Summary

A critical authentication bypass vulnerability in SimpleHelp (CVE-2026-48558), a popular remote monitoring and management (RMM) platform, is being actively exploited to deploy “Djinn Stealer” — a previously undocumented cross-platform information stealer targeting Windows, macOS, and Linux systems.

The vulnerability allows attackers to create highly privileged technician accounts on SimpleHelp instances without any authentication, effectively turning the RMM platform into a malware delivery mechanism. Once inside, the Djinn Stealer specifically targets cloud credentials, AI API keys, and developer tokens — a focus that reflects the high value of cloud and AI infrastructure access in today’s threat landscape.

The campaign is notable for its cross-platform reach and its laser focus on modern credential types. Rather than going after traditional banking credentials or browser passwords, Djinn Stealer prioritizes AWS keys, Azure tokens, OpenAI/Anthropic API keys, and cloud service account credentials — the keys to kingdom in cloud-native and AI-dependent organizations.

Sources

Commentary

RMM tools have become prime targets because they’re effectively pre-authorized backdoors into entire fleets of managed machines. SimpleHelp, ConnectWise, Kaseya — the pattern keeps repeating. But what makes Djinn Stealer interesting is its targeting profile. This isn’t commodity malware going after browser cookies — it’s purpose-built to harvest the credentials that matter most in 2026: cloud infrastructure and AI platform keys.

The cross-platform design (Windows, macOS, Linux) and the auth bypass entry point make this a particularly dangerous combination. If you’re running SimpleHelp, patch immediately. If you’re an MSP or IT shop using any RMM tool, audit your instance’s exposure and enforce MFA on technician accounts — assuming the vulnerability even respects authentication boundaries.

By Allan