A coordinated wave of ransomware attacks in the UK has shown just how dangerous things can be in today’s digital age. The Medusa and DragonForce exploited three critical vulnerabilities in the RMM tool SimpleHelp (CVE-2024-57726, CVE-2024-57727, CVE-2024-57728) to gain access to customer networks via compromised MSPs and managed service providers.

Shifting tactics: From victim to supplier
Rather than directly targeting large companies, the attackers targeted the trust organizations place in third-party providers. By exploiting versions of SimpleHelp running with SYSTEM privileges, they achieved complete control of networks with minimal detection — a move that bypasses firewalls and leverages the internal trust of the environment.
See also: How GlassWorm returned to developers' code
How the attacks worked
Zensec researchers identified waves of attacks in the first two quarters of 2025. Medusa started first, pushing malicious payloads through compromised MSPs; DragonForce followed with a similar “productive” pattern. Both groups combined automation and manual techniques, adapting tools to penetrate, maintain access, and extract data before encrypting systems.

Defense bypass techniques
Medusa used PDQ Deploy to execute PowerShell commands that disabled Microsoft Defender , added exclusion paths, and disabled real-time monitoring:
Add-MpPreference -ExclusionPath “C:”
Set-MpPreference -MAPSReporting Disable
Set-MpPreference -DisableRealtimeMonitoring $true
It also promoted the “Gaze.exe” ransomware and specialized drivers (Smuot.sys, CSAgent.sys), enhancing its ability to bypass protections.
DragonForce chose a different strategy: it created local “admin” accounts, installed AnyDesk for permanent access, and ran scripts such as Get-Veeam-Creds.ps1 to extract credentials from Veeam systems , undermining recovery processes.
See also: Konni hackers turn Google's Find Hub into a "weapon"
Export and double blackmail
The extraction tools varied: Medusa leveraged RClone (renamed “lsp.exe”) for filtered file transfer, while DragonForce used Restic, an backup , to transfer stolen data to Wasabisys S3 compatible cloud storage endpoints. Before encryption, the attackers extracted sensitive data and used it for double blackmail, threatening publication.
Countermeasures and best practices
Organizations need to rethink supply chain security their: limiting privileges in RMM tools, strict password management, regular software updates, and network segmentation. Enabling logging and monitoring for unusual activities, implementing MFA, and encrypting sensitive inventory are essential.

MSP-customer collaboration
Prevention requires shared responsibility: MSPs should implement hardening, least-privilege, and transparent reporting. Customers should require security SLAs, control access rights, and conduct regular third-party audits.
See also: Quantum Route Redirect: Phishing service targets Microsoft 365 users
Attackers are targeting financial incentives, but also gaining access to critical chains. Prompt notification, regular simulations, and information sharing between organizations will limit the success of such campaigns.
☁️ Keep safe copies with Proton Drive
Encrypted cloud storage from Proton — protect your files from ransomware, corruption, and data loss with end-to-end encryption.
- ✔ End-to-end encrypted files & backups
- ✔ Version history — recover files after ransomware
- ✔ Free space — sync across all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Collective vigilance and action are essential.
