logo

Campaign Exploiting SimpleHelp RMM Software for Initial Access

ID: 93cc34f3-68eb-5765-997a-7648bbe8bf8a

STIX ID: report--93cc34f3-68eb-5765-997a-7648bbe8bf8a

Feed Name: Arctic Wolf Blog

Threat Score
70/100

Date Published: 2025-01-24

Date Updated: 2026-04-27

...
...

Arctic Wolf observed a campaign beginning January 22, 2025 that involved unauthorized access to devices running SimpleHelp RMM, potentially tied to recently disclosed SimpleHelp vulnerabilities (CVE-2024-57726/57727/57728). The bulletin describes initial access and reconnaissance activity (unapproved server communications, account/domain enumeration via cmd.exe), lists affected and fixed SimpleHelp versions, recommends patching/uninstalling unused clients, password rotation and IP restrictions, and cites historical RMM abuse by ransomware and state-aligned actors.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.