Skip to content
OnMSFT.com
  • Home
  • About
  • Contact
  • Windows
  • Surface
  • Xbox
  • How-To
  • OnPodcast
  • Edge
  • Teams
  • Gaming
Menu
  • Home
  • About
  • Contact
  • Windows
  • Surface
  • Xbox
  • How-To
  • OnPodcast
  • Edge
  • Teams
  • Gaming
  1. Home
  2. News
  3. Microsoft confirmed Clop ransomware gang responsible for MOVEit data-theft attacks

Microsoft confirmed Clop ransomware gang responsible for MOVEit data-theft attacks

Pranav Bhardwaj Pranav Bhardwaj
June 5, 2023
2 min read

In a recent revelation, it has come to light that hackers are taking advantage of a newly discovered vulnerability in MOVEit Transfer, a widely used file-transfer tool employed by enterprises for sharing large files online. Microsoft, in its investigation, has identified the Clop ransomware gang as the culprit behind the recent attacks that exploit a zero-day vulnerability in the MOVEit Transfer platform. Their objective has been to steal data from various organizations.

This vulnerability has enabled unauthorized access to the databases of affected MOVEit servers. Progress Software, the developer of MOVEit software, has already taken steps to address this issue by releasing several patches.

According to a tweet by the Microsoft Threat Intelligence team on Sunday night, the attacks exploiting the CVE-2023-34362 MOVEit Transfer 0-day vulnerability have been attributed to Lace Tempest, a threat actor known for ransomware operations and operating the Clop extortion site.

Microsoft is attributing attacks exploiting the CVE-2023-34362 MOVEit Transfer 0-day vulnerability to Lace Tempest, known for ransomware operations & running the Clop extortion site. The threat actor has used similar vulnerabilities in the past to steal data & extort victims. pic.twitter.com/q73WtGru7j

— Microsoft Threat Intelligence (@MsftSecIntel) June 5, 2023

MOVEit Transfer is a managed file transfer (MFT) solution that enables secure file transfers between enterprises, business partners, and customers through protocols like SFTP, SCP, and HTTP-based uploads.

The attacks, which are believed to have commenced on May 27th during the extended US Memorial Day holiday, have resulted in the theft of valuable data from numerous organizations.

To execute their malicious activities, the threat actors exploited the zero-day vulnerability in MOVEit Transfer to deploy specially crafted webshells on servers. These webshells allowed the hackers to obtain a list of files stored on the server, download files, and steal credentials and secrets associated with configured Azure Blob Storage containers.

The Clop ransomware operation has a history of targeting managed file transfer software, previously exploiting a GoAnywhere MFT zero-day in January 2023 and conducting zero-day attacks on Accellion FTA servers in 2020.

Authorities and affected organizations are actively working to mitigate the impact of these attacks and prevent further exploitation of the vulnerability. It is crucial for enterprises utilizing MOVEit Transfer to promptly apply the released patches and ensure the security of their systems to safeguard their valuable data.

Via: Bleeping Computer

Related

Share this article:
Previous Article Microsoft says ChatGPT creator OpenAI is contemplating investment opportunities in Israel Next Article Having issues with Exchange, Outlook, Teams, OneDrive? Microsoft confirms and is currently working on a fix

Related Articles

NVIDIA Neural Rendering Reduces VRAM From 6.5GB to 970MB Without Losing Detail

April 4, 2026

H.264 Licensing Fees Rise to $4.5 Million for Streaming Platforms in 2026

April 4, 2026
Sony quietly updates PlayStation Studios site as PC plans come into question

Sony quietly updates PlayStation Studios site as PC plans come into question

April 4, 2026

Leave a Comment Cancel reply

Your email address will not be published. Required fields are marked *

Recent Posts

  • NVIDIA Neural Rendering Reduces VRAM From 6.5GB to 970MB Without Losing Detail
  • H.264 Licensing Fees Rise to $4.5 Million for Streaming Platforms in 2026
  • Sony quietly updates PlayStation Studios site as PC plans come into question
  • Red Magic 11 runs PC games like GTA 5 and Cyberpunk 2077 on Android at 60 FPS
  • New Ryzen 9 9950X3D2 loses performance on air cooling

Recent Comments

  1. XxRIVTYxX on Intel Says It Tried to Help Before Crimson Desert Dropped Arc Support
  2. Gaurav Kumar on Chrome Prepares Nudge to ‘Move Tabs to the Side’ as Vertical Tabs Near Release
OnMSFT.com

The Tech News Site

Categories

  • Windows
  • Surface
  • Xbox
  • How-To
  • OnPodcast
  • Gaming
  • Edge
  • Teams

Recent Posts

  • NVIDIA Neural Rendering Reduces VRAM From 6.5GB to 970MB Without Losing Detail
  • H.264 Licensing Fees Rise to $4.5 Million for Streaming Platforms in 2026
  • Sony quietly updates PlayStation Studios site as PC plans come into question
  • Red Magic 11 runs PC games like GTA 5 and Cyberpunk 2077 on Android at 60 FPS
  • New Ryzen 9 9950X3D2 loses performance on air cooling

Quick Links

  • About OnMSFT.com
  • Contact OnMSFT
  • Join Our Team
  • Privacy Policy
© 2010–2026 OnMSFT.com LLC. All rights reserved.
About OnMSFT.comContact OnMSFTPrivacy Policy