CARDS
CARDS
CISA and the FBI assess that the CL0P ransomware gang began exploiting the then-zero-day SQL injection vulnerability CVE-2023-34362 in Progress MOVEit Transfer on or about May 27, 2023. Public reporting describes exploitation of internet-facing managed-file-transfer applications, deployment of the LEMURLOOT web shell, data theft, and extortion pressure. The operational response is to scope the actual server, account, file-transfer, and data-access evidence; public victim and leak-site claims are not proof of compromise on their own.
Last updated May 24, 2026, 8:00 PM EDT
Evidence Boundary
Bottom Line Up Front
CISA and the FBI assess that the CL0P ransomware gang began exploiting the then-zero-day SQL injection vulnerability CVE-2023-34362 in Progress MOVEit Transfer on or about May 27, 2023. Public reporting describes exploitation of internet-facing managed-file-transfer applications, deployment of the LEMURLOOT web shell, data theft, and extortion pressure. The operational response is to scope the actual server, account, file-transfer, and data-access evidence; public victim and leak-site claims are not proof of compromise on their own.[1][2][3][4]
Sensitive-file exposure, extortion, third-party notification and contractual obligations, identity or privacy risk, and a potentially long investigation when an MFT platform holds data for many customers or business units. Organization-specific impact requires server, database, file-transfer, and egress evidence.[1][2][3][4]
Inventory every internet-facing MOVEit Transfer instance and verify the vendor remediation path for CVE-2023-34362 and related 2023 advisories Preserve MOVEit, web-server, database, authentication, and file-transfer evidence before destructive cleanup Hunt for the LEMURLOOT / human2.aspx web-shell indicators and unexpected MOVEit service accounts described by CISA/FBI Review outbound transfers, anomalous database or file access, archive creation, and newly created or privileged accounts Scope third-party and downstream data ownership from confirmed records, then coordinate legal, privacy, customer, and insurer workflows[1][2][3][4]
Decision Summary
CISA and the FBI assess that the CL0P ransomware gang began exploiting the then-zero-day SQL injection vulnerability CVE-2023-34362 in Progress MOVEit Transfer on or about May 27, 2023. Public reporting describes exploitation of internet-facing managed-file-transfer applications, deployment of the LEMURLOOT web shell, data theft, and extortion pressure. The operational response is to scope the actual server, account, file-transfer, and data-access evidence; public victim and leak-site claims are not proof of compromise on their own.
The retained record scopes this as ransomware / extortion / mass exploitation / kev / managed file transfer / web shell / data theft activity during 2023-05-27 onward public reporting and remediation window. Sensitive-file exposure, extortion, third-party notification and contractual obligations, identity or privacy risk, and a potentially long investigation when an MFT platform holds data for many customers or business units. Organization-specific impact requires server, database, file-transfer, and egress evidence.[1][2][3][4]
Inventory every internet-facing MOVEit Transfer instance and verify the vendor remediation path for CVE-2023-34362 and related 2023 advisories Preserve MOVEit, web-server, database, authentication, and file-transfer evidence before destructive cleanup Hunt for the LEMURLOOT / human2.aspx web-shell indicators and unexpected MOVEit service accounts described by CISA/FBI Review outbound transfers, anomalous database or file access, archive creation, and newly created or privileged accounts Scope third-party and downstream data ownership from confirmed records, then coordinate legal, privacy, customer, and insurer workflows[1][2][3][4]
Confirmed reporting is separated from attribution, victim, and prevalence claims that the retained sources do not establish. Confidence: High for CISA/FBI's CL0P attribution, CVE-2023-34362 exploitation, and remediation context; victim-specific impact, downstream exposure, and adversary claims require incident evidence..[1][2][3][4]
Actor Mapping
Targeting
Tradecraft
Tools / Observables
Source Reconciliation
Campaign rows are retained as source-backed context. Actor mappings do not automatically merge actor records; SOCRadar, MITRE, Mandiant, CrowdStrike, Microsoft, and other future sources can disagree on boundaries, aliases, or campaign ownership.
CISA/FBI and Progress govern public exploitation and remediation details. MITRE tracks TA505 as a cybercrime group involved in ransomware campaigns involving Clop, but related names should not be treated as interchangeable proof for every incident. Public victim lists and leak-site posts are analytical leads, not confirmation of an organization's compromise or data exposure.
IntelliOS
Citations