logo

Cleo MFT Zero-Day Exploits Are About Escalate, Analysts Warn

ID: 31227569-c33e-5c2a-9605-5a95d02797b5

STIX ID: report--31227569-c33e-5c2a-9605-5a95d02797b5

Feed Name: Dark Reading

Threat Score
85/100

Date Published: 2024-12-13

Date Updated: 2026-04-21

Author: Becky Bracken, Senior Editor, Dark Reading

...
...

An active ransomware campaign is exploiting an insufficiently patched zero-day (CVE-2024-50623) in Cleo managed file transfer products; a public proof-of-concept and active intrusions (at least 10 customers) have been reported. The attack chain uses a PowerShell stager to deploy a Java-based 'Cleopatra' backdoor (cross-platform) linked to the 'Termite' ransomware group, and patching confusion has left many instances exposed, raising the risk of widespread mass exploitation similar to MOVEit incidents.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.