logo

Threat Campaign Targeting Cleo MFT Products - Remediation Guidance

ID: 5596f92c-93c4-54be-9914-0a6ef0489c90

STIX ID: report--5596f92c-93c4-54be-9914-0a6ef0489c90

Feed Name: Arctic Wolf Blog

Threat Score
75/100

Date Published: 2024-12-10

Date Updated: 2026-04-27

...
...

Arctic Wolf Labs observed an active campaign (first indications Oct 19, spike in Dec 2024) targeting Cleo MFT products (Harmony, VLTrader, LexiCom), where threat actors are suspected to leverage a remote code execution vulnerability (CVE-2024-50623) or similar flaws to run malicious PowerShell via the Autorun feature, drop and execute JAR payloads, and perform system reconnaissance; the bulletin provides detection context, mitigation steps (patching, disabling/hardening Autorun), and a list of suspicious files/IOCs to remove.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.