SimpleHelp is a legitimate remote monitoring and management (RMM) platform used for remote support and administration. Threat actors have repeatedly abused attacker-configured SimpleHelp clients as remote-access implants, often packaging them with JWrapper to create self-contained installers and make deployments resemble trusted software. In malicious use, SimpleHelp provides persistent interactive access and can support operator command execution, host monitoring, and follow-on activity while blending with legitimate IT tooling.
Observed delivery chains include phishing and spearphishing lures impersonating document-signing services, government and tax organizations, financial institutions, collaboration platforms, and transportation-related workflows. Other observed deployments follow exploitation of public-facing vulnerabilities or occur as a second-stage RMM installed by an already compromised endpoint. Installations have been configured as Windows services, accompanied by firewall changes, and used as redundant access alongside other remote-access products.
SimpleHelp abuse has been reported in intrusions associated with Medusa ransomware operators and affiliates, MuddyWater, and KONNI-linked activity, as well as financially motivated campaigns targeting logistics and transportation organizations for cargo theft. In ransomware intrusions, it has supported persistence after initial compromise and preceded credential access, lateral movement, data theft, and ransomware deployment. Its legitimate signing and administrative purpose make behavioral context—such as unauthorized deployment, suspicious parent processes, and unexpected remote-management tenancy—central to detection.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
5 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Unknown threat actors were observed exploiting CVE-2026-5027 against canary systems to drop a Python credential harvester, proxy agents, and SimpleHelp for remote access. | Unknown threat actors were observed exploiting CVE-2026-5027 to drop a Python credential harvester, proxy agents, and SimpleHelp for remote access.
CVE-2025-31161 is a 9.8 CVSS critical severity vulnerability that affects how the CrushFTP file transfer application handles user authentication... CrushFTP versions 10.0.0 through 10.8.3 and 11.0.0 through 11.3.0 are affected by a vulnerability in the S3 authorization header processing that allows authentication bypass.
Initial Access Exploitation of React2Shell (CVE-2025-55182) against crypto staking platforms... We observed this threat actor perform mass scanning to identify targets vulnerable to React2Shell...
“the Cofense Phishing Defense Center (PDC) identified multiple samples using the SimpleHelp Remote Monitoring and Management (RMM) tool… JWrapper-wrapped SimpleHelp is increasingly abused by threat actors as a stealthy Remote Access Trojan (RAT).”
Arctic Wolf has issued a warning regarding CVE-2026-1731, a nearly maximum-severity flaw (CVSS 9.9) in self-hosted BeyondTrust Remote Support and Privileged Remote Access environments... allows unauthenticated attackers to execute operating system commands... added to CISA’s Known Exploited Vulnerabilities (KEV) Catalog... threat actors using the exploit to deploy SimpleHelp...
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
...TA450 historically using several RMM tools, such as Atera, PDQ Connect, ScreenConnect, and SimpleHelp...
"To maintain persistence, they abused remote monitoring and management (RMM) tools, specifically SimpleHelp and MeshAgent."
16 distinct techniques documented for this family, organized by ATT&CK tactic.
T1078 (Valid Accounts) - атакующий использует trial или free аккаунт вендора как валидную учётную запись
the host held a seven-tool remote monitoring and management (RMM) arsenal for persistence, including ScreenConnect and SimpleHelp
The attackers also used some typical commands related to the Impacket WMIExec hacktool... During that intrusion, it’s believed the attackers used WMI to launch the SimpleHelp installer on the victim network.
MITRE ATT&CK techniques Tactic ID Technique Resource Development T1583.001 Acquire Infrastructure: Domains Initial Access T1189 Drive-by Compromise Initial Access T1566.002 Phishing: Spearphishing Link Execution T1204.002 User Execution: Malicious File Execution T1059.003 Command and Scripting Interpreter: Windows Command Shell Execution T1059.001 Command and Scripting Interpreter: PowerShell
MITRE ATT&CK techniques Tactic ID Technique Resource Development T1583.001 Acquire Infrastructure: Domains Initial Access T1189 Drive-by Compromise Initial Access T1566.002 Phishing: Spearphishing Link Execution T1204.002 User Execution: Malicious File Execution T1059.003 Command and Scripting Interpreter: Windows Command Shell Execution T1059.001 Command and Scripting Interpreter: PowerShell Persistence T1543.003 Create or Modify System Process: Windows Service Defense Evasion T1553.002 Subvert Trust Controls: Code Signing
77 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
21 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A legitimate remote support and management product referenced as being installed after host profiling by a dropper.
A legitimate remote-support tool abused by attackers to provide remote access to a compromised host.
A legitimate RMM/remote-support tool abused as an already-resident remote-access channel and delivery mechanism for ScreenConnect. In the deepest case it provided unattended access, scripting, persistence, and a PowerShell cradle to silently download and install ScreenConnect.
A self-contained remote access tool abused in phishing campaigns, especially invitation-themed lures. Its binaries embed configuration internally and often spawn a child process for the remote access session.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.