logo

Cleo Vulnerabilities Targeted by Cl0p Ransomware (Campaign)

ID: bac2f9f0-7be5-5b96-97cb-eefe86a7e431

STIX ID: report--bac2f9f0-7be5-5b96-97cb-eefe86a7e431

Feed Name: Wiz Cloud Threat Landscape

Threat Score
88/100

Date Published: 2024-12-15

Date Updated: 2026-05-01

Author: [email protected] (Wiz Threat Research)

...
...

Multiple critical vulnerabilities in Cleo file transfer products (CVE-2024-50623 and CVE-2024-55956) were actively exploited in the wild by the Clop ransomware group to upload Java-based backdoors, execute arbitrary commands, perform reconnaissance and privilege escalation (including OverPass-The-Hash), exfiltrate sensitive data, and deploy ransomware and Cobalt Strike beacons; initial patches were incomplete and threat actors bypassed fixes to continue attacks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.