DragonForce Ransomware Gang Hijacks MSP Tool to Infiltrate Multiple Customer Networks


# DragonForce Ransomware Exploits MSP Tool in Sophisticated Supply Chain Attack

DragonForce ransomware operators have successfully compromised an unnamed Managed Service Provider (MSP) by exploiting vulnerabilities in the SimpleHelp remote monitoring and management tool. According to Sophos analysis, the attackers leveraged three security flaws in SimpleHelp (CVE-2024-57727, CVE-2024-57728, and CVE-2024-57726) disclosed in January 2025 to gain access to the MSP’s deployment.

The attack was discovered after suspicious installation of a SimpleHelp installer file was pushed through the legitimate RMM instance operated by the MSP. Threat actors collected extensive information from customer environments, including device configurations, user data, and network connections. While one client managed to block the attackers, numerous downstream customers suffered data theft and ransomware attacks, leading to double-extortion attempts.

This MSP supply chain attack highlights DragonForce’s evolution into a ransomware “cartel” with a novel affiliate branding model that allows cybercriminals to create their own versions under different names. The group’s emergence coincided with defacements of BlackLock and Mamona ransomware leak sites and an apparent hostile takeover of RansomHub.

Recent attacks targeting UK retailers have brought increased attention to DragonForce, with evidence suggesting collaboration with Scattered Spider, a group known for cloud-first, identity-centric intrusion methods. Despite arrests of alleged members in 2024, Scattered Spider remains mysterious, particularly regarding recruitment of young hackers from the UK and US.

The ransomware landscape is increasingly volatile, with groups fragmenting, decentralizing, and battling low affiliate loyalty. The growing use of AI in malware development further complicates the threat landscape.

In related developments, multiple groups including 3AM ransomware are combining email bombing and vishing techniques to breach networks by posing as tech support and using Microsoft Quick Assist to gain remote access. These attacks deploy QDoor, a network tunneling backdoor previously seen in Blacksuit and Lynx ransomware operations.

Security experts recommend prioritizing employee awareness, limiting remote access, blocking execution of virtual machines and remote access software on unauthorized computers, and restricting network traffic associated with remote control.

Share This Article