Arctic Wolf observed a campaign beginning January 22, 2025, in which attackers used unauthorized access to devices running SimpleHelp remote monitoring and management (RMM) software for initial access. An existing SimpleHelp client connected to an unapproved server, and attackers enumerated accounts and domain information before the session was terminated. The activity followed Horizon3’s disclosure of CVE-2024-57726, CVE-2024-57727, and CVE-2024-57728, but Arctic Wolf did not confirm that those vulnerabilities enabled the campaign.
SimpleHelp published a security advisory covering vulnerabilities in version 5.5.7 and earlier. Organizations should upgrade SimpleHelp servers to fixed versions, remove unused clients, rotate administrator and Technician passwords, and restrict login source IP addresses. Security teams should also investigate client connections to unapproved SimpleHelp servers and associated account or domain enumeration, rather than assuming that patching alone addresses unauthorized access.

Get the actors, campaigns, and ATT&CK mapping behind it.
4 events from the most recent confirmed update back to the earliest known activity.
Arctic Wolf began observing attackers using unauthorized access to devices running SimpleHelp as an initial access vector. Existing clients connected to an unapproved SimpleHelp server, and attackers used cmd.exe, net, and nltest to enumerate accounts and domain information; exploitation of the disclosed vulnerabilities was not confirmed.
Arctic Wolf recommended upgrading to fixed SimpleHelp versions 5.5.8, 5.4.10, or 5.3.9 and removing unnecessary clients left by third-party support sessions. The bulletin also relayed SimpleHelp's recommendations to rotate administrator and Technician passwords and restrict login source IP addresses.
The SimpleHelp session was terminated after the attackers performed account and domain enumeration. Arctic Wolf did not observe the attackers progressing to their objectives.
Horizon3 publicly disclosed CVE-2024-57726, CVE-2024-57727, and CVE-2024-57728 roughly one week before the observed campaign emerged. The vulnerabilities could allow arbitrary file downloads, administrative file uploads, and privilege escalation.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.