SimpleHelp RMM (versions prior to the patched release)
SimpleHelp is a remote support and monitoring tool used by IT teams and managed service providers to access and manage computers remotely.
Root Cause
The flaw exists in SimpleHelp's authentication layer, which fails to properly verify that a request comes from a legitimate, credentialed user before granting access. An attacker can craft a request that bypasses this check entirely. Think of it like a staff entrance that checks for a badge but accepts a blank card.
Attack Vector
An attacker sends a specially crafted request to an exposed SimpleHelp server. The server skips credential validation and grants access. The attacker then deploys Djinn Stealer, which harvests credentials for cloud platforms, source control systems, package registries, and AI development tools across Windows, macOS, and Linux.
Detection Notes
- Unexpected new processes or files appearing on machines managed via SimpleHelp
- Outbound connections to unfamiliar hosts from the SimpleHelp server process
- Credential alerts from cloud platforms shortly after SimpleHelp activity
Recommended Actions
- Apply the vendor patch immediately — check the official SimpleHelp advisory
- Restrict SimpleHelp server access to trusted IP ranges only
- Audit logs for unauthorised access attempts against your SimpleHelp instance

