Cl0p MOVEit Transfer Mass Exploitation
CVE-2023-34362, LEMURLOOT, Data-Theft Extortion, and Evidence-Led Scoping
- Field
- Decision Question
- Value
- Which MOVEit Transfer systems and data were exposed during the Cl0p campaign, what evidence establishes exploitation or theft, and which remediation and notification decisions follow?
- Field
- User Topic
- Value
- Cl0p MOVEit Transfer Mass Exploitation: what happened, what evidence establishes exposure, and what decisions remain for responders, executives, counsel, insurers, and affected data owners?
- Field
- Interpreted Questions
- Value
- Was an internet-facing MOVEit Transfer instance vulnerable between the first observed exploitation and remediation? What artifacts indicate exploitation or data theft? Which files and data owners were affected? What does public attribution establish—and what must be proved from local evidence? Which remediation, notification, contractual, and insurance decisions follow?
- Field
- Initial Observations
- Value
- The strongest retained record converges on exploitation beginning before public disclosure, rapid server-side data theft, deployment of the LEMURLOOT web shell in at least some intrusions, and a response problem centered on historical access and downstream data ownership. Patching is necessary but is not retrospective proof that data was not accessed. Mandiant observed activity as early as May 27 and data theft within minutes in some cases; Progress separately documented three 2023 MOVEit Transfer CVEs and their patch sequence.1, 3, 5, 6
- Field
- Tier 0 Through Tier 8 Coverage
- Value
- The Source Coverage table below records the retained evidence coverage. Any tier without a retained source contributed no published evidence to this brief; absence is not filled with inferred or invented material.
- Field
- Fact / Analysis / Unknown Boundaries
- Value
- CISA/FBI are authoritative for their public CL0P exploitation assessment, observed artifacts, and response guidance. Progress controls product remediation and patch chronology. NVD and CISA KEV govern the vulnerability record and active-exploitation context. Mandiant contributes primary incident-response observations that may not represent every intrusion. MITRE's TA505 relationship and ATT&CK mappings are contextual and do not establish identical identity, responsibility, or impact in every Cl0p-branded or managed-file-transfer incident.
- Field
- Source Coverage
- Value
- Tier
- Government advisories and vulnerability records
- Checked
- 4
- Candidate Hits
- 4
- Planner Selected
- 4
- Not Used
- 0
- Tier
- Vendor advisories and patch records
- Checked
- 2
- Candidate Hits
- 2
- Planner Selected
- 2
- Not Used
- 0
- Tier
- Primary incident-response research
- Checked
- 2
- Candidate Hits
- 1
- Planner Selected
- 1
- Not Used
- 1
- Tier
- Authoritative ATT&CK framework records
- Checked
- 3
- Candidate Hits
- 3
- Planner Selected
- 3
- Not Used
- 0
- Tier
- Secondary news, social, and victim-count reporting
- Checked
- 8
- Candidate Hits
- 5
- Planner Selected
- 0
- Not Used
- 8
Tier Checked Candidate Hits Planner Selected Not Used Government advisories and vulnerability records 4 4 4 0 Vendor advisories and patch records 2 2 2 0 Primary incident-response research 2 1 1 1 Authoritative ATT&CK framework records 3 3 3 0 Secondary news, social, and victim-count reporting 8 5 0 8
| Field | Value | ||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Decision Question | Which MOVEit Transfer systems and data were exposed during the Cl0p campaign, what evidence establishes exploitation or theft, and which remediation and notification decisions follow? | ||||||||||||||||||||||||||||||
| User Topic | Cl0p MOVEit Transfer Mass Exploitation: what happened, what evidence establishes exposure, and what decisions remain for responders, executives, counsel, insurers, and affected data owners? | ||||||||||||||||||||||||||||||
| Interpreted Questions | Was an internet-facing MOVEit Transfer instance vulnerable between the first observed exploitation and remediation? What artifacts indicate exploitation or data theft? Which files and data owners were affected? What does public attribution establish—and what must be proved from local evidence? Which remediation, notification, contractual, and insurance decisions follow? | ||||||||||||||||||||||||||||||
| Initial Observations | The strongest retained record converges on exploitation beginning before public disclosure, rapid server-side data theft, deployment of the LEMURLOOT web shell in at least some intrusions, and a response problem centered on historical access and downstream data ownership. Patching is necessary but is not retrospective proof that data was not accessed. Mandiant observed activity as early as May 27 and data theft within minutes in some cases; Progress separately documented three 2023 MOVEit Transfer CVEs and their patch sequence.1, 3, 5, 6 | ||||||||||||||||||||||||||||||
| Tier 0 Through Tier 8 Coverage | The Source Coverage table below records the retained evidence coverage. Any tier without a retained source contributed no published evidence to this brief; absence is not filled with inferred or invented material. | ||||||||||||||||||||||||||||||
| Fact / Analysis / Unknown Boundaries | CISA/FBI are authoritative for their public CL0P exploitation assessment, observed artifacts, and response guidance. Progress controls product remediation and patch chronology. NVD and CISA KEV govern the vulnerability record and active-exploitation context. Mandiant contributes primary incident-response observations that may not represent every intrusion. MITRE's TA505 relationship and ATT&CK mappings are contextual and do not establish identical identity, responsibility, or impact in every Cl0p-branded or managed-file-transfer incident. | ||||||||||||||||||||||||||||||
| Source Coverage |
|
Exploited CVE
CVE-2023-34362
NVD describes a SQL injection vulnerability in MOVEit Transfer that can allow an unauthenticated attacker to access the application's database.
Public Exploitation
May 27, 2023
CISA/FBI state that CL0P began exploiting the then-zero-day vulnerability on or about this date.
KEV Added
Jun 2, 2023
CISA added CVE-2023-34362 to the Known Exploited Vulnerabilities catalog based on evidence of active exploitation.
Primary Hunt Lead
LEMURLOOT
CISA/FBI document the LEMURLOOT web shell, including the human2.aspx filename, in their MOVEit advisory.
