Researchers believe that some hackers are exploiting vulnerabilities in SimpleHelp Remote Monitoring and Management (RMM) software to gain initial access to networks.

The vulnerabilities are tracked as CVE-2024-57726, CVE-2024-57727, and CVE-2024-57728 and allow cybercriminals to download and upload files to devices and escalate their privileges to administrator levels.
The vulnerabilities were discovered and disclosed by researchers at Horizon3 two weeks ago. SimpleHelp has released updates to fix them (product versions 5.5.8, 5.4.10, and 5.3.9).
See also: Apple fixes first zero-day vulnerability for 2025
Arctic Wolf reporting that hackers are targeting SimpleHelp servers. The campaign appears to have begun about a week after the vulnerabilities were publicly disclosed.
The company is not 100% sure that the attacks exploit these bugs, but it believes to some extent that they are related to the Horizon3 report.
“While it has not been confirmed that the recently disclosed vulnerabilities are responsible for the observed campaign, Arctic Wolf strongly recommends upgrading to the latest available stable versions of the SimpleHelp server software,” the report states.
“In cases where the SimpleHelp client was installed on devices for third-party support sessions, but is not actively used for daily operations, Arctic Wolf recommends uninstalling the software to reduce the likelihood of an attack.“.
See also: Apache Solr vulnerability allows Arbitrary Path write-access
Threat monitoring platform Shadowserver Foundation reported seeing 580 vulnerable devices. Most (345) are located in the United States.
Attacks
Arctic Wolf reports that the SimpleHelp 'Remote Access.exe' process was already running in the background before the attack, indicating that SimpleHelp had previously been installed for remote support on devices.
The first sign of a breach was the SimpleHelp client on the target device communicating with an unauthorized SimpleHelp server.
The attacker can exploit vulnerabilities in SimpleHelp to gain control of the client or use stolen credentials to compromise the connection.

Once inside, the attacker runs cmd.exe commands, such as "net" and "nltest", to gather information about the system (e.g. list of user accounts, groups, shared resources, domain controllers) and test Active Directory connectivity.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
These actions are common in attacks aimed at privilege escalation and lateral movement. However, Arctic Wolf says the malicious session was terminated before it could be determined what the attacker was going to do next.
See also: Critical Fleet Server vulnerability exposes sensitive information
SimpleHelp users are advised to upgrade to the latest version to fix the vulnerabilities.
More information on how to apply security updates is available in the SimpleHelp newsletter
In today's digital landscape, cyberattacks are becoming increasingly sophisticated and widespread. With the rise of remote work and virtual collaboration, it is more important than ever for organizations to prioritize cybersecurity measures to protect sensitive data and systems.
A critical aspect of network security is timely application of patches and security updates. These updates often contain critical fixes for known vulnerabilities that hackers could exploit.
In the case of the recently patched SimpleHelp RMM software vulnerabilities, immediate updating could have prevented attackers from gaining initial access to target networks.
Source: www.bleepingcomputer.com
