HomeSecurityAbuse of RMM tools to distribute Medusa & DragonForce ransomware

Abuse of RMM tools to distribute Medusa & DragonForce ransomware

A coordinated wave of ransomware attacks in the UK has shown just how dangerous things can be in today’s digital age. The Medusa and DragonForce exploited three critical vulnerabilities in the RMM tool SimpleHelp (CVE-2024-57726, CVE-2024-57727, CVE-2024-57728) to gain access to customer networks via compromised MSPs and managed service providers.

RMM Medusa & DragonForce ransomware

Shifting tactics: From victim to supplier

Rather than directly targeting large companies, the attackers targeted the trust organizations place in third-party providers. By exploiting versions of SimpleHelp running with SYSTEM privileges, they achieved complete control of networks with minimal detection — a move that bypasses firewalls and leverages the internal trust of the environment.

See also: How GlassWorm returned to developers' code

How the attacks worked

Zensec researchers identified waves of attacks in the first two quarters of 2025. Medusa started first, pushing malicious payloads through compromised MSPs; DragonForce followed with a similar “productive” pattern. Both groups combined automation and manual techniques, adapting tools to penetrate, maintain access, and extract data before encrypting systems.

Abuse of RMM tools to distribute Medusa & DragonForce ransomware

Defense bypass techniques

Medusa used PDQ Deploy to execute PowerShell commands that disabled Microsoft Defender , added exclusion paths, and disabled real-time monitoring:

Add-MpPreference -ExclusionPath “C:”
Set-MpPreference -MAPSReporting Disable
Set-MpPreference -DisableRealtimeMonitoring $true

It also promoted the “Gaze.exe” ransomware and specialized drivers (Smuot.sys, CSAgent.sys), enhancing its ability to bypass protections.

DragonForce chose a different strategy: it created local “admin” accounts, installed AnyDesk for permanent access, and ran scripts such as Get-Veeam-Creds.ps1 to extract credentials from Veeam systems , undermining recovery processes.

See also: Konni hackers turn Google's Find Hub into a "weapon"

Export and double blackmail

The extraction tools varied: Medusa leveraged RClone (renamed “lsp.exe”) for filtered file transfer, while DragonForce used Restic, an backup , to transfer stolen data to Wasabisys S3 compatible cloud storage endpoints. Before encryption, the attackers extracted sensitive data and used it for double blackmail, threatening publication.

Countermeasures and best practices

Organizations need to rethink supply chain security their: limiting privileges in RMM tools, strict password management, regular software updates, and network segmentation. Enabling logging and monitoring for unusual activities, implementing MFA, and encrypting sensitive inventory are essential.

Abuse of RMM tools to distribute Medusa & DragonForce ransomware

MSP-customer collaboration

Prevention requires shared responsibility: MSPs should implement hardening, least-privilege, and transparent reporting. Customers should require security SLAs, control access rights, and conduct regular third-party audits.

See also: Quantum Route Redirect: Phishing service targets Microsoft 365 users

Attackers are targeting financial incentives, but also gaining access to critical chains. Prompt notification, regular simulations, and information sharing between organizations will limit the success of such campaigns.

Selecting the team

☁️ Keep safe copies with Proton Drive

Encrypted cloud storage from Proton — protect your files from ransomware, corruption, and data loss with end-to-end encryption.

  • ✔ End-to-end encrypted files & backups
  • ✔ Version history — recover files after ransomware
  • ✔ Free space — sync across all devices
Get started for free with Proton Drive →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Collective vigilance and action are essential.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS