Clop Ransomware Group Exploits GoAnywhere MFT Flaw
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2023-0669 | Pre-Authentication Deserialization RCE in Fortra GoAnywhere MFT Fortra (formerly HelpSystems) GoAnywhere MFT is vulnerable to pre-authentication remote code execution (CWE-502) in the License Response Servlet, which deserializes an attacker-controlled object without validating it. An unauthenticated attacker who can reach the exposed administrative interface can send a crafted serialized object to the servlet and trigger code execution on the server. Successful exploitation gives the attacker the ability to run arbitrary code in the context of the application, which has been leveraged for ransomware operations. All organizations running GoAnywhere MFT with the affected component reachable by untrusted networks are in scope. The flaw is being actively exploited: CISA added it to the Known Exploited Vulnerabilities catalog on 2023-02-10, ransomware use is confirmed, and EPSS puts the 30-day exploitation probability at 100%. Do: Apply the vendor's updates for GoAnywhere MFT immediately, per Fortra's instructions, as required by the CISA KEV catalog. Until patched, restrict or block untrusted/internet access to the administrative interface hosting the License Response Servlet, and review logs for signs of exploitation given confirmed in-the-wild and ransomware use. | 7.2 | 100% | KEV ransomware PoC ×3 |
| moderate≈1,000–10,000 internet-exposed GoAnywhere MFT instances (public internet scans of the exposed administrative interface) |
Full article354 words · extracted from infosecurity-magazine.com · click to collapse
The ransomware gang known as Clop has been observed exploiting a pre-authentication command injection vulnerability (CVE-2023-0669) in Fortra's file transfer solution GoAnywhere MFT.
The high-level vulnerability has a CVSS:3.1 score of 7.2 and was exploited against several companies in the US and elsewhere, according to a new advisory by security experts at CloudSEK.
The flaw derives from a deserialization bug that can be exploited by sending a post request to the endpoint. CloudSEK warned that a Metasploit module is also available to take advantage of the vulnerability.
“The exploit for this CVE was available a day before the patch (7.1.2) was released on February 7 2023. Many vulnerable admin panels of GoAnywhere were found to be indexed on Shodan [a search engine for Internet-connected devices] running on port 8000,” reads the technical write-up.
The company clarified that only the GoAnywhere administrative interface was vulnerable to the exploit used by the Clop ransomware group and not the web client interface used by most people.
Read more on Clop here: Members of Clop Ransomware Gang Arrested in Ukraine
Still, threat actors could search for web client interfaces on the internet and then try to find admin panels on the same IP.
“Shodan search results indicate that thousands of web panels for GoAnywhere are exposed on the web,” CloudSEK wrote. “Of these thousands, around 94 of them are running on port 8000 or port 8001 where the admin panel [...] is located. In order to obtain remote code execution, only a post request needs to be made to the vulnerable endpoint.”
To mitigate the impact of this vulnerability, CloudSEK advised system defenders to update their machines to the latest GoAnywhere version as well as stop exposing port 8000 (the internet location of the GoAnywhere MFT admin panel).
Admin user accounts should also be reviewed for suspicious activity such as unrecognized usernames, accounts created by unknown ‘systems,’ suspicious timing of account creation and disabled or non-existent super users creating accounts.
The CloudSEK advisory follows a report published by Microsoft in October last year linking Raspberry Robin Worm actors to the Clop and LockBit ransomware groups.
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.infosecurity-magazine.com/news/clop-ransomware-exploits/