This brief covers the 2023 mass exploitation of Progress MOVEit Transfer associated by CISA and the FBI with the CL0P ransomware gang. It centers CVE-2023-34362, a SQL injection vulnerability in an internet-facing managed-file-transfer application, the documented LEMURLOOT web shell, data-theft and extortion risk, and the operational discipline needed to distinguish a public claim from confirmed organization-specific exposure.1, 2, 3
CISOs, infrastructure and MFT owners, vulnerability-management teams, SOC/IR teams, privacy and breach counsel, third-party-risk teams, cyber-insurance response teams, and business owners responsible for high-volume sensitive-file exchange. The operational focus is asset inventory, vendor remediation, evidence preservation, web-shell hunting, data-access scoping, and coordinated notification decisions.
- This was a mass data-theft and extortion campaign, not a conventional encryption event: CL0P exploited internet-facing MOVEit Transfer systems to steal data at scale and pressure affected organizations. Restoring service or finding no encrypted systems does not resolve the exposure question.1
- The exploitation window began before defenders had a patch: CISA/FBI place exploitation on or about May 27, 2023; Progress published its initial critical-vulnerability guidance on May 31 and CISA added CVE-2023-34362 to KEV on June 2. Exposure during that gap requires retrospective investigation.1, 3, 4
- Patching closes the vulnerability but does not prove data was safe: Teams must determine whether vulnerable MOVEit servers, databases, accounts, files, and outbound traffic show exploitation or data access, and preserve that evidence before destructive cleanup.1, 2, 3
- LEMURLOOT and human2.aspx are priority hunt leads: CISA/FBI document the LEMURLOOT web shell, human2.aspx, attacker-created accounts, database activity, and file-transfer behavior. Hunt these artifacts alongside local web, application, identity, database, and network evidence.1
- The real business problem is downstream data ownership: MOVEit often concentrates files belonging to employees, customers, partners, and third parties. Scoping must identify what data was accessed, who owned it, where it moved, and which contractual, regulatory, customer, insurer, or legal workflows are triggered.1, 3
- Keep attribution and victim claims evidence-bound: CISA/FBI associate the campaign with CL0P and use TA505 naming, while MITRE supplies broader related context. A group label or leak-site post does not establish that a particular organization was compromised or define its data exposure.1, 7
CISA and the FBI report that CL0P began exploiting CVE-2023-34362 in Progress MOVEit Transfer on or about May 27, 2023. NVD records the issue as a SQL injection vulnerability that could let an unauthenticated attacker access the MOVEit Transfer database. CISA added the CVE to KEV on June 2, and Progress published critical-vulnerability guidance on May 31.1, 2, 3, 4
The intrusion was built for rapid theft from an internet-facing file-transfer platform, not conventional enterprise-wide encryption. CISA/FBI and Mandiant describe exploitation, LEMURLOOT, account and database activity, file enumeration, and exfiltration; Mandiant observed data theft within minutes in some cases and access to connected Azure Blob credentials where configured.1, 5
A completed patch prevents known future exploitation but does not answer whether data was accessed before remediation. The decision-ready output is an asset-by-asset exposure record plus a file- and data-owner scope supported by preserved web, application, database, identity, storage, transfer, and egress evidence.1, 3, 5, 6
IntelliOS uses the Cl0p label as CISA/FBI-supported campaign context and retains TA505 as MITRE-supported related actor context. Public claims and aggregate victim counts can prioritize review, but they do not prove compromise, file contents, or legal impact for a particular organization.1, 7
This card records material changes to the published intelligence baseline. It does not count formatting or routine no-change checks as threat-intelligence deltas.
- Update
- Jul 18, 2026
- Source-backed Delta
- The brief now separates the original exploited CVE from two later MOVEit Transfer vulnerabilities and records the vendor's three-patch sequence.
- Update
- Jul 18, 2026
- Source-backed Delta
- Mandiant incident-response observations were added for exploitation timing, rapid data theft, Azure Blob credential access, account manipulation, and LEMURLOOT behavior.
- Why It Matters
- The investigation can move from generic web-shell hunting to a clearer list of server, database, identity, storage, and egress questions.5
- Update
- Daily
- Source-backed Delta
- The PANDA AI Agent checks authoritative sources for material changes; Page Alerts are enabled.
| Update | Source-backed Delta | Why It Matters |
|---|---|---|
| Jul 18, 2026 | The brief now separates the original exploited CVE from two later MOVEit Transfer vulnerabilities and records the vendor's three-patch sequence. | Responders can distinguish the May 2023 intrusion window from the later hardening sequence and verify the correct remediation history.3, 6 |
| Jul 18, 2026 | Mandiant incident-response observations were added for exploitation timing, rapid data theft, Azure Blob credential access, account manipulation, and LEMURLOOT behavior. | The investigation can move from generic web-shell hunting to a clearer list of server, database, identity, storage, and egress questions.5 |
| Daily | The PANDA AI Agent checks authoritative sources for material changes; Page Alerts are enabled. | Subscribers should be notified only when retained evidence changes a card, conclusion, or source boundary—not for a no-change run.1, 3, 4, 5, 6 |
- Stakeholder
- Executives / boards
- Why This Campaign Matters
- A file-transfer platform can concentrate sensitive data from many business units and third parties; operational restoration does not resolve the data-theft exposure.
- Stakeholder
- Security / IT
- Why This Campaign Matters
- Exploitation began before public disclosure and data theft could occur quickly, leaving little time for preventive action during the original window.
- Stakeholder
- Legal / privacy / insurance
- Why This Campaign Matters
- The same MOVEit server may hold data belonging to multiple organizations, jurisdictions, contracts, or insured entities.
| Stakeholder | Why This Campaign Matters | Decision It Should Drive |
|---|---|---|
| Executives / boards | A file-transfer platform can concentrate sensitive data from many business units and third parties; operational restoration does not resolve the data-theft exposure. | Require a named owner and deadline for historical exposure, data-owner, and notification scope—not only a patch-complete status.1, 5 |
| Security / IT | Exploitation began before public disclosure and data theft could occur quickly, leaving little time for preventive action during the original window. | Validate every instance, preserve evidence, and hunt across web, database, identity, storage, file-transfer, and egress telemetry.1, 3, 5 |
| Legal / privacy / insurance | The same MOVEit server may hold data belonging to multiple organizations, jurisdictions, contracts, or insured entities. | Base notices and coverage positions on confirmed files, owners, access evidence, and contractual roles rather than leak-site or aggregate victim claims.1, 5 |
- Date / Period
- May 27, 2023
- Event / Meaning
- CISA/FBI state that CL0P began exploiting the previously unknown CVE-2023-34362 SQL injection vulnerability in MOVEit Transfer on or about this date.1
- Sources
- 1
- Date / Period
- May 31, 2023
- Event / Meaning
- Progress published its critical-vulnerability advisory and remediation guidance for MOVEit Transfer.3
- Sources
- 3
- Date / Period
- June 2, 2023
- Date / Period
- June 7, 2023
- Event / Meaning
- CISA and FBI issued AA23-158A with the CL0P assessment, technical indicators, and recommended response actions.1
- Sources
- 1
| Date / Period | Event / Meaning | Sources |
|---|---|---|
| May 27, 2023 | CISA/FBI state that CL0P began exploiting the previously unknown CVE-2023-34362 SQL injection vulnerability in MOVEit Transfer on or about this date.1 | 1 |
| May 31, 2023 | Progress published its critical-vulnerability advisory and remediation guidance for MOVEit Transfer.3 | 3 |
| June 2, 2023 | CISA added CVE-2023-34362 to the KEV catalog based on active-exploitation evidence.1, 4 | 1, 4 |
| June 7, 2023 | CISA and FBI issued AA23-158A with the CL0P assessment, technical indicators, and recommended response actions.1 | 1 |
| June 9, 2023 | Progress issued a second MOVEit Transfer patch for CVE-2023-35036. Its July FAQ said the company had no indication at that time that this follow-on issue had been exploited.6 | 6 |
| June 15–16, 2023 | Progress issued a third MOVEit Transfer patch for CVE-2023-35708, completing the three-release sequence documented in its July customer FAQ.6 | 6 |
- Phase
- Establish the MFT asset and data-owner scope
- Phase
- Verify remediation, not just a ticket
- Phase
- Preserve server and transfer evidence
- Action
- Before destructive cleanup, preserve web-server, MOVEit, database, authentication, administrative, file-transfer, and network-egress evidence. Record the asset, log-retention, and acquisition gaps explicitly.1
- Sources
- 1
- Phase
- Hunt documented intrusion artifacts
- Action
- Hunt for LEMURLOOT, human2.aspx, unexpected accounts, suspicious database access, large file retrieval, archive creation, and anomalous outbound transfer patterns. Validate against local timestamps and asset context.1
- Sources
- 1
- Phase
- Decide downstream actions from confirmed evidence
| Phase | Action | Sources |
|---|---|---|
| Establish the MFT asset and data-owner scope | Identify every MOVEit Transfer instance, hosting arrangement, public endpoint, connected database, data owner, service account, and third-party workflow. Treat unknown remediation state as an investigation priority.1, 3 | 1, 3 |
| Verify remediation, not just a ticket | Apply and validate Progress guidance for CVE-2023-34362 and the relevant 2023 follow-on advisories. Restrict public access according to vendor and incident-response guidance while remediation is in progress.1, 3, 4 | 1, 3, 4 |
| Preserve server and transfer evidence | Before destructive cleanup, preserve web-server, MOVEit, database, authentication, administrative, file-transfer, and network-egress evidence. Record the asset, log-retention, and acquisition gaps explicitly.1 | 1 |
| Hunt documented intrusion artifacts | Hunt for LEMURLOOT, human2.aspx, unexpected accounts, suspicious database access, large file retrieval, archive creation, and anomalous outbound transfer patterns. Validate against local timestamps and asset context.1 | 1 |
| Decide downstream actions from confirmed evidence | Map accessed or exfiltrated data to owners and contractual obligations, then coordinate privacy, legal, customer, regulator, and insurer activity from that evidence. Do not use a public leak-site claim as the sole basis for impact determination.1, 5, 7 | 1, 5, 7 |
- Term
- MOVEit Transfer
- Term
- CVE-2023-34362
- Meaning Here
- NVD records a SQL injection vulnerability in MOVEit Transfer that could allow an unauthenticated attacker to gain access to the product database.2
- Sources
- 2
- Term
- LEMURLOOT / human2.aspx
- Meaning Here
- CISA/FBI's documented web-shell and filename references for the MOVEit intrusion chain. Hunt them as source-backed leads and validate them in local evidence.1
- Sources
- 1
- Term
- Managed file transfer
| Term | Meaning Here | Sources |
|---|---|---|
| MOVEit Transfer | Progress Software's managed-file-transfer product. The public campaign targeted internet-facing MOVEit Transfer environments.1, 3 | 1, 3 |
| CVE-2023-34362 | NVD records a SQL injection vulnerability in MOVEit Transfer that could allow an unauthenticated attacker to gain access to the product database.2 | 2 |
| LEMURLOOT / human2.aspx | CISA/FBI's documented web-shell and filename references for the MOVEit intrusion chain. Hunt them as source-backed leads and validate them in local evidence.1 | 1 |
| Managed file transfer | A platform that often aggregates sensitive files and cross-organizational transfers, which makes data ownership and downstream notification scope central to the response.1, 3 | 1, 3 |
| Cl0p and TA505 context | CISA/FBI refer to CL0P as also known as TA505 in AA23-158A. MITRE tracks TA505 and notes ransomware campaigns involving Clop; IntelliOS retains this context with attribution boundaries.1, 7 | 1, 7 |
- Behavior / ATT&CK
- T1190 - Exploit Public-Facing Application
- Behavior / ATT&CK
- T1505.003 - Web Shell
- Behavior / ATT&CK
- T1136 / T1078 - Account Creation and Valid Accounts
- Campaign Mapping
- CISA/FBI describe attacker account activity after access. Review unexpected service accounts, roles, credential changes, and successful authentication in the investigation window.1
- Sources
- 1
| Behavior / ATT&CK | Campaign Mapping | Sources |
|---|---|---|
| T1190 - Exploit Public-Facing Application | CISA/FBI describe exploitation of CVE-2023-34362 to infiltrate the MOVEit Transfer web application. MITRE defines T1190 as exploitation of an internet-facing application for initial access.1, 8 | 1, 8 |
| T1505.003 - Web Shell | The advisory and Mandiant document LEMURLOOT, a web shell used to interact with compromised MOVEit environments. Hunt server-side artifacts and execution evidence.1, 5, 9 | 1, 5, 9 |
| T1136 / T1078 - Account Creation and Valid Accounts | CISA/FBI describe attacker account activity after access. Review unexpected service accounts, roles, credential changes, and successful authentication in the investigation window.1 | 1 |
| T1005 / T1560 - Data Collection and Archiving | Managed-file-transfer servers can hold many organizations' data. Review database and file access plus staging or archive behavior before defining the data-exposure scope.1 | 1 |
| T1041 - Exfiltration Over C2 Channel | CISA/FBI report data theft in the campaign. Correlate MFT, proxy, network, and storage telemetry to establish what left the environment.1 | 1 |
- Question
- If the server is patched, is the incident closed?
- Question
- Was this a normal ransomware encryption event?
- Question
- Does no human2.aspx mean no compromise?
- Question
- Does the Cl0p or TA505 label prove our data was stolen?
- Question
- Who may need to be involved?
| Question | Source-bound Answer |
|---|---|
| If the server is patched, is the incident closed? | No. Patching removes a known path forward; it does not determine whether exploitation or data theft occurred before remediation. Preserve and review historical server, database, account, storage, transfer, and network evidence.1, 3, 5, 6 |
| Was this a normal ransomware encryption event? | The MOVEit campaign was principally a mass data-theft and extortion operation. The absence of encrypted systems does not eliminate breach, contractual, regulatory, or notification exposure.1, 5 |
| Does no human2.aspx mean no compromise? | No. human2.aspx and LEMURLOOT are high-value leads, but an investigation should not rely on one filename. Mandiant documented alternate naming and behavior that can involve database, account, Azure Blob, and file-download activity.1, 5 |
| Does the Cl0p or TA505 label prove our data was stolen? | No. Campaign attribution describes the public threat assessment. Organization-specific impact requires evidence that a particular asset was vulnerable, accessed, and used to reach particular data.1, 7 |
| Who may need to be involved? | The answer follows the data: system and service owners, privacy and breach counsel, affected business units, third-party data owners, insurers, regulators, customers, and law enforcement as facts and obligations require.1, 5 |
These records answer different questions. The original mass exploitation centered on CVE-2023-34362; later 2023 MOVEit Transfer CVEs belong in remediation validation, not automatic campaign attribution.
- Reference
- CVE-2023-34362
- Role in This Brief
- Campaign entry vulnerability
- What It Establishes
- SQL injection in MOVEit Transfer with unauthenticated database access potential; actively exploited and added to KEV.
- Reference
- CVE-2023-35036
- Role in This Brief
- Follow-on June 9 patch record
- What It Establishes
- Progress issued a second patch for another SQL injection vulnerability after the original May 31 disclosure.
- Limit
- Progress's July 2023 FAQ said it had no indication this later issue was exploited at that time.6
- Reference
- CVE-2023-35708
- Role in This Brief
- Follow-on June 15/16 patch record
- What It Establishes
- Progress issued a third patch in the 2023 MOVEit Transfer remediation sequence.
- Limit
- Do not merge this CVE into the original Cl0p exploitation claim without separate evidence.6
| Reference | Role in This Brief | What It Establishes | Limit |
|---|---|---|---|
| CVE-2023-34362 | Campaign entry vulnerability | SQL injection in MOVEit Transfer with unauthenticated database access potential; actively exploited and added to KEV. | A vulnerable version or KEV status does not prove that a specific server was exploited.1, 2, 3, 4 |
| CVE-2023-35036 | Follow-on June 9 patch record | Progress issued a second patch for another SQL injection vulnerability after the original May 31 disclosure. | Progress's July 2023 FAQ said it had no indication this later issue was exploited at that time.6 |
| CVE-2023-35708 | Follow-on June 15/16 patch record | Progress issued a third patch in the 2023 MOVEit Transfer remediation sequence. | Do not merge this CVE into the original Cl0p exploitation claim without separate evidence.6 |
This public brief retains defensible detection and scoping observables, not raw attacker infrastructure or operational instructions. Validate against owned telemetry before blocking or attributing.
- Observable
- MOVEit Transfer exposure and remediation state
- Observable
- LEMURLOOT / human2.aspx
- Defender Use
- CISA/FBI list these as observed web-shell artifacts. Preserve the file, path, timestamps, process, and adjacent logs when found.1
- Sources
- 1
- Observable
- Unexpected MOVEit accounts or role changes
- Defender Use
- Review administrative, service, and database account creation or modification during the exploitation window, then correlate to web and transfer activity.1
- Sources
- 1
| Observable | Defender Use | Sources |
|---|---|---|
| MOVEit Transfer exposure and remediation state | Identify internet-facing MOVEit Transfer services and verify the exact remediation state against Progress guidance and the NVD affected-version record.2, 3 | 2, 3 |
| LEMURLOOT / human2.aspx | CISA/FBI list these as observed web-shell artifacts. Preserve the file, path, timestamps, process, and adjacent logs when found.1 | 1 |
| Unexpected MOVEit accounts or role changes | Review administrative, service, and database account creation or modification during the exploitation window, then correlate to web and transfer activity.1 | 1 |
| Abnormal file, database, archive, or egress activity | Investigate anomalous data reads, downloads, archive creation, database queries, and outbound transfers from MOVEit-related hosts.1 | 1 |
| Extortion or public leak-site claims | Retain as a case-management lead only. Validate any claimed victim or data set through owned records, legal review, and incident evidence.1, 5, 7 | 1, 5, 7 |
- Actor / Label
- CISA/FBI campaign assessment
- Attribution Boundary
- AA23-158A identifies the CL0P ransomware gang, also known as TA505, as exploiting CVE-2023-34362. That is the campaign attribution anchor for this brief.1
- Sources
- 1
| Actor / Label | Attribution Boundary | Sources |
|---|---|---|
| CISA/FBI campaign assessment | AA23-158A identifies the CL0P ransomware gang, also known as TA505, as exploiting CVE-2023-34362. That is the campaign attribution anchor for this brief.1 | 1 |
| MITRE TA505 context | MITRE describes TA505 as a cybercrime group and notes ransomware campaigns involving Clop. Use this as related actor context, not an automatic identity resolution for every claim.7 | 7 |
| Actor attribution does not establish impact | Campaign-level attribution does not establish that a specific organization was compromised, what files were accessed, or whether a third party has notification obligations. Those are evidence questions.1, 5, 7 | 1, 5, 7 |
- Audience
- Executive
- Audience
- Operations
| Audience | Decision-ready Point | Sources |
|---|---|---|
| Executive | MOVEit response is a data-access and trust exercise. A patch closes a path forward; evidence determines whether sensitive data was accessed during the vulnerable period.1, 3 | 1, 3 |
| Operations | Managed-file-transfer systems deserve the same disciplined inventory, segmentation, credential governance, log retention, and incident playbooks as other high-value public-facing applications.1, 3 | 1, 3 |
| Legal / privacy | The right first question is which confirmed data, data owners, and recipients were involved. Public victim lists may help prioritize review but cannot replace a scoped factual record.1 | 1 |
- Decision
- Open or close historical exposure review
- Minimum Evidence / Trigger
- Instance inventory, internet exposure, version, hosting model, and confirmed remediation date for the May 27–patch window.
- Likely Owner
- Vulnerability / infrastructure
- Decision
- Declare or expand an incident
- Minimum Evidence / Trigger
- LEMURLOOT-related artifacts, suspicious account/database activity, abnormal downloads, storage-token access, or unexplained egress.
- Likely Owner
- SOC / incident response
- Decision
- Begin notification analysis
- Minimum Evidence / Trigger
- Confirmed or reasonably supportable access to files mapped to people, customers, partners, contracts, or regulated data.
- Likely Owner
- Legal / privacy
- Decision
- Notify downstream data owners
- Minimum Evidence / Trigger
- Evidence that the MOVEit environment handled another organization's data during the affected window.
- Likely Owner
- Business / legal / third-party risk
| Decision | Minimum Evidence / Trigger | Likely Owner | Required Output |
|---|---|---|---|
| Open or close historical exposure review | Instance inventory, internet exposure, version, hosting model, and confirmed remediation date for the May 27–patch window. | Vulnerability / infrastructure | Asset-level exposure register with gaps and accountable owners.1, 2, 3, 5 |
| Declare or expand an incident | LEMURLOOT-related artifacts, suspicious account/database activity, abnormal downloads, storage-token access, or unexplained egress. | SOC / incident response | Preserved evidence, timeline, affected assets, and confidence-rated findings.1, 5 |
| Begin notification analysis | Confirmed or reasonably supportable access to files mapped to people, customers, partners, contracts, or regulated data. | Legal / privacy | Data-owner matrix, jurisdiction and contract analysis, notice decisions, and documented assumptions.1, 5 |
| Notify downstream data owners | Evidence that the MOVEit environment handled another organization's data during the affected window. | Business / legal / third-party risk | Recipient-specific facts, evidence boundary, requested actions, and communication record.1, 5 |
- Technology / Trust Path
- Internet-facing MFT applications
- Technology / Trust Path
- Web, application, and database trust
| Technology / Trust Path | Risk / Defensive Priority | Sources |
|---|---|---|
| Internet-facing MFT applications | An exposed file-transfer application can be both an initial-access path and a concentrated data repository. Maintain a complete asset owner, exposure, version, and evidence-retention record.1, 2, 3 | 1, 2, 3 |
| Web, application, and database trust | The documented SQL injection and web-shell path spans the web application, database, server file system, accounts, and data-transfer services. Scope across those layers.1, 2 | 1, 2 |
| Third-party data concentration | MFT systems can handle files on behalf of many affiliates, customers, or partners. Confirm ownership and routing from records before making downstream impact or notice decisions.1 | 1 |
- Tier / Class
- Tier 0 — Government
- Retained Sources
- CISA/FBI advisory, NVD, CISA KEV, CISA 2023 routinely exploited review
- What They Control
- Campaign assessment, CVE record, active exploitation, indicators, response priorities, and retrospective prioritization.
- Tier / Class
- Tier 0 — Vendor
- Retained Sources
- Progress May 31 advisory and July patch FAQ
- What They Control
- Affected product, remediation, patch sequence, and vendor-stated exploitation boundary for later CVEs.
- Tier / Class
- Tier 1 — Primary research
- Retained Sources
- Mandiant / Google Threat Intelligence
- What They Control
- Observed timing, rapid theft, LEMURLOOT functionality, account and Azure Blob activity, and incident-response lessons.
- Boundary
- Observed cases may not represent every intrusion or affiliate behavior.5
- Tier / Class
- Tier 5 — Framework
- Retained Sources
- MITRE TA505, T1190, and T1505.003
- What They Control
- Stable actor context and ATT&CK terminology for public-application exploitation and web shells.
- Tier / Class
- Tiers 6–8 — Leads only
- Retained Sources
- No social posts, actor claims, unsourced lists, or secondary victim counts retained as controlling evidence
- What They Control
- Lead generation only.
