logo

DragonForce Ransomware Leverages SimpleHelp Exploits to Hit MSPs

ID: 37eb4a83-911e-5513-a1a3-fffd31535b1a

STIX ID: report--37eb4a83-911e-5513-a1a3-fffd31535b1a

Feed Name: Halcyon Blog

Threat Score
88/100

Date Published: 2025-05-27

Date Updated: 2026-04-28

...
...

DragonForce exploited known SimpleHelp RMM vulnerabilities to compromise an MSP and its downstream clients, using the MSP's legitimate RMM instance to deploy malicious installers, exfiltrate device and user data, and execute double-extortion ransomware; the campaign leveraged chained CVE-2024-57726 and CVE-2024-57727 exploits and displayed RaaS sophistication including log-wiping and evasion, highlighting severe supply-chain and trust-based risks for MSP-managed environments.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.