DragonForce ransomware abuses SimpleHelp in MSP supply chain attack
ID: 282ec802-8f67-5f43-aef7-9b5b6ee3fa2e
STIX ID: report--282ec802-8f67-5f43-aef7-9b5b6ee3fa2e
Feed Name: Bleeping Computer
Threat Score
Sophos investigated a DragonForce ransomware campaign that breached a managed service provider by exploiting older SimpleHelp RMM vulnerabilities (CVE-2024-57727, CVE-2024-57728, CVE-2024-57726), enabling reconnaissance, data theft and encryption of downstream customer systems; IOCs were shared to help defenders, and the report links these actions to DragonForce’s broader retail breaches and RaaS expansion.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
