The Clop ransomware gang has confirmed that they are responsible for the recent data-theft attacks targeting Cleo’s file transfer platforms. These attacks utilized zero-day exploits to infiltrate corporate networks and steal sensitive data.
Cleo, known for its managed file transfer solutions like Cleo Harmony, VLTrader, and LexiCom, provides secure file exchange services to businesses and their partners. In October, Cleo addressed a vulnerability (CVE-2024-50623) that allowed unrestricted file uploads and downloads, which could lead to remote code execution.
However, cybersecurity firm Huntress discovered last week that the patch for the vulnerability was incomplete, and cybercriminals were exploiting a bypass to continue their data theft operations. The attackers used a JAVA backdoor to facilitate data exfiltration, execute remote commands, and further compromise the breached networks.
CISA confirmed that the CVE-2024-50623 flaw in Cleo’s file transfer software had been exploited in recent ransomware attacks. Cleo, however, did not publicly acknowledge the exploitation of the flaw following their October patch.
Initially, it was believed that the attacks on Cleo were carried out by a new ransomware group called Termite. However, the tactics, techniques, and procedures (TTPs) observed in the attacks were consistent with previous campaigns attributed to the Clop ransomware gang.
However, now Clop confirmed that they were behind the recent exploitation of both the CVE-2024-50623 vulnerability and the original flaw that Cleo patched in October. Clop also stated they were removing data linked to previous victims from their leak server, signaling a shift to working only with companies affected by the Cleo breaches.
The Clop ransomware group, also known as TA505 and Cl0p, has been active since March 2019. Initially, the group targeted corporate networks with a variant of CryptoMix ransomware, spreading laterally across systems to steal data before deploying encryption.
Since 2020, however, Clop has increasingly focused on exploiting vulnerabilities in secure file transfer platforms to conduct data theft.
Their most significant attack to date occurred with the MOVEit Transfer platform, where Clop exploited a zero-day vulnerability to steal data from 2,773 organizations, according to a report by Emsisoft.
It is unclear how many organizations have been affected by the Cleo data theft attacks, and no companies have yet publicly confirmed being breached via Cleo’s platform. The U.S. State Department’s Rewards for Justice program has offered a $10 million reward for information linking Clop’s ransomware activities to foreign governments.















Comments