Campaign Exploiting SimpleHelp RMM Software for Initial Access
ID: 93cc34f3-68eb-5765-997a-7648bbe8bf8a
STIX ID: report--93cc34f3-68eb-5765-997a-7648bbe8bf8a
Feed Name: Arctic Wolf Blog
Arctic Wolf observed a campaign beginning January 22, 2025 that involved unauthorized access to devices running SimpleHelp RMM, potentially tied to recently disclosed SimpleHelp vulnerabilities (CVE-2024-57726/57727/57728). The bulletin describes initial access and reconnaissance activity (unapproved server communications, account/domain enumeration via cmd.exe), lists affected and fixed SimpleHelp versions, recommends patching/uninstalling unused clients, password rotation and IP restrictions, and cites historical RMM abuse by ransomware and state-aligned actors.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
