AI gives ransomware gangs a deadly upgrade
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2024-50623 | Unauthenticated RCE via Unrestricted File Upload in Cleo Harmony, VLTrader, LexiCom CVE-2024-50623 is an unrestricted file upload and download flaw (CWE-434) in Cleo's managed file transfer products — Harmony, VLTrader, and LexiCom — before version 5.8.0.21. It is reachable over the network with no authentication or user interaction (CVSS 9.8, AV:N/AC:L/PR:N), letting an attacker send crafted requests that upload arbitrary files to the server. The unrestricted upload leads to remote code execution, giving the attacker full control of the host for staging, data theft, or ransomware, while the download capability risks exposure of business files the server moves with trading partners. Any organization running these products is affected, and managed file transfer servers are typically internet-facing and handle sensitive B2B data. Exploitation is confirmed in the wild: CISA added it to the KEV catalog on 2024-12-13 with ransomware use noted, EPSS assigns a 98.6% probability of exploitation within 30 days, and the Clop ransomware gang has claimed dozens of breaches (some disputed), including a confirmed breach at WK Kellogg. Do: Upgrade Harmony, VLTrader, and LexiCom to 5.8.0.21 or later per vendor instructions; if upgrading is not possible, apply vendor mitigations or discontinue use of the product, as CISA's KEV entry requires. Prioritize internet-exposed instances, hunt for indicators of compromise (unexpected file writes and execution on the transfer host, new accounts, suspicious outbound connections), and restrict the service to trusted partner networks. Given known ransomware use by Clop, any suspected compromise should trigger checks for lateral movement and staged exfiltration of transferred files. | 9.8 | 99% | KEV ransomware |
| moderate≈1,000–3,000 internet-exposed Cleo servers (tens of thousands of enterprise deployments) | |
| CVE-2024-55956 | Unauthenticated File Upload RCE in Cleo Harmony, VLTrader, and LexiCom CVE-2024-55956 is an unauthenticated command-execution flaw (CWE-77) in Cleo's managed file transfer products: by default the Autorun directory automatically imports and runs files, so an unauthenticated attacker can import Bash or PowerShell commands that execute on the host. It is triggered over the network with no authentication and no user interaction (CVSS 3.1 score 9.8), by sending crafted import requests to a vulnerable Cleo server. Successful exploitation yields arbitrary command execution on the server, enabling data theft, lateral movement, and ransomware deployment. Any organization running Cleo Harmony, VLTrader, or LexiCom before 5.8.0.24 is affected — typically enterprises using these servers for EDI and partner file exchange. The flaw is actively exploited in the wild: it was added to CISA KEV on 2024-12-17 with known ransomware use (widely attributed to Cl0p), EPSS is 94% (top percentile), and confirmed downstream breaches such as WK Kellogg's have been tied to it. Do: Upgrade all Cleo Harmony, VLTrader, and LexiCom instances to 5.8.0.24 or later immediately, per the CISA KEV required action to apply vendor mitigations or discontinue use. If patching is delayed, restrict or remove internet exposure of the server. Because exploitation is confirmed and ransomware-linked, inspect the Autorun directory for unexpected imported files, review application logs for executed commands, and hunt for signs of data exfiltration or staging. | 9.8 | 94% | KEV ransomware PoC |
| largetens of thousands of installations (Cleo cites 100,000+ business customers; public internet scans showed roughly 1,000–2,000 exposed instances) |
Full article706 words · extracted from helpnetsecurity.com · click to collapse
Ransomware continues to be the major threat to large and medium-sized businesses, with numerous ransomware gangs abusing AI for automation, according to Acronis.
Ransomware gangs maintain pressure on victims
From January to June 2025, the number of publicly reported ransomware victims jumped 70% compared to the same period in both 2023 and 2024. February stood out as the worst month, with 955 reported cases.
Cl0p alone was responsible for 335 of those cases, a 300% month-over-month surge that leveraged the mass exploitation of high-severity vulnerabilities in CLEO MFT platforms (Harmony, VLTrader, Lexicom), CVE-2024-50623 (remote code execution) and CVE-2024-55956 (command injection).
The pace of attacks slowed in Q2 2025, with 1,522 victims compared to 2,120 in Q1. This drop was likely the result of law enforcement crackdowns, rebranding pauses by major groups, and stronger corporate defenses.
Manufacturing, retail and technologies were the most targeted industries for ransomware attacks in Q1 2025. Retail, food and drink (12%) and telcos and media (10%) were also popular targets.
MSPs under attack
While the overall number of attacks targeting MSPs fell over the measured time period, the nature of attacks changed significantly; phishing accounted for 52% of all attacks targeting MSPs as compared to 30% in 2024, while Remote Desktop Protocol (RDP) attacks all but vanished.
Despite a small dip from 15% to 13%, credential abuse remains a steady threat, fueled by attackers harvesting valid tokens and passwords through infostealers.
In the first half of 2025, Akira, Play, Cl0p, RansomHub, Qilin, and RALord/Nova stood out as the most active ransomware groups going after MSPs and telecom providers.
Each group has its own approach to getting in. Cl0p, for example, keeps taking advantage of known vulnerabilities in third-party software, while Akira and RansomHub lean more on phishing and stealing credentials, often supported by infostealers.
Attacks on MSPs now occur on regular basis and affect providers of all sizes and in regions around the world.
Attackers are leveraging trust in collaboration tools
Attackers are exploiting the trust users place in real-time communication tools, using tactics like deepfake-based BEC to impersonate CEOs to bypass traditional defenses. The persistence of advanced attacks, though low in volume, indicates that zero-day exploits and AI-driven threats remain a critical concern.
Between January 1 and May 15, 2025, researchers scanned over 714 million emails and nearly 1.28 billion files and URLs. During that time, they detected a total of 7,201,107 attacks, which works out to about 205 attacks per organization each month. Looking closer at the emails, around 30% were flagged as spam, while 1.1% were outright malicious, carrying phishing links, malware, or advanced attack payloads.
Malware in collaboration apps took a big hit, dropping from 82% to 45%. At the same time, phishing jumped from 9% to 30.5%, and advanced attacks climbed from 9% to 24.5%. This shows that attackers are diversifying their tactics, with a growing focus on phishing and possibly AI-driven attacks within collaboration platforms.
Total email attacks fell by 6.5% (7.2 million versus 7.7 million), and attacks per organization per month dropped dropped by 29.6% (205 versus 291).
The spam ratio rose slightly from 27.6% to 30.2%, indicating persistent high-volume, low-effort attacks. The malicious email ratio fell from 1.5% to 1.1%, suggesting attackers are shifting toward more targeted, high-impact attacks.
Phishing dropped from 79% to 69.8% but social engineering and BEC increased from 20% to 25.6%, reflecting the use of AI to craft convincing impersonations.
AI-powered cyberthreats
The rise of AI-powered cyberthreats has fueled the growth of cybercrime-as-a-service (CaaS) models. On the dark web, AI tools and services are being made available to less technically skilled criminals, giving more people access to sophisticated attack capabilities. This trend is lowering the barrier to entry for cybercrime, allowing a wider range of actors to carry out attacks.
“While the endgame for cybercriminals is still ransomware, how they get there is changing” said Gerald Beuchelt, CISO at Acronis. “Even the least sophisticated attackers today have access to advanced AI capabilities, generating social engineering attacks, and automating their activities with minimal effort. The result is MSPs, manufacturers, ISPs, and others are constantly exposed to sophisticated attacks including increasingly advanced deepfakes, and all it takes is one mistake to the put the organizations’ entire future at risk.”
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2025/08/22/ransomware-gangs-ai/