logo

Clop ransomware targets Gladinet CentreStack in data theft attacks

ID: e610e0b4-2b95-52e3-b967-c0c079765c06

STIX ID: report--e610e0b4-2b95-52e3-b967-c0c079765c06

Feed Name: Bleeping Computer

Threat Score
78/100

Date Published: 2025-12-18

Date Updated: 2026-07-17

Author: Sergiu Gatlan

...
...

Clop (Cl0p) is actively targeting Internet-facing Gladinet CentreStack file servers in a new data-theft extortion campaign, scanning for exposed instances, breaching systems, and leaving ransom notes after exfiltrating files; the exploited vulnerability is currently unknown and may be an n-day or zero-day. The report frames this activity within Clop's history of high-impact breaches of file-transfer products (e.g., MOVEit, Accellion, Oracle EBS) and notes potential broad exposure of CentreStack instances.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.