SimpleHelp is a legitimate remote monitoring and management (RMM) platform used by IT teams and managed service providers that threat actors abuse as a remote access trojan. It provides interactive remote control, monitoring, and script execution, enabling attackers to execute commands, deploy additional tooling, and maintain persistent access. Malicious deployments are documented on Windows, and Linux remote-access packages have also appeared in attacker-controlled tooling collections.
Attackers distribute preconfigured SimpleHelp clients through phishing and spearphishing, using invitation, document-signing, tax, Social Security, and software-installer lures. Spoofed document portals persuade victims to download and execute installers. SimpleHelp is also deployed after exploitation of internet-facing services or by existing droppers, backdoors, and remote-access tools. Its self-contained clients commonly use JWrapper, which bundles the application and Java runtime, and can embed connection configuration for attacker-controlled management servers.
SimpleHelp abuse includes installation as a persistent Windows service, command execution through PowerShell, and deployment of additional RMM agents such as ScreenConnect to provide redundant access. Observed deployments have modified firewall rules and filesystem permissions. Attackers have also executed commands through SimpleHelp to tamper with Microsoft Defender. Its legitimate signed binaries help malicious activity blend with authorized administration; some tampered installers have retained valid signatures by placing additional data in unauthenticated Authenticode attributes.
SimpleHelp has been used by the Iranian state-sponsored actor MuddyWater and the North Korea-aligned actor Konni, and in intrusions associated with Play, Medusa, and ALPHV/BlackCat ransomware. It has also appeared in cyber-enabled cargo-theft campaigns targeting trucking carriers and freight brokers. These activities represent malicious use of a commercial administration product rather than a single coordinated malware campaign.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
5 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Unknown threat actors were observed exploiting CVE-2026-5027 against canary systems to drop a Python credential harvester, proxy agents, and SimpleHelp for remote access. | Unknown threat actors were observed exploiting CVE-2026-5027 to drop a Python credential harvester, proxy agents, and SimpleHelp for remote access.
CVE-2025-31161 is a 9.8 CVSS critical severity vulnerability that affects how the CrushFTP file transfer application handles user authentication... CrushFTP versions 10.0.0 through 10.8.3 and 11.0.0 through 11.3.0 are affected by a vulnerability in the S3 authorization header processing that allows authentication bypass.
Initial Access Exploitation of React2Shell (CVE-2025-55182) against crypto staking platforms... We observed this threat actor perform mass scanning to identify targets vulnerable to React2Shell...
“the Cofense Phishing Defense Center (PDC) identified multiple samples using the SimpleHelp Remote Monitoring and Management (RMM) tool… JWrapper-wrapped SimpleHelp is increasingly abused by threat actors as a stealthy Remote Access Trojan (RAT).”
Arctic Wolf has issued a warning regarding CVE-2026-1731, a nearly maximum-severity flaw (CVSS 9.9) in self-hosted BeyondTrust Remote Support and Privileged Remote Access environments... allows unauthenticated attackers to execute operating system commands... added to CISA’s Known Exploited Vulnerabilities (KEV) Catalog... threat actors using the exploit to deploy SimpleHelp...
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
...TA450 historically using several RMM tools, such as Atera, PDQ Connect, ScreenConnect, and SimpleHelp...
"To maintain persistence, they abused remote monitoring and management (RMM) tools, specifically SimpleHelp and MeshAgent."
16 distinct techniques documented for this family, organized by ATT&CK tactic.
T1078 (Valid Accounts) - атакующий использует trial или free аккаунт вендора как валидную учётную запись
the host held a seven-tool remote monitoring and management (RMM) arsenal for persistence, including ScreenConnect and SimpleHelp
The attackers also used some typical commands related to the Impacket WMIExec hacktool... During that intrusion, it’s believed the attackers used WMI to launch the SimpleHelp installer on the victim network.
MITRE ATT&CK techniques Tactic ID Technique Resource Development T1583.001 Acquire Infrastructure: Domains Initial Access T1189 Drive-by Compromise Initial Access T1566.002 Phishing: Spearphishing Link Execution T1204.002 User Execution: Malicious File Execution T1059.003 Command and Scripting Interpreter: Windows Command Shell Execution T1059.001 Command and Scripting Interpreter: PowerShell
MITRE ATT&CK techniques Tactic ID Technique Resource Development T1583.001 Acquire Infrastructure: Domains Initial Access T1189 Drive-by Compromise Initial Access T1566.002 Phishing: Spearphishing Link Execution T1204.002 User Execution: Malicious File Execution T1059.003 Command and Scripting Interpreter: Windows Command Shell Execution T1059.001 Command and Scripting Interpreter: PowerShell Persistence T1543.003 Create or Modify System Process: Windows Service Defense Evasion T1553.002 Subvert Trust Controls: Code Signing
77 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
23 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Legitimate remote-support and system-management software weaponized to obtain remote control, monitoring, and script-execution capabilities. The report shows phishing-based distribution and notes that the server address is stored as hexadecimal data in the sg_servers configuration entry.
A legitimate remote support and management product referenced as being installed after host profiling by a dropper.
A legitimate remote-support tool abused by attackers to provide remote access to a compromised host.
A legitimate RMM/remote-support tool abused as an already-resident remote-access channel and delivery mechanism for ScreenConnect. In the deepest case it provided unattended access, scripting, persistence, and a PowerShell cradle to silently download and install ScreenConnect.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.