logo

Ransomware Gang Exploits SimpleHelp RMM to Compromise Utility Billing Firm

ID: 9ce87f75-d9ff-5512-b80f-222169401a65

STIX ID: report--9ce87f75-d9ff-5512-b80f-222169401a65

Feed Name: Infosecurity Magazine (News)

Threat Score
78/100

Date Published: 2025-06-13

Date Updated: 2026-04-22

...
...

Ransomware actors have been exploiting multiple SimpleHelp RMM vulnerabilities (including CVE-2024-57727, CVE-2024-57728, and CVE-2024-57726) to access downstream customers and deploy DragonForce ransomware in double-extortion attacks; CISA has added the flaw to its KEV catalog and issued mitigation guidance urging vendors, downstream customers, and end users to identify affected instances, isolate or stop vulnerable servers, patch immediately, and conduct threat hunting for indicators of compromise.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.