logo

DragonForce Exploits SimpleHelp Vulnerabilities in Ransomware Campaign (Campaign)

ID: c68c2b31-505e-538c-962d-c28086be2f4d

STIX ID: report--c68c2b31-505e-538c-962d-c28086be2f4d

Feed Name: Wiz Cloud Threat Landscape

Threat Score
80/100

Date Published: 2025-05-28

Date Updated: 2026-05-01

Author: [email protected] (Wiz Threat Research)

...
...

DragonForce exploited three known SimpleHelp vulnerabilities (CVE-2024-57726, CVE-2024-57727, CVE-2024-57728) in a supply-chain style compromise of an MSP: they accessed the MSP's SimpleHelp instance, delivered a weaponized installer to client environments, and used it for credential harvesting, network reconnaissance, and ransomware deployment.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.