logo

Clop Ransomware Group Exploits New 0-Day Vulnerabilities in Active Attacks

ID: 9c499123-dfcf-53c6-ab29-35d6eab649bc

STIX ID: report--9c499123-dfcf-53c6-ab29-35d6eab649bc

Feed Name: GBHackers

Threat Score
88/100

Date Published: 2025-11-05

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

The report describes active exploitation of a critical Oracle E-Business Suite zero-day (CVE-2025-61882) by the Clop ransomware group, documents infrastructure and SSL-fingerprint reuse linking current activity to prior MOVit and GoAnywhere campaigns, and shares IOCs and geographic distribution data to highlight the group's scale and operational persistence.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.