logo

CL0P Ransomware Group Targets Gladinet CentreStack in New Campaign

ID: f9f83cc0-e7d7-5df0-a93b-31045c87dd32

STIX ID: report--f9f83cc0-e7d7-5df0-a93b-31045c87dd32

Feed Name: The Cyber Express

Threat Score
75/100

Date Published: 2025-12-19

Date Updated: 2026-04-23

Author: Paul Shread

...
...

CL0P appears to be staging an extortion campaign against internet-facing Gladinet CentreStack file servers, potentially exploiting recently disclosed CentreStack vulnerabilities (including CVE-2025-11371, CVE-2025-30406, CVE-2025-14611). Curated Intelligence and Huntress reporting, plus observed port-scan data and CL0P’s history of large-scale file-transfer exploits (Oracle EBS, MOVEit, Cleo, etc.), indicate credible preparation for coordinated data leak publications, though no victim samples or deadlines have been posted yet.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.