Ransomware Groups Medusa and DragonForce Exploit RMM Tools in 2025 Attacks
First seen 11 Nov 2025, 11:18 UTC
•
•52
Export
Article Content
Browse articles
In 2025, ransomware groups Medusa and DragonForce targeted UK organizations by exploiting vulnerabilities in the SimpleHelp Remote Monitoring and Management platform. They leveraged three critical vulnerabilities (CVE-2024-57726, CVE-2024-57727, CVE-2024-57728) to gain unauthorized access through trusted third-party vendors and Managed Service Providers.
Ask AI about this cluster
Answers cite the sources they use
Analyzing cluster data...
Referenced clusters
Something went wrong. Please try again.
More articles in this cluster
Continue Reading
CISA Alerts on Critical Flaws in SimpleHelp, Samsung MagicINFO, and D-Link Devices
DragonForce Ransomware Cartel Emerges as Major Threat in Cybersecurity
Teen Hacker Extradited for Role in Scattered Spider Cybercrime Group
DragonForce Ransomware Exploits Microsoft Teams for Covert C2 Communications
Scattered Spider Reclassified as Decentralized Cybercrime Collective
Payroll Pirate Campaign Targets Payroll Systems Using AiTM Session Hijacking