logo

Hackers exploit SimpleHelp RMM flaws to deploy Sliver malware

ID: b061cbd4-b1bf-5d3c-9fbc-19c3e034ba28

STIX ID: report--b061cbd4-b1bf-5d3c-9fbc-19c3e034ba28

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2025-02-06

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Attackers exploited critical SimpleHelp RMM vulnerabilities to establish unauthorized RMM connections, run discovery, create persistent administrator accounts (e.g., "sqladmin", "fpmhlttech"), install the Sliver post-exploitation framework and a Cloudflare Tunnel disguised as svchost.exe, and subsequently compromise a Domain Controller; Field Effect confirmed active exploitation and observed indicators (attacker IP, C2 in the Netherlands) and signs consistent with Akira ransomware activity, and the vendor has released patches to address the CVEs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.