SimpleHelp Support Software Attack

Released: Jun 16, 2025



Ransomware Actors Target Remote Monitoring and Management Software

FortiGuard Labs continues to observe ongoing attack attempts targeting SimpleHelp, a Remote Monitoring and Management (RMM) software, due to a critical unauthenticated path traversal vulnerability (CVE-2024-57727) affecting versions 5.5.7 and earlier. Learn More »

Common Vulnerabilities and Exposures




Background

This flaw allows remote attackers to access and download arbitrary files from the server without authentication, simply by sending specially crafted HTTP requests. The exposed files may contain highly sensitive information, including server configuration data, hashed administrator passwords, API keys, and other credentials. These exploits impact SimpleHelp v5.5.7 and all earlier releases and The root cause is improper input validation, which lets attackers manipulate file paths to reach files outside the intended directories.

According to Cybersecurity Advisory published by the Cybersecurity and Infrastructure Security Agency (CISA), multiple ransomware groups, including initial access brokers with ties to Play ransomware operators, exploited the vulnerabilities in remote monitoring and management (RMM) tool SimpleHelp to conduct remote code execution.

Latest Development

Recent news and incidents related to cybersecurity threats encompassing various events such as data breaches, cyber-attacks, security incidents, and vulnerabilities discovered.


FortiGuard Labs urges all users of SimpleHelp to upgrade to the latest available version as soon as possible, if not done already.

FortiGuard Cybersecurity Framework

Mitigate security threats and vulnerabilities by leveraging the range of FortiGuard Services.


PROTECT
  • Lure

  • Decoy VM

  • AV

  • Vulnerability

  • IPS

DETECT
  • IOC

  • Outbreak Detection

RESPOND
  • Automated Response

  • Assisted Response Services

RECOVER
  • NOC/SOC Training

  • End-User Training

IDENTIFY
  • Vulnerability Management

  • Attack Surface Hardening

Threat Intelligence

Information gathered from analyzing ongoing cybersecurity events including threat actors, their tactics, techniques, and procedures (TTPs), indicators of compromise (IOCs), malware and related vulnerabilities.