ZeroHour
The Recordpublished ()ingested

Clop ransomware group behind MOVEit file transfer hacks: Microsoft

criticalRansomwareimportance 60CVE-2023-34362

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2023-34362
Unauthenticated SQL Injection in Progress MOVEit Transfer

CVE-2023-34362 is an unauthenticated SQL injection flaw (CWE-89) in Progress MOVEit Transfer that allows an attacker with no credentials to gain unauthorized access to the product's database. It is triggered remotely via crafted input submitted to the MOVEit Transfer web application, with the impact varying by the backend database engine in use (MySQL, Microsoft SQL Server, or Azure SQL). A successful attacker can infer the structure and contents of the database and, depending on the engine, execute SQL statements that alter or delete database elements, exposing data handled by the file-transfer service. Any organization running an internet-reachable MOVEit Transfer instance is affected; public internet-exposure scans around disclosure identified on the order of a few thousand servers, each typically serving enterprise or government user bases. Exploitation is confirmed in the wild: the flaw was added to CISA KEV on 2023-06-02 with known ransomware use and an EPSS exploitation probability of 99.9% (100th percentile), while no public PoC is known.

Do: Apply the vendor's updates immediately, per Progress instructions and CISA's required action. Until patched, restrict internet exposure of MOVEit Transfer and check the backend database for unexpected structure or content changes and deletions. Because in-the-wild exploitation and ransomware use are confirmed, treat any unpatched, internet-facing instance as potentially compromised and review stored transfer data and access logs for anomalies.

9.8100% KEV ransomware PoC
  • Progress MOVEit Transfer
large≈2,000-3,000 internet-exposed MOVEit Transfer servers (public internet-exposure scans)
Full article497 words · extracted from therecord.media · click to collapse

The Clop ransomware group is allegedly exploiting a serious zero-day vulnerability affecting the widely-used MOVEit file transfer tool, according to research from Microsoft.

Since Thursday, cybersecurity experts have raised alarms about the new vulnerability — tagged as CVE-2023-34362 — affecting Progress Software’s MOVEit Transfer solution.

The vulnerability was added to the Cybersecurity and Infrastructure Security Agency’s (CISA) list of exploited bugs on Friday, giving all federal civilian agencies in the U.S. until June 23 to apply any mitigations or patches, which were released this weekend.

On Sunday, Microsoft identified the perpetrators as the Clop ransomware group — which has made a point of exploiting popular file transfer services used by major corporations and governments in the last three years.

“Microsoft is attributing [the] attacks … to Lace Tempest, known for ransomware operations & running the Clop extortion site,” Microsoft’s security team said on Sunday. “The threat actor has used similar vulnerabilities in the past to steal data & extort victims … Exploitation is often followed by deployment of a web shell w/ data exfil capabilities.”

The BBC and British Airways became the first victims to confirm that they had data stolen through the exploitation of the issue after their payroll provider, Zellis, was affected by the vulnerability. BleepingComputer first reported that MOVEit-related attacks started over Memorial Day weekend.

Security firm Censys has observed 3,803 hosts exposed to the internet currently running the MOVEit service, and experts have spent recent days trying to understand which group was behind the bug’s exploitation.

The vulnerability has sparked concern because of its wide usage among governments and large financial institutions. Data from the software company Censys shows the education sector has 27 hosts exposed on the internet while more than 60 from U.S. federal and state government arms are still exposed.

On Sunday, incident responders from the cybersecurity company Rapid7 identified a method to determine which, and how much, data was exfiltrated from MOVEit customer environments.

The Clop ransomware group recently exploited a vulnerability affecting Fortra’s GoAnywhere file transfer product. The group said it stole data from more than 130 companies, governments and organizations — including the government of Tasmania, the city of Toronto, British multinational conglomerate Virgin, mining giant Rio Tinto, Procter & Gamble, Japanese tech giant Hitachi, Hatch Bank, the U.K. Pension Protection Fund, cloud data management giant Rubrik and more.

Clop ransomware actors were also the primary cybercriminals behind a spate of attacks that targeted the Accellion file transfer tool, stealing data from some of the biggest companies and schools in the world including the University of Colorado, Kroger, Morgan Stanley and Shell.

No previous article

No new articles

Jonathan Greig

is a Breaking News Reporter at Recorded Future News. Jonathan has worked across the globe as a journalist since 2014. Before moving back to New York City, he worked for news outlets in South Africa, Jordan and Cambodia. He previously covered cybersecurity at ZDNet and TechRepublic.

Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/clop-behind-moveit-attacks-microsoft