216.73.216.6

Protecting Against the Exploited CVEs in the Cleo Data Theft Attacks

· Published 22/01/2025 14:41 · Modified 22/01/2025 18:17

Export JSON

Essential information

Published
22/01/2025 14:41
Modified
22/01/2025 18:17
Tags
2025-01-22 CVE-2024-50623 CVE-2024-55956 clop data theft extortion file transfer persistence powershell ransomware
Related entities
2 observables, 1 intrusion sets (apt), 11 techniques (mitre), 1 malware, 4 others

Description

The group has exploited critical vulnerabilities in Cleo's managed software, specifically and . These vulnerabilities allow unrestricted file upload/download and execution of arbitrary commands. Imperva has observed over 1 million exploitation attempts targeting nearly 10,000 sites across 60 countries, with a focus on the United States and Australia. Financial Services and Government sectors are primary targets. The attack involves a first-stage dropper file that invokes a script to retrieve JAR files for . 's tactics include targeting backup systems, encrypting files, and exfiltrating data for . The group has previously exploited vulnerabilities in other programs, potentially earning over $75 million in ransoms.

External references