logo

Clop is back to wreak havoc via vulnerable file-transfer software

ID: a4ada8b6-53c0-5074-9996-7558ed040cdf

STIX ID: report--a4ada8b6-53c0-5074-9996-7558ed040cdf

Feed Name: CyberScoop

Threat Score
78/100

Date Published: 2024-12-17

Date Updated: 2026-04-21

Author: Greg Otto

...
...

Clop-affiliated threat actors have actively exploited critical vulnerabilities in Cleo’s LexiCom, VLTrader, and Harmony file-transfer products (notably CVE-2024-50623 and CVE-2024-55956), leading to confirmed compromises, published stolen data on a leak site, and vendor patches; multiple security firms (Huntress, Rapid7) and CISA report active exploitation and potential post-compromise activity consistent with extortion/ransomware tactics, raising concern given Clop’s prior large-scale MOVEit campaign.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.