| Tier / Class | Retained Sources | What They Control | Boundary |
|---|---|---|---|
| Tier 0 — Government | CISA/FBI advisory, NVD, CISA KEV, CISA 2023 routinely exploited review | Campaign assessment, CVE record, active exploitation, indicators, response priorities, and retrospective prioritization. | Campaign-level records do not prove exposure or impact for one organization.1, 2, 4, 10 |
| Tier 0 — Vendor | Progress May 31 advisory and July patch FAQ | Affected product, remediation, patch sequence, and vendor-stated exploitation boundary for later CVEs. | Vendor guidance does not replace independent incident scoping.3, 6 |
| Tier 1 — Primary research | Mandiant / Google Threat Intelligence | Observed timing, rapid theft, LEMURLOOT functionality, account and Azure Blob activity, and incident-response lessons. | Observed cases may not represent every intrusion or affiliate behavior.5 |
| Tier 5 — Framework | MITRE TA505, T1190, and T1505.003 | Stable actor context and ATT&CK terminology for public-application exploitation and web shells. | Framework mappings organize behavior; they do not independently prove a local event.7, 8, 9 |
| Tiers 6–8 — Leads only | No social posts, actor claims, unsourced lists, or secondary victim counts retained as controlling evidence | Lead generation only. | Must be validated against a primary disclosure, authoritative source, or owned evidence before use.1, 5 |
- Issue
- Vulnerability and exploitation record
- Issue
- Cl0p and TA505 naming
- Issue
- Government advisory versus IR observations
- How IntelliOS Handles It
- CISA/FBI provide the public campaign assessment; Mandiant adds primary case observations such as rapid theft, alternate LEMURLOOT filenames, account manipulation, and Azure Blob credential access. Overlap raises confidence while case-specific details remain bounded to observed intrusions.1, 5
| Issue | How IntelliOS Handles It | Sources |
|---|---|---|
| Vulnerability and exploitation record | NVD supplies the vulnerability description and affected version information; CISA/FBI supply the active-exploitation and response narrative; Progress supplies vendor remediation. Use all three together.1, 2, 3 | 1, 2, 3 |
| Cl0p and TA505 naming | CISA/FBI's advisory uses CL0P and TA505 together. MITRE's TA505 group record provides broader cybercrime context. IntelliOS presents the relationship without asserting that all aliases or campaigns are identical.1, 7 | 1, 7 |
| Government advisory versus IR observations | CISA/FBI provide the public campaign assessment; Mandiant adds primary case observations such as rapid theft, alternate LEMURLOOT filenames, account manipulation, and Azure Blob credential access. Overlap raises confidence while case-specific details remain bounded to observed intrusions.1, 5 | 1, 5 |
| Public reporting versus organization evidence | The campaign is well documented, but individual victim, data, and downstream impact claims must be resolved from local logs, records, contractual context, and investigation findings.1, 5 | 1, 5 |
- Contributor
- CISA / FBI
- Role in This Brief
- Primary public source for the CL0P assessment, technical indicators, recommended actions, and active-exploitation timeline.1
- Sources
- 1
- Contributor
- Progress Software
- Role in This Brief
- Vendor source for MOVEit Transfer vulnerability remediation and implementation guidance.3
- Sources
- 3
- Contributor
- NIST NVD / CISA KEV
| Contributor | Role in This Brief | Sources |
|---|---|---|
| CISA / FBI | Primary public source for the CL0P assessment, technical indicators, recommended actions, and active-exploitation timeline.1 | 1 |
| Progress Software | Vendor source for MOVEit Transfer vulnerability remediation and implementation guidance.3 | 3 |
| NIST NVD / CISA KEV | Authoritative CVE detail, affected-version context, and known-exploited-vulnerability status.2, 4 | 2, 4 |
| Mandiant / Google Threat Intelligence | Primary incident-response observations for early exploitation, rapid data theft, LEMURLOOT functions, account manipulation, and connected Azure Blob access.5 | 5 |
| MITRE ATT&CK | Source for TA505 actor context and framework references for the documented behaviors.7, 8, 9 | 7, 8, 9 |
- Observed Example
- Pre-disclosure exploitation
- Source-backed Fact
- Mandiant observed exploitation beginning as early as May 27, before Progress's May 31 public advisory.
- Observed Example
- Rapid data theft
- Source-backed Fact
- Mandiant reported that in some intrusions data theft occurred within minutes of exploitation.
- Operational Lesson
- Do not assume a short exposure interval was harmless; prioritize database, file-download, storage, and egress evidence.5
- Observed Example
- Cloud-storage reach
- Source-backed Fact
- LEMURLOOT functionality included retrieving MOVEit configuration information, including Azure Blob storage credentials in applicable environments.
- Operational Lesson
- Scope beyond the web server when MOVEit was connected to external storage or held reusable service credentials.5
- Observed Example
- Three-patch remediation sequence
- Source-backed Fact
- Progress documented May 31, June 9, and June 15/16 patches for three separate 2023 MOVEit Transfer CVEs.
- Operational Lesson
- A single patch ticket is insufficient; verify version-specific completion of the full applicable vendor sequence.6
| Observed Example | Source-backed Fact | Operational Lesson |
|---|---|---|
| Pre-disclosure exploitation | Mandiant observed exploitation beginning as early as May 27, before Progress's May 31 public advisory. | Review historical exposure and logs; current patch state alone cannot answer whether the server was accessed.3, 5 |
| Rapid data theft | Mandiant reported that in some intrusions data theft occurred within minutes of exploitation. | Do not assume a short exposure interval was harmless; prioritize database, file-download, storage, and egress evidence.5 |
| Cloud-storage reach | LEMURLOOT functionality included retrieving MOVEit configuration information, including Azure Blob storage credentials in applicable environments. | Scope beyond the web server when MOVEit was connected to external storage or held reusable service credentials.5 |
| Three-patch remediation sequence | Progress documented May 31, June 9, and June 15/16 patches for three separate 2023 MOVEit Transfer CVEs. | A single patch ticket is insufficient; verify version-specific completion of the full applicable vendor sequence.6 |
This brief deliberately does not reproduce an unsourced victim list. It separates direct public records, campaign-wide reporting, and organization-specific proof so scoping teams do not mistake one for another.
- Disclosure Class
- Government campaign assessment
- What the Public Record Says
- CISA/FBI describe a broad Cl0p MOVEit exploitation campaign and provide technical indicators and response guidance.
- Appropriate Use
- Establish threat plausibility, timing, and investigation priorities.
- Limit
- Not a complete or adjudicated victim inventory.1
- Disclosure Class
- Primary IR observations
- What the Public Record Says
- Mandiant observed multiple intrusions across industries and countries and documented common exploitation and theft behavior.
- Appropriate Use
- Shape hypotheses and evidence collection.
- Limit
- The observed case set does not prove any unexamined organization was affected.5
- Disclosure Class
- Actor or secondary victim claim
- What the Public Record Says
- Not retained as a controlling row without an attributable organization disclosure or authoritative corroboration.
- Appropriate Use
- Case-management lead only.
- Disclosure Class
- Organization-specific impact
- What the Public Record Says
- Must be established from the organization's asset, access, file, data-owner, and disclosure evidence.
