logo

Clop Ransomware Group Exploiting Gladinet CentreStack Servers to Steal Data

ID: 7a9c072f-5954-507a-a5ff-c93cb9087d92

STIX ID: report--7a9c072f-5954-507a-a5ff-c93cb9087d92

Feed Name: cybersecurityNews.com

Threat Score
85/100

Date Published: 2025-12-19

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

**Clop is actively exploiting CentreStack/Triofox (CVE-2025-11371 and CVE-2025-14611) to obtain machine keys via an LFI endpoint, perform ViewState deserialization for RCE, forge persistent access tickets and exfiltrate data; organizations should update to version 16.12.10420.56791, rotate machine keys, and review web logs for suspicious GET requests containing the encrypted Web.config path.**

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.