Tag: Cl0p Ransomware

Google Mandiant Probes New Oracle Extortion Wave Possibly Linked to Cl0p Ransomware
News

Google Mandiant Probes New Oracle Extortion Wave Possibly Linked to Cl0p Ransomware

Google Mandiant and Google Threat Intelligence Group (GTIG) have revealed that they are monitoring a new cluster of activity that may be connected to Cl0p, a threat actor with financial motivations. Sending extortion emails to executives at different companies while claiming to have stolen confidential information from their Oracle E-Business Suite is the harmful action. In a statement to The Hacker News, Genevieve Stark, Head of Cybercrime and Information Operations Intelligence Analysis at GTIG, stated that although this activity started on or before September 29, 2025, Mandiant's experts are still in the early phases of several investigations and have not yet verified the group's claims. The ongoing activity was characterized by Mandiant CTO Charles Carmakal as a "high-volume ...
Third Flaw Uncovered in MOVEit Transfer App Amidst Cl0p Ransomware Mass Attack
News

Third Flaw Uncovered in MOVEit Transfer App Amidst Cl0p Ransomware Mass Attack

A third vulnerability affecting Progress Software's MOVEit Transfer tool was exposed on Thursday as the Cl0p cybercrime group used extortion against the impacted businesses. The newly discovered bug also involves a SQL injection vulnerability that "could result in escalated privileges and potential unauthorised access to the environment," according to the CVE that has not yet been assigned to it. While a patch is being developed to fix the vulnerability, the business is advising all of its customers to disable all HTTP and HTTPs traffic to MOVEit Transfer on ports 80 and 443 read more Third Flaw Uncovered in MOVEit Transfer App Amidst Cl0p Ransomware Mass Attack. Stay one step ahead of cyber threats with ReconBee.com. Explore our comprehensive coverage of recent cyber attacks, cy...
Notorious Cyber Gang FIN7 Returns With Cl0p Ransomware in New Wave of Attacks
News

Notorious Cyber Gang FIN7 Returns With Cl0p Ransomware in New Wave of Attacks

Cl0p (also known as Clop) ransomware has been seen being used by the prominent cybercrime group FIN7, marking the threat actor's first ransomware campaign since late 2021. Microsoft is tracking the financially motivated player under their new taxonomy Sangria Tempest after noticing the behavior in April 2023. The Lizar post-exploitation tool is loaded by Sangria Tempest in these new attacks in order to gain access to a target network, according to the threat intelligence team of the business read more Notorious Cyber Gang FIN7 Returns With Cl0p Ransomware in New Wave of Attacks. With ReconBee.com Stay ahead of the latest threats with in-depth coverage of cyber attacks and cybersecurity trends, and the latest cybersecurity news.
Microsoft Confirms PaperCut Servers Used to Deliver LockBit and Cl0p Ransomware
News

Microsoft Confirms PaperCut Servers Used to Deliver LockBit and Cl0p Ransomware

Microsoft has determined that attacks aimed at delivering the Cl0p and LockBit ransomware families are connected to the active exploitation of PaperCut servers. A portion of the incursions are being attributed by the tech giant's threat intelligence team to an actor it tracks by the name of Lace Tempest (formerly known as DEV-0950), who shares similarities with other hacker outfits including FIN11, TA505, and Evil Corp. Microsoft stated in a series of tweets that in the attacks it has observed, "Lace Tempest ran multiple PowerShell commands to deliver a TrueBot DLL, which connected to a C2 server, attempted to steal LSASS credentials, and injected the TrueBot payload into the conhost.exe service read more Microsoft Confirms PaperCut Servers Used to Deliver LockBit and Cl0p Ransomwar...