DragonForce Ransomware Strikes MSP in Supply Chain Attack
ID: b6d0e459-1a93-543c-956a-b239804bf24f
STIX ID: report--b6d0e459-1a93-543c-956a-b239804bf24f
Feed Name: Dark Reading
Date Published: 2025-05-27
Date Updated: 2026-04-21
Author: Alexander Culafi, Senior News Writer, Dark Reading
Sophos reported that the DragonForce ransomware group exploited a chain of SimpleHelp RMM vulnerabilities to perform a supply-chain attack against an MSP, pushing a malicious SimpleHelp installer to downstream customers; multiple endpoints were encrypted and some victims suffered data theft for double-extortion. The report details the exploited CVEs, describes DragonForce's affiliate-friendly RaaS model and aggressive marketing, and recommends detection, patching, identity controls, and endpoint monitoring for infostealer activity.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
