulnerabilities to attack MSP, customers – Sophos News

Date:

Share post:

Sophos MDR recently responded to a targeted attack involving a Managed Service Provider (MSP). In this incident, a threat actor gained access to the MSP’s remote monitoring and management (RMM) tool, SimpleHelp, and then used it to deploy DragonForce ransomware across multiple endpoints. The attackers also exfiltrated sensitive data, leveraging a double extortion tactic to pressure victims into paying the ransom.

Sophos MDR has medium confidence the threat actor exploited a chain of vulnerabilities that were released in January 2025:

  • CVE-2024-57727: Multiple path traversal vulnerabilities
  • CVE-2024-57728: Arbitrary file upload vulnerability
  • CVE-2024-57726: Privilege escalation vulnerability

DragonForce

DragonForce ransomware is an advanced and competitive ransomware-as-a-service (RaaS) brand that first emerged in mid-2023. As discussed in recent research from Sophos Counter Threat Unit (CTU), DragonForce began efforts in March to rebrand itself as a “cartel” and shift to a distributed affiliate branding model.

Coinciding with this effort to appeal to a wider range of affiliates, DragonForce recently garnered attention in the threat landscape for claiming to “take over” the infrastructure of RansomHub. Reports also suggest that well-known ransomware affiliates, including Scattered Spider (UNC3944) who was formerly a RansomHub affiliate, have been using DragonForce in attacks targeting multiple large retail chains in the UK and the US.

The incident

Sophos MDR was alerted to the incident by detection of a suspicious installation of a SimpleHelp installer file. The installer was pushed via a legitimate SimpleHelp RMM instance, hosted and operated by the MSP for their clients. The attacker also used their access through the MSP’s RMM instance to gather information on multiple customer estates managed by the MSP, including collecting device names and configuration, users, and network connections.

One client of the MSP was enrolled with Sophos MDR and had Sophos XDR endpoint protection deployed. Through a combination of behavioral and malware detection and blocking by Sophos endpoint protection and MDR actions to shut down attacker access to the network, thwarting the ransomware and double extortion attempt on that customer’s network. However, the MSP and clients that were not using Sophos MDR were impacted by both the ransomware and data exfiltration. The MSP engaged Sophos Rapid Response to provide digital forensics and incident response on their environment.

Indicators of compromise related to this investigation are available from our GitHub.

 

 

 

 

 

Source link

spot_img

Related articles

Bulletproof Host Stark Industries Evades EU Sanctions – Krebs on Security

In May 2025, the European Union levied financial sanctions on the owners of Stark Industries Solutions Ltd., a bulletproof...

MSI Afterburner developer adding ‘triple channel voltage’ support for future MSI RTX 50 graphics cards

MSI Afterburner's sole developer, Alexey Nicolaychuk, is working on a new update for the app that will expand...

AMD FSR 4 now available in over 85 games

Delivering incredible graphics without compromising performance remains a priority for gamers and developers alike. Enter AMD FidelityFX™...