Arctic Wolf Observes Campaign Exploiting SimpleHelp RMM Software for Initial Access
ID: 82eb4331-9255-52a1-96f2-a643176762eb
STIX ID: report--82eb4331-9255-52a1-96f2-a643176762eb
Feed Name: Arctic Wolf
Arctic Wolf observed an active campaign (reported 2025-01-22) involving unauthorized access to devices using SimpleHelp RMM, potentially linked to recently disclosed SimpleHelp vulnerabilities (CVE-2024-57726/57727/57728) that allow arbitrary file download/upload and privilege escalation; the campaign showed client communications to an unapproved SimpleHelp server and basic domain enumeration before sessions were terminated. Arctic Wolf recommends upgrading affected SimpleHelp server versions, uninstalling unused clients, rotating passwords, and restricting IPs, and notes historical abuse of RMM tools by ransomware and state-aligned actors.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
