logo

DragonForce Ransomware Strikes MSP in Supply Chain Attack

ID: b6d0e459-1a93-543c-956a-b239804bf24f

STIX ID: report--b6d0e459-1a93-543c-956a-b239804bf24f

Feed Name: Dark Reading

Threat Score
85/100

Date Published: 2025-05-27

Date Updated: 2026-04-21

Author: Alexander Culafi, Senior News Writer, Dark Reading

...
...

Sophos reported that the DragonForce ransomware group exploited a chain of SimpleHelp RMM vulnerabilities to perform a supply-chain attack against an MSP, pushing a malicious SimpleHelp installer to downstream customers; multiple endpoints were encrypted and some victims suffered data theft for double-extortion. The report details the exploited CVEs, describes DragonForce's affiliate-friendly RaaS model and aggressive marketing, and recommends detection, patching, identity controls, and endpoint monitoring for infostealer activity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.