IntelliOS Threat Intel Operating System
IntelliOSPANDAModule|AIFlash Threat Intel Brief

Cl0p MOVEit Transfer Mass Exploitation

CVE-2023-34362, LEMURLOOT, Data-Theft Extortion, and Evidence-Led Scoping

CVE-2023-34362CISA KEVMass data theft
Published
Jul 11, 2026
Brief Version
v1.2
Updated
Jul 18, 2026
Next AI Monitor
Daily at 1:00 PM ET for 12 months
Brief ID
PANDA-FTIB-CLOP-MOVEIT-2026-001
Template
Flash Threat Brief v2.0
  • This was a mass data-theft and extortion campaign, not a conventional encryption event: CL0P exploited internet-facing MOVEit Transfer systems to steal data at scale and pressure affected organizations. Restoring service or finding no encrypted systems does not resolve the exposure question.1
  • The exploitation window began before defenders had a patch: CISA/FBI place exploitation on or about May 27, 2023; Progress published its initial critical-vulnerability guidance on May 31 and CISA added CVE-2023-34362 to KEV on June 2. Exposure during that gap requires retrospective investigation.1, 3, 4
  • Patching closes the vulnerability but does not prove data was safe: Teams must determine whether vulnerable MOVEit servers, databases, accounts, files, and outbound traffic show exploitation or data access, and preserve that evidence before destructive cleanup.1, 2, 3
  • LEMURLOOT and human2.aspx are priority hunt leads: CISA/FBI document the LEMURLOOT web shell, human2.aspx, attacker-created accounts, database activity, and file-transfer behavior. Hunt these artifacts alongside local web, application, identity, database, and network evidence.1
  • The real business problem is downstream data ownership: MOVEit often concentrates files belonging to employees, customers, partners, and third parties. Scoping must identify what data was accessed, who owned it, where it moved, and which contractual, regulatory, customer, insurer, or legal workflows are triggered.1, 3
  • Keep attribution and victim claims evidence-bound: CISA/FBI associate the campaign with CL0P and use TA505 naming, while MITRE supplies broader related context. A group label or leak-site post does not establish that a particular organization was compromised or define its data exposure.1, 7

CISA and the FBI report that CL0P began exploiting CVE-2023-34362 in Progress MOVEit Transfer on or about May 27, 2023. NVD records the issue as a SQL injection vulnerability that could let an unauthenticated attacker access the MOVEit Transfer database. CISA added the CVE to KEV on June 2, and Progress published critical-vulnerability guidance on May 31.1, 2, 3, 4

The intrusion was built for rapid theft from an internet-facing file-transfer platform, not conventional enterprise-wide encryption. CISA/FBI and Mandiant describe exploitation, LEMURLOOT, account and database activity, file enumeration, and exfiltration; Mandiant observed data theft within minutes in some cases and access to connected Azure Blob credentials where configured.1, 5

A completed patch prevents known future exploitation but does not answer whether data was accessed before remediation. The decision-ready output is an asset-by-asset exposure record plus a file- and data-owner scope supported by preserved web, application, database, identity, storage, transfer, and egress evidence.1, 3, 5, 6

IntelliOS uses the Cl0p label as CISA/FBI-supported campaign context and retains TA505 as MITRE-supported related actor context. Public claims and aggregate victim counts can prioritize review, but they do not prove compromise, file contents, or legal impact for a particular organization.1, 7