CL0P Ransomware Group Targets Gladinet CentreStack in New Campaign
ID: f9f83cc0-e7d7-5df0-a93b-31045c87dd32
STIX ID: report--f9f83cc0-e7d7-5df0-a93b-31045c87dd32
Feed Name: The Cyber Express
CL0P appears to be staging an extortion campaign against internet-facing Gladinet CentreStack file servers, potentially exploiting recently disclosed CentreStack vulnerabilities (including CVE-2025-11371, CVE-2025-30406, CVE-2025-14611). Curated Intelligence and Huntress reporting, plus observed port-scan data and CL0P’s history of large-scale file-transfer exploits (Oracle EBS, MOVEit, Cleo, etc.), indicate credible preparation for coordinated data leak publications, though no victim samples or deadlines have been posted yet.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
