The group behind the DragonForce ransomware managed to compromise a managed service provider (MSP) and used the SimpleHelp remote monitoring and management (RMM) platform to steal data and install encryptors on the MSP's customers' systems.
See also: Iranian man confesses to involvement in Robbinhood ransomware

Sophos was called in to investigate the attack and believes the attackers exploited a chain of older vulnerabilities in SimpleHelp, which are listed as CVE-2024-57727, CVE-2024-57728 , and CVE-2024-57726, to compromise the system.
SimpleHelp is a commercial remote support and access tool widely used by MSPs to manage systems and install software on customer networks. According to the report , the attackers initially used SimpleHelp to identify themselves on customer systems, collecting information such as device names, settings, users and network connections.
The cybercriminals then attempted to steal data and install decryptors on customers’ networks. On one of the networks, endpoint protection was able to thwart the attack. However, other customers were not as lucky, with devices encrypted and data stolen in double-ransom attacks.
Sophos has shared indicators of compromise (IOCs) related to the attack, aiming to help organizations strengthen their defenses.
See also: MathWorks: Ransomware attack behind service outage
MSPs have long been a valuable target for ransomware gangs, as a single breach can lead to attacks on multiple companies. Some of the attackers’ partners have specialized in tools widely used by MSPs, such as SimpleHelp, ConnectWise ScreenConnect , and Kaseya.

This phenomenon has led to devastating attacks, such as the massive REvil group attack on Kaseya, which affected over 1,000 companies.
The DragonForce ransomware gang has recently gained increased notoriety, as it is linked to a wave of high-profile attacks in the retail sector, in which the attackers used tactics similar to those of the Scattered Spider.
As first reported by BleepingComputer, the group's ransomware was used in attacks against British chain Marks & Spencer. Shortly after, the same attackers also breached British chain Co-op, which confirmed the theft of a significant amount of customer data.
BleepingComputer has also reported that DragonForce is trying to create a kind of "cartel" by offering a ransomware-as-a-service (RaaS) model, allowing partners to use redesigned versions of its decryptor.
With its increasing partner-friendliness and continued increase in victims, DragonForce is rapidly evolving into one of the major players in the ransomware space.
See also: Nova Scotia Power confirms Ransomware attack
☁️ Keep safe copies with Proton Drive
Encrypted cloud storage from Proton — protect your files from ransomware, corruption, and data loss with end-to-end encryption.
- ✔ End-to-end encrypted files & backups
- ✔ Version history — recover files after ransomware
- ✔ Free space — sync across all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Based on the above, it is clear that ransomware groups like DragonForce are pursuing increasingly sophisticated strategies to increase their influence and efficiency. A typical example is the adoption of Ransomware-as-a-Service (RaaS), which allow smaller or less technically skilled criminals to carry out attacks with tools developed by more specialized groups.
Source: bleepingcomputer