- Appropriate Use
- Controls notification, regulatory, contractual, insurance, and customer decisions.
| Disclosure Class | What the Public Record Says | Appropriate Use | Limit |
|---|---|---|---|
| Government campaign assessment | CISA/FBI describe a broad Cl0p MOVEit exploitation campaign and provide technical indicators and response guidance. | Establish threat plausibility, timing, and investigation priorities. | Not a complete or adjudicated victim inventory.1 |
| Primary IR observations | Mandiant observed multiple intrusions across industries and countries and documented common exploitation and theft behavior. | Shape hypotheses and evidence collection. | The observed case set does not prove any unexamined organization was affected.5 |
| Actor or secondary victim claim | Not retained as a controlling row without an attributable organization disclosure or authoritative corroboration. | Case-management lead only. | Claimed, confirmed, direct, and downstream entities are often conflated.1, 5 |
| Organization-specific impact | Must be established from the organization's asset, access, file, data-owner, and disclosure evidence. | Controls notification, regulatory, contractual, insurance, and customer decisions. | Cannot be inferred solely from product use or campaign attribution.1, 3, 5 |
- Item
- CVE-2023-34362 / KEV
- Status
- Added to CISA KEV on June 2, 2023 after active exploitation; original MOVEit campaign vulnerability.
- Response Meaning
- Treat any potentially exposed, unremediated instance in the relevant window as an urgent retrospective investigation and remediation matter.
- Item
- CVE-2023-35036
- Status
- Separate June 2023 MOVEit Transfer SQL injection vulnerability addressed in Progress's second patch release.
- Response Meaning
- Verify the applicable June 9 patch or a later cumulative fixed release.
- Boundary
- Progress reported no indication of exploitation at the time of its July FAQ.6
- Item
- CVE-2023-35708
- Status
- Separate June 2023 MOVEit Transfer SQL injection vulnerability addressed in the third patch release.
- Response Meaning
- Verify the applicable June 15/16 patch or a later cumulative fixed release.
- Boundary
- Do not attribute exploitation to Cl0p without evidence specific to this CVE.6
| Item | Status | Response Meaning | Boundary |
|---|---|---|---|
| CVE-2023-34362 / KEV | Added to CISA KEV on June 2, 2023 after active exploitation; original MOVEit campaign vulnerability. | Treat any potentially exposed, unremediated instance in the relevant window as an urgent retrospective investigation and remediation matter. | KEV is prioritization evidence, not proof of local compromise.1, 2, 4, 10 |
| CVE-2023-35036 | Separate June 2023 MOVEit Transfer SQL injection vulnerability addressed in Progress's second patch release. | Verify the applicable June 9 patch or a later cumulative fixed release. | Progress reported no indication of exploitation at the time of its July FAQ.6 |
| CVE-2023-35708 | Separate June 2023 MOVEit Transfer SQL injection vulnerability addressed in the third patch release. | Verify the applicable June 15/16 patch or a later cumulative fixed release. | Do not attribute exploitation to Cl0p without evidence specific to this CVE.6 |
- Lifecycle / ATT&CK
- Initial Access — T1190
- Campaign Behavior
- Exploit CVE-2023-34362 in an internet-facing MOVEit Transfer application.
- Evidence to Seek
- Exposure history, exact version, IIS/MOVEit requests, application and database anomalies.
- Lifecycle / ATT&CK
- Persistence — T1505.003
- Campaign Behavior
- Use LEMURLOOT as a server-side web shell, including human2.aspx or alternate naming.
- Evidence to Seek
- Web-root files, hashes, timestamps, web requests, account changes, process and database activity.
- Lifecycle / ATT&CK
- Credential / Cloud Access
- Campaign Behavior
- Retrieve configuration and, where present, Azure Blob credentials; create or manipulate MOVEit accounts.
- Evidence to Seek
- Configuration access, token use, cloud-storage logs, account creation/deletion, role changes.
- Defensive Breakpoint
- Rotate exposed secrets, scope connected storage, restrict service-account privileges, and alert on administrative changes.5
- Lifecycle / ATT&CK
- Collection
- Campaign Behavior
- Enumerate folders and files and select data held by the managed-file-transfer platform.
- Evidence to Seek
- Database queries, file metadata, abnormal downloads, transfer history, and data-owner mapping.
- Lifecycle / ATT&CK
- Exfiltration / Extortion
- Campaign Behavior
- Download data rapidly and use theft to pressure affected organizations without requiring enterprise-wide encryption.
- Evidence to Seek
- Large downloads, egress, archives, cloud access, extortion communications, and matching file evidence.
| Lifecycle / ATT&CK | Campaign Behavior | Evidence to Seek | Defensive Breakpoint |
|---|---|---|---|
| Initial Access — T1190 | Exploit CVE-2023-34362 in an internet-facing MOVEit Transfer application. | Exposure history, exact version, IIS/MOVEit requests, application and database anomalies. | Remove public exposure while remediating; maintain rapid external-asset and KEV response.1, 2, 3, 5, 8 |
| Persistence — T1505.003 | Use LEMURLOOT as a server-side web shell, including human2.aspx or alternate naming. | Web-root files, hashes, timestamps, web requests, account changes, process and database activity. | File-integrity monitoring, restricted write paths, web-shell analytics, and preserved server evidence.1, 5, 9 |
| Credential / Cloud Access | Retrieve configuration and, where present, Azure Blob credentials; create or manipulate MOVEit accounts. | Configuration access, token use, cloud-storage logs, account creation/deletion, role changes. | Rotate exposed secrets, scope connected storage, restrict service-account privileges, and alert on administrative changes.5 |
| Collection | Enumerate folders and files and select data held by the managed-file-transfer platform. | Database queries, file metadata, abnormal downloads, transfer history, and data-owner mapping. | Behavioral analytics for bulk access and defensible transfer-log retention.1, 5 |
| Exfiltration / Extortion | Download data rapidly and use theft to pressure affected organizations without requiring enterprise-wide encryption. | Large downloads, egress, archives, cloud access, extortion communications, and matching file evidence. | Egress monitoring, rate and volume alerts, segmentation, rapid credential revocation, and legal evidence preservation.1, 5 |
- Source
- CISA / FBI AA23-158A
- Weight
- Controlling
- Claims It Controls
- Public campaign assessment, exploitation timing, Cl0p naming, LEMURLOOT indicators, mitigations, and response guidance.
- Known Limits
- Not a complete victim list and not proof of organization-specific exposure.1
- Source
- NVD and CISA KEV
- Weight
- Controlling
- Claims It Controls
- CVE definition, affected-product context, active-exploitation status, and prioritization.
