Clop ransomware claims responsibility for Cleo data theft attacks
ID: 033d0d1c-aee4-51b7-a6ca-2fa8506d8b42
STIX ID: report--033d0d1c-aee4-51b7-a6ca-2fa8506d8b42
Feed Name: Bleeping Computer
Clop has claimed responsibility for recent data-theft attacks exploiting two Cleo managed-file-transfer zero-days (CVE-2024-50623 and CVE-2024-55956) that allowed unauthenticated file writes and remote code execution; attackers deployed a Java backdoor called Malichus to steal data and move laterally. Multiple vendors and researchers (Huntress, Rapid7) and CISA have confirmed exploitation in the wild, fixes have been released for Cleo products, and Clop continues to post extortion content while stating it will delete some previously posted data.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
