Cleo Vulnerabilities Targeted by Cl0p Ransomware (Campaign)
ID: bac2f9f0-7be5-5b96-97cb-eefe86a7e431
STIX ID: report--bac2f9f0-7be5-5b96-97cb-eefe86a7e431
Feed Name: Wiz Cloud Threat Landscape
Date Published: 2024-12-15
Date Updated: 2026-05-01
Author: [email protected] (Wiz Threat Research)
Multiple critical vulnerabilities in Cleo file transfer products (CVE-2024-50623 and CVE-2024-55956) were actively exploited in the wild by the Clop ransomware group to upload Java-based backdoors, execute arbitrary commands, perform reconnaissance and privilege escalation (including OverPass-The-Hash), exfiltrate sensitive data, and deploy ransomware and Cobalt Strike beacons; initial patches were incomplete and threat actors bypassed fixes to continue attacks.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
