216.73.217.22

Not-so-SimpleHelp exploits enabling deployment of Sliver backdoor

· Published 07/02/2025 00:08 · Modified 07/02/2025 08:22

Export JSON

Essential information

Published
07/02/2025 00:08
Modified
07/02/2025 08:22
Tags
2025-02-07 akira backdoor cloudflared exploit lateral movement rmm simplehelp sliver
Related entities
6 observables, 19 techniques (mitre), 1 malware, 3 others

Description

A sophisticated breach was identified where threat actors exploited vulnerabilities in 's Remote Monitoring and Management client to infiltrate a network. The attack involved post-compromise tactics including network discovery, administrator account creation, and persistence establishment. The threat actor connected via a vulnerable client, executed discovery commands, created a new admin account, and installed a . The was configured to connect to specific IP addresses. On the domain controller, a tunnel was installed for potential further payload deployment. The attack's TTPs resembled those of the Ransomware group. A previous incident involving exploitation was also confirmed. Organizations are urged to update their clients and adopt robust cybersecurity solutions.

External references