Online-Erpresserbande Clop bedroht Cleo-Hacking-Opfer

Teilen:

The Clop cybercriminal group is threatening to make public the companies swept up by its mass hacking of managed file-transfer software built by Cleo Communications.

See Also: Live Webinar | North Korea’s Secret IT Army and How to Combat It

Clop, aka Cl0p, a ransomware extortion organization believed to be based in Russia, took responsibility earlier this month for mass attacks targeting Harmony, VLTrader and LexiCom MFT software built by Rockford, Illinois-based Cleo (see: Clop Ransomware Takes Responsibility for Cleo Mass Exploits).

In a Dec. 24 update to its dark web leak site, Clop asserted it has “data of many companies who use Cleo” and that it will publish within 48 hours a list of at least 66 companies it hacked. The criminal gang said it is contacting the companies with extortion instructions after already publishing the first five characters in their names.

Cleo hurried a patch out to users on Dec. 11 following signs of mass exploitation. Hackers appeared to be exploiting an unrestricted file upload vulnerability in the managed file transfer tracked as CVE-2024-50623, for which a patch published in October apparently did not fully prevent hacks. Analysis by Rapid7 suggested hackers might have used a new file-write vulnerability, CVE-2024-55956, for writing a malicious host file to the targeted system and then exploiting CVE-2024-50623 to obtain needed credentials and force the system to run the malicious host file, which allows them to remotely execute code.

Cleo has told customers it “strongly advises” them to immediately apply the latest fix.

How long attackers have been exploiting one or both flaws remains unclear. “The campaign began on Dec. 7, and is ongoing as of the publication of this article,” Arctic Wolf said in a Thursday blog post.

Clop is no stranger to mass zero-day exploitation of file transfer software. The group launched a carefully prepared attack against MOVEit software that unfolded over the U.S. Memorial Day weekend in 2023. The count of organizations affected directly or indirectly by the MOVEit incident stands at over 2,770, with data pertaining to more than 95 million individuals exposed, calculates security firm Emsisoft.

Earlier in 2023, Clop took responsibility for a large-scale attack campaign that exploited a zero-day vulnerability to steal data from customers of Fortra’s widely used managed file transfer software GoAnywhere MFT. In December 2020, it targeted zero-day flaws in the Accellion File Transfer Appliance in another global attack campaign.

Quelle

Kommentar verfassen

Deine E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert

lade-bild
London, GB
1:52 am, Juni 10, 2025
Wetter-Symbol 14°C
L: 13° | H: 15°
broken clouds
Luftfeuchtigkeit: 79 %
Druck: 1017 mb
Wind: 14 mph WSW
Windböe: 0 mph
UV-Index: 0
Niederschlag: 0 mm
Wolken: 75%
Regen Chance: 0%
Sichtbarkeit: 10 km
Sonnenaufgang: 4:43 am
Sonnenuntergang: 9:16 pm
TäglichStündlich
Tägliche VorhersageStündliche Vorhersage
Today 10:00 pm
Wetter-Symbol
13° | 15°°C 0.31 mm 31% 11 mph 84 % 1021 mb 0 mm/h
Tomorrow 10:00 pm
Wetter-Symbol
13° | 24°°C 0 mm 0% 11 mph 91 % 1021 mb 0 mm/h
Do. Juni 12 10:00 pm
Wetter-Symbol
14° | 25°°C 0 mm 0% 11 mph 75 % 1017 mb 0 mm/h
Fr. Juni 13 10:00 pm
Wetter-Symbol
16° | 28°°C 1 mm 100% 12 mph 93 % 1020 mb 0 mm/h
Sa. Juni 14 10:00 pm
Wetter-Symbol
18° | 27°°C 1 mm 100% 8 mph 96 % 1019 mb 0 mm/h
Today 4:00 am
Wetter-Symbol
14° | 15°°C 0 mm 0% 11 mph 81 % 1017 mb 0 mm/h
Today 7:00 am
Wetter-Symbol
15° | 15°°C 0 mm 0% 10 mph 84 % 1016 mb 0 mm/h
Today 10:00 am
Wetter-Symbol
17° | 17°°C 0 mm 0% 10 mph 84 % 1017 mb 0 mm/h
Today 1:00 pm
Wetter-Symbol
20° | 20°°C 0.31 mm 31% 9 mph 66 % 1017 mb 0 mm/h
Today 4:00 pm
Wetter-Symbol
21° | 21°°C 0.21 mm 21% 10 mph 54 % 1018 mb 0 mm/h
Today 7:00 pm
Wetter-Symbol
20° | 20°°C 0 mm 0% 4 mph 52 % 1019 mb 0 mm/h
Today 10:00 pm
Wetter-Symbol
16° | 16°°C 0 mm 0% 4 mph 65 % 1021 mb 0 mm/h
Tomorrow 1:00 am
Wetter-Symbol
14° | 14°°C 0 mm 0% 4 mph 77 % 1021 mb 0 mm/h
Name Preis24H (%)
Bitcoin(BTC)
€96,467.01
4.20%
Ethereum(ETH)
€2,375.73
8.31%
Fesseln(USDT)
€0.88
-0.01%
XRP(XRP)
€2.03
2.34%
Solana(SOL)
€140.96
5.49%
USDC(USDC)
€0.88
0.00%
Dogecoin(DOGE)
€0.171247
6.32%
Shiba Inu(SHIB)
€0.000011
5.39%
Pepe(PEPE)
€0.000011
10.16%
Peanut das Eichhörnchen(PNUT)
€0.259065
13.22%
Nach oben scrollen