logo

DragonForce ransomware abuses SimpleHelp in MSP supply chain attack

ID: 282ec802-8f67-5f43-aef7-9b5b6ee3fa2e

STIX ID: report--282ec802-8f67-5f43-aef7-9b5b6ee3fa2e

Feed Name: Bleeping Computer

Threat Score
80/100

Date Published: 2025-05-27

Date Updated: 2026-04-20

Author: Lawrence Abrams

...
...

Sophos investigated a DragonForce ransomware campaign that breached a managed service provider by exploiting older SimpleHelp RMM vulnerabilities (CVE-2024-57727, CVE-2024-57728, CVE-2024-57726), enabling reconnaissance, data theft and encryption of downstream customer systems; IOCs were shared to help defenders, and the report links these actions to DragonForce’s broader retail breaches and RaaS expansion.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.