RMM
SimpleHelp
SimpleHelp is a remote monitoring and management (RMM) tool. It has been observed being abused by threat actors as a persistence and remote-access vector during ransomware operations, including campaigns delivering the "Crazy" ransomware (VoidCrypt family) reported by Huntress in February 2026.
Tool overview
- Category
- RMM
- Research authors
- Not recorded
- Created
- 2024-08-02
- Last modified
- 2026-05-04
- Privileges
- Not recorded
- Free / availability
- Not recorded
- Verification required
- Not recorded
- Supported platforms
Windows
Executables & installation paths
- Filename
- Not recorded
- OriginalFileName
- Not recorded
- Description
- Not recorded
Installation paths
simplehelpcustomer.exe
simpleservice.exe
simplegatewayservice.exe
remote access.exe
windowslauncher.exe
spsrv.exe
serviceconfig.xml
C:\ProgramData\JWrapper-Remote Access\*
%APPDATA%\JWrapper-SimpleSetup\*
vhost.exe
Code signing
- signer name
- SimpleHelp Ltd
- certificate thumbprint
- 40F61D013FE82F45E7B01D040B4653E8AE80E041
- src file sha256
- 77b8f597b7d20d4f7ae84caa5c22b94a8d9e09051f7cdaa17f41890ccf8c77a2
- src file path
- downloaded_files/simplehelp/77b8f597b7d20d4f7ae84caa5c22b94a8d9e09051f7cdaa17f41890ccf8c77a2
- src file company
- SimpleHelp Ltd
FORENSIC EVIDENCE
Disk artifacts
- File
- C:\ProgramData\JWrapper-Remote Access\
- Description
- Default SimpleHelp "Remote Access" service installation directory observed in Huntress reporting on Crazy ransomware operations.
- OS
- Windows
- File
- %APPDATA%\JWrapper-SimpleSetup\
- Description
- SimpleHelp customer-side setup/wrapper directory dropped by the SimpleSetup installer (e.g. windowslauncher.exe, SimpleSetupECompatibility.exe).
- OS
- Windows
FORENSIC EVIDENCE
Registry artifacts
- Path
- HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\SimpleSetup
- Description
- Uninstall key written by the SimpleHelp SimpleSetup installer; URLUpdateInfo points to https://www.simple-help.com/media/static/SimpleSetup/.
FORENSIC EVIDENCE
Network artifacts
- Description
- Known remote domains
- Domains
- user_managed
- simple-help.com
- 51.255.19.178
- 51.255.19.179
- Ports
- 443
- Description
- Threat-actor-controlled SimpleHelp / Net Monitor infrastructure observed by Huntress during the "Crazy" (VoidCrypt) ransomware campaign documented in February 2026. NOT vendor-legitimate — these are attacker-operated SimpleHelp gateways and update servers.
- Domains
- dronemaker.org
- telesupportgroup.com
- microuptime.com
- 192.144.34.42
- 160.191.182.41
- Ports
- 443
Detections
- Sigma
- https://github.com/magicsword-io/LOLRMM/blob/main/detections/sigma/simplehelp_network_sigma.yml
- Description
- Detects potential network activity of SimpleHelp RMM tool
- Sigma
- https://github.com/magicsword-io/LOLRMM/blob/main/detections/sigma/simplehelp_processes_sigma.yml
- Description
- Detects potential processes activity of SimpleHelp RMM tool
References
- https://simple-help.com/remote-support
- https://www.huntress.com/blog/employee-monitoring-simplehelp-abused-in-ransomware-operations
- https://www.huntress.com/blog/slashandgrab-screen-connect-post-exploitation-in-the-wild-cve-2024-1709-cve-2024-1708
- https://www.group-ib.com/blog/muddywater-infrastructure/
Acknowledgements
- Person
- KapAttack133
- Handle
- KapAttack133
- Person
- Phyo Paing Htun
- Handle
- Not recorded