HomeSecurityHackers exploit vulnerabilities in SimpleHelp RMM

Hackers exploit vulnerabilities in SimpleHelp RMM

Hackers are targeting vulnerable SimpleHelp RMM clients to create administrator accounts, install backdoors and the Sliver malware , and potentially lay the groundwork for ransomware.

SimpleHelp RMM vulnerabilities

Last week, Arctic Wolf reported that the vulnerabilities tracked as CVE-2024-57726, CVE-2024-57727, and CVE-2024-57728 were used in attacks. However, the cybersecurity firm couldn’t say for sure whether they were used in specific attacks. Cybersecurity firm Field Effect reportedly confirmed to BleepingComputer that the bugs were being exploited in recent attacks and published a report shedding light on the post-exploit activity.

See also: Critical Microsoft Outlook vulnerability used in attacks

Additionally, cybersecurity researchers report that the observed activity has evidence that shows some similarity to attacks by the ransomware group Akira, but this is not certain either.

Targeting SimpleHelp RMM

The attack began with attackers exploiting vulnerabilities in the SimpleHelp RMM client to establish an unauthorized connection to a target endpoint.

The attackers connected from IP 194.76.227[.]171, a server in Estonia running a SimpleHelp instance on port 80.

After connecting via RMM, the intruders quickly executed a series of reconnaissance commands to learn more about the target environment (e.g., system and network details, users and privileges, scheduled tasks and services and domain controller information).

Security researchers also noticed a command to search for the CrowdStrike Falcon security suite (likely a bypass attempt).

Later, the attackers proceeded to create a new administrator account named “sqladmin” to maintain access to the environment and then installed the Sliver post-exploitation framework (agent.exe).

See also: Multiple vulnerabilities in Cisco SNMP allow DoS attacks

Hackers exploit vulnerabilities in SimpleHelp RMM

Sliver was developed by BishopFox and is often used, recently, as an alternative to Cobalt Strike.

When deployed, Sliver will reconnect to a command and control (C2) server to open a reverse shell or wait for commands to be executed on the infected host.

The Silver beacon, in this particular attack, connected to a C2 in the Netherlands.

Having secured persistence, the attackers advanced deeper into the network, compromising the Domain Controller, using the same SimpleHelp RMM client and creating another administrator account (“fpmhlttech”).

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Instead of a backdoor, the attackers installed a Cloudflare Tunnel disguised as Windows svchost.exe to maintain hidden access and bypass security checks and firewalls.

SimpleHelp protection

To protect against such attacks, SimpleHelp users are urged to apply the available security updates for vulnerabilities CVE-2024-57726, CVE-2024-57727, and CVE-2024-57728. For more information, please refer to the vendor bulletin.

See also: CISA added Linux kernel vulnerability to KEV List

Additionally, look for administrator accounts named “ sqladmin ” and “ fpmhlttech ” or any other unknown accounts and look for connections to the IPs listed in the Field Effect report

Finally, it is important to limit SimpleHelp access to trusted IP ranges.

The recent SimpleHelp vulnerabilities serve as a reminder of the importance of securing RMM tools and implementing appropriate cybersecurity protocols. With the increasing reliance on these tools and the increasing sophistication of cyber threats, organizations must prioritize protecting their systems and maintaining a strong security posture to guard against potential exploits.

By staying vigilant and assessing and addressing any vulnerabilities in their RMM tools, organizations can mitigate the risk of falling victim to similar attacks in the future.

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS