Desk live·
ForensicPost
Ransomware/Third party/File 25-0601b

They Used the Tool the Provider Used to Manage Everyone

The DragonForce operation breached a managed service provider and used its remote monitoring platform to reach downstream customers, exploiting a chain of vulnerabilities disclosed the previous year.

Constructed geometry · not a chart of case data
TargetManaged service provider
ActorDragonForce
D. Kennedy12 min readConfidence: high2 sources reviewed

The DragonForce ransomware operation breached a managed service provider and used its SimpleHelp remote monitoring and management platform to steal data and deploy encryptors on downstream customer systems. Investigators assess that a chain of vulnerabilities tracked as CVE-2024-57726, CVE-2024-57727 and CVE-2024-57728 was used to reach the provider.

The MSP Is The Answer To The Small-Firm Problem

This desk filed at 25-0612b that a third of small businesses could not absorb a $10,000 loss, and at 25-0616b that what such organisations need is not an obligation but capability they cannot build.

A managed service provider is that capability. It gives a twenty-person firm patching, monitoring, backup and a helpdesk it could never staff — genuinely better security than the alternative, which is nothing.

It also gives one organisation administrative access to every customer at once. The corpus has recorded this trade repeatedly — a shared platform gives a small district professional-grade software it could never build, at 25-0105 — and here the second half arrived.

Remote Management Is The Highest-Value Target Class In This Database

Ground-station links at 25-0623. A support portal at 25-0105. A backup service holding every customer’s firewall configuration at 25-0917. An integration reaching seven hundred environments at 25-0818. Connected applications at 25-1121b.

Each is the mechanism by which a small team operates a large estate, and each concentrates reach accordingly. An RMM platform is the purest example: its entire purpose is executing commands on other people’s computers.

The Identifiers Carry The Year

CVE-2024-57726, -57727 and -57728, exploited in 2025. This desk drew the distinction at 25-1107b between zero-days, where the customer could do nothing, and known defects with available fixes.

This is the second category, and it lands on an organisation whose product is keeping other people patched.

How we reported this

Compiled from published vendor research, listed below. The provider and its customers are not named. Attribution follows the investigating vendor’s assessment. Corrections: corrections@forensicpost.com.

Sources
  1. DragonForce ransomware abuses SimpleHelp in MSP supply chain attackBleepingComputer
  2. Most notable supply-chain attacks of 2025Kaspersky
D. Kennedy
Identity and access reporter. Former DFIR consultant. Signal on request.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary