Cyber AttacksVulnerabilities

DragonForce exploits SimpleHelp flaws to breach MSP

0

Sophos researchers have uncovered a cyberattack in which a DragonForce ransomware operator exploited three chained vulnerabilities in the SimpleHelp remote management tool to compromise a managed service provider (MSP) and its customers.

SimpleHelp is remote support and access software commonly used by IT teams to troubleshoot and maintain client systems. The attackers leveraged three recently disclosed vulnerabilities—CVE-2024-57727, CVE-2024-57728, and CVE-2024-57726—to gain initial access and escalate privileges.

  • CVE-2024-57727 (CVSS 7.5): An unauthenticated path traversal flaw that allows attackers to download arbitrary files, including serverconfig.xml, which contains encrypted admin and technician credentials and other sensitive data protected by a hardcoded key.

  • CVE-2024-57728 (CVSS 7.2): A vulnerability enabling arbitrary file uploads, potentially leading to remote code execution. On Linux, it allows command execution via crontab; on Windows, it facilitates overwriting executables.

  • CVE-2024-57726 (CVSS 7.2): A privilege escalation issue allowing low-privilege technician accounts to elevate to admin due to missing backend authorization checks. This grants full access to client machines and the SimpleHelp server.

These vulnerabilities were first reported to SimpleHelp by Horizon3 on January 6, 2025. A security patch (version 5.3.9) was released on January 13.

Shortly after public disclosure, Arctic Wolf researchers began observing a targeted campaign against SimpleHelp servers. According to their report, attackers began exploiting these flaws around January 22, using SimpleHelp as an initial access vector.

Arctic Wolf warned that if a threat actor chains these vulnerabilities together and gains administrative access to a SimpleHelp server, they could theoretically use it to compromise devices running the SimpleHelp client software.

Sophos’ investigation revealed that the attacker hijacked a legitimate SimpleHelp instance operated by an MSP to deploy a suspicious installer and penetrate client environments. The attacker then gathered host information, user data, and network configurations across multiple customers.

One client, protected by Sophos MDR and XDR, successfully blocked the ransomware and data theft attempt. Unfortunately, others without these defenses were compromised. Sophos Rapid Response has since been engaged to contain and investigate the breach.

“The installer was pushed via a legitimate SimpleHelp RMM instance, hosted and operated by the MSP for their clients,” Sophos noted. “The attacker used their access to collect details on customer environments, including device names, user accounts, and network connections.”

Sophos has published Indicators of Compromise (IOCs) related to the attack on their GitHub repository.

The DragonForce ransomware group, responsible for the attack, recently became popular for claiming breaches of major UK retailers including Marks & Spencer, Co-op, and Harrods. Known for encrypting and stealing victim data, DragonForce operates a cybercrime-as-a-service model, offering tools to affiliates. The group is active on Telegram and Discord and is believed to consist primarily of English-speaking teenagers.

Priyanka R
Cyber Security Enthusiast, Security Blogger, Technical Editor, Author at Cyber Safe News

Chinese Hackers exploit Trimble Cityworks flaw to infiltrate U.S. Local Government Systems

Previous article

Russian Cyberspy Group ‘Laundry Bear’ tied to Dutch Police Breach

Next article

You may also like

Comments

Leave a reply

Your email address will not be published. Required fields are marked *