RMM

SimpleHelp

SimpleHelp is a remote monitoring and management (RMM) tool. It has been observed being abused by threat actors as a persistence and remote-access vector during ransomware operations, including campaigns delivering the "Crazy" ransomware (VoidCrypt family) reported by Huntress in February 2026.

Tool overview

Category
RMM
Research authors
Not recorded
Created
2024-08-02
Last modified
2026-05-04
Privileges
Not recorded
Free / availability
Not recorded
Verification required
Not recorded
Supported platforms
Windows

Executables & installation paths

Filename
Not recorded
OriginalFileName
Not recorded
Description
Not recorded

Installation paths

simplehelpcustomer.exe
simpleservice.exe
simplegatewayservice.exe
remote access.exe
windowslauncher.exe
spsrv.exe
serviceconfig.xml
C:\ProgramData\JWrapper-Remote Access\*
%APPDATA%\JWrapper-SimpleSetup\*
vhost.exe

Code signing

signer name
SimpleHelp Ltd
certificate thumbprint
40F61D013FE82F45E7B01D040B4653E8AE80E041
src file sha256
77b8f597b7d20d4f7ae84caa5c22b94a8d9e09051f7cdaa17f41890ccf8c77a2
src file path
downloaded_files/simplehelp/77b8f597b7d20d4f7ae84caa5c22b94a8d9e09051f7cdaa17f41890ccf8c77a2
src file company
SimpleHelp Ltd

FORENSIC EVIDENCE

Disk artifacts

File
C:\ProgramData\JWrapper-Remote Access\
Description
Default SimpleHelp "Remote Access" service installation directory observed in Huntress reporting on Crazy ransomware operations.
OS
Windows
File
%APPDATA%\JWrapper-SimpleSetup\
Description
SimpleHelp customer-side setup/wrapper directory dropped by the SimpleSetup installer (e.g. windowslauncher.exe, SimpleSetupECompatibility.exe).
OS
Windows

FORENSIC EVIDENCE

Registry artifacts

Path
HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\SimpleSetup
Description
Uninstall key written by the SimpleHelp SimpleSetup installer; URLUpdateInfo points to https://www.simple-help.com/media/static/SimpleSetup/.

FORENSIC EVIDENCE

Network artifacts

Description
Known remote domains
Domains
  • user_managed
  • simple-help.com
  • 51.255.19.178
  • 51.255.19.179
Ports
  • 443
Description
Threat-actor-controlled SimpleHelp / Net Monitor infrastructure observed by Huntress during the "Crazy" (VoidCrypt) ransomware campaign documented in February 2026. NOT vendor-legitimate — these are attacker-operated SimpleHelp gateways and update servers.
Domains
  • dronemaker.org
  • telesupportgroup.com
  • microuptime.com
  • 192.144.34.42
  • 160.191.182.41
Ports
  • 443

Detections

Sigma
https://github.com/magicsword-io/LOLRMM/blob/main/detections/sigma/simplehelp_network_sigma.yml
Description
Detects potential network activity of SimpleHelp RMM tool
Sigma
https://github.com/magicsword-io/LOLRMM/blob/main/detections/sigma/simplehelp_processes_sigma.yml
Description
Detects potential processes activity of SimpleHelp RMM tool

References

Acknowledgements

Person
KapAttack133
Handle
KapAttack133
Person
Phyo Paing Htun
Handle
Not recorded