logo

Clop ransomware claims responsibility for Cleo data theft attacks

ID: 033d0d1c-aee4-51b7-a6ca-2fa8506d8b42

STIX ID: report--033d0d1c-aee4-51b7-a6ca-2fa8506d8b42

Feed Name: Bleeping Computer

Threat Score
88/100

Date Published: 2024-12-15

Date Updated: 2026-03-27

Author: Lawrence Abrams

...
...

Clop has claimed responsibility for recent data-theft attacks exploiting two Cleo managed-file-transfer zero-days (CVE-2024-50623 and CVE-2024-55956) that allowed unauthenticated file writes and remote code execution; attackers deployed a Java backdoor called Malichus to steal data and move laterally. Multiple vendors and researchers (Huntress, Rapid7) and CISA have confirmed exploitation in the wild, fixes have been released for Cleo products, and Clop continues to post extortion content while stating it will delete some previously posted data.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.