- Source
- Progress advisories / FAQ
- Weight
- Controlling for product
- Claims It Controls
- MOVEit remediation instructions, patch chronology, and vendor-stated boundaries for follow-on CVEs.
- Source
- Mandiant / Google Threat Intelligence
- Weight
- High
- Claims It Controls
- Primary incident observations, timing, LEMURLOOT functionality, rapid theft, account and cloud-storage behavior.
- Known Limits
- Case observations may not describe every intrusion or actor variation.5
- Source
- MITRE ATT&CK
- Weight
- Contextual
- Claims It Controls
- TA505 relationship and normalized behavior vocabulary.
- Source
- CISA 2023 routinely exploited review
- Weight
- Corroborating
- Claims It Controls
- Retrospective confirmation that CVE-2023-34362 remained a major routinely exploited vulnerability.
- Known Limits
- Adds prioritization context rather than new organization-specific facts.10
| Source | Weight | Claims It Controls | Known Limits |
|---|---|---|---|
| CISA / FBI AA23-158A | Controlling | Public campaign assessment, exploitation timing, Cl0p naming, LEMURLOOT indicators, mitigations, and response guidance. | Not a complete victim list and not proof of organization-specific exposure.1 |
| NVD and CISA KEV | Controlling | CVE definition, affected-product context, active-exploitation status, and prioritization. | Do not establish local exploitation, file access, or attribution.2, 4 |
| Progress advisories / FAQ | Controlling for product | MOVEit remediation instructions, patch chronology, and vendor-stated boundaries for follow-on CVEs. | Do not replace forensic validation of a customer's environment.3, 6 |
| Mandiant / Google Threat Intelligence | High | Primary incident observations, timing, LEMURLOOT functionality, rapid theft, account and cloud-storage behavior. | Case observations may not describe every intrusion or actor variation.5 |
| MITRE ATT&CK | Contextual | TA505 relationship and normalized behavior vocabulary. | Framework records do not independently establish campaign responsibility or local impact.7, 8, 9 |
| CISA 2023 routinely exploited review | Corroborating | Retrospective confirmation that CVE-2023-34362 remained a major routinely exploited vulnerability. | Adds prioritization context rather than new organization-specific facts.10 |
CARDS Campaign
Cl0p MOVEit Transfer Mass Exploitation Campaign Card
Canonical campaign record with CVE linkage, CISA/FBI citations, ATT&CK mappings, defensive takeaways, and this PANDA brief.
CARDS Actor
Cl0p Actor Card
Actor profile for source-bound CL0P/TA505 context, managed-file-transfer targeting, and the linked MOVEit campaign.
Create an account and sign-in to use this card.
Record your personal notes and comments in this card related to this brief.
- Version
- v1.2
- Date
- Jul 18, 2026
- Changes
- Completed a 32-card FortiBleed-standard review. Rebuilt Research Framing, separated previously duplicated card content, added Mandiant incident-response observations and the Progress patch sequence, expanded citations, and added decision, evidence, lifecycle, disclosure, and source-weighting tables.
- Version
- v1.1
- Date
- Jul 18, 2026
- Changes
- Reworked the BLUF for scoping and executive briefings; clarified mass data-theft, retrospective exposure, hunting, downstream data-owner, and attribution boundaries; enabled daily AI Agent monitoring and Page Alerts.
- Version
- v1.0
- Date
- Jul 11, 2026
- Changes
- Initial source-backed IntelliOS Flash Threat Intel Brief with reciprocal CARDS links, source reconciliation, public-disclosure boundaries, CVE/KEV context, and incident-response guidance.
| Version | Date | Changes |
|---|---|---|
| v1.2 | Jul 18, 2026 | Completed a 32-card FortiBleed-standard review. Rebuilt Research Framing, separated previously duplicated card content, added Mandiant incident-response observations and the Progress patch sequence, expanded citations, and added decision, evidence, lifecycle, disclosure, and source-weighting tables. |
| v1.1 | Jul 18, 2026 | Reworked the BLUF for scoping and executive briefings; clarified mass data-theft, retrospective exposure, hunting, downstream data-owner, and attribution boundaries; enabled daily AI Agent monitoring and Page Alerts. |
| v1.0 | Jul 11, 2026 | Initial source-backed IntelliOS Flash Threat Intel Brief with reciprocal CARDS links, source reconciliation, public-disclosure boundaries, CVE/KEV context, and incident-response guidance. |
- #
- 1
- Tier
- Tier 0 - Government advisory
- Publisher
- CISA / FBI
- Published
- June 7, 2023
- Why Used
- Primary public campaign record for the active-exploitation timeline, CL0P assessment, LEMURLOOT and human2.aspx indicators, techniques, and recommended response.
- #
- 2
- Tier
- Tier 0 - Government vulnerability record
- Publisher
- NIST NVD
- Published
- May 2023; maintained record
- Why Used
- Authoritative CVE description, affected-version context, vendor references, and CISA KEV indication.
- Source
- CVE-2023-34362
- #
- 3
- Tier
- Tier 0 - Vendor advisory
- Publisher
- Progress Software
- Published
- May 31, 2023
- Why Used
- Vendor remediation and product-specific guidance for the original critical MOVEit Transfer vulnerability.
- #
- 4
- Tier
- Tier 0 - Government prioritization
- Publisher
- CISA
- Published
- June 2, 2023
- Why Used
- KEV inclusion and active-exploitation prioritization context.
- #
- 5
- Tier
- Tier 1 - Primary incident-response research
- Publisher
- Mandiant / Google Threat Intelligence
- Published
- June 2, 2023; updated June 2023
- Why Used
- Primary incident-response observations for exploitation beginning May 27, rapid data theft, LEMURLOOT functionality and filenames, account manipulation, Azure Blob credential access, affected industries, and campaign attribution evolution.
- #
- 6
- Tier
- Tier 0 - Vendor patch record
- Publisher
- Progress Software
- Published
- Updated July 5, 2023
- Why Used
- Vendor chronology for the May 31, June 9, and June 15/16 patches covering CVE-2023-34362, CVE-2023-35036, and CVE-2023-35708, including the vendor's then-current exploitation boundary for the later CVEs.
- #
- 7
- Tier
- Tier 0 - Authoritative framework
- Publisher
- MITRE ATT&CK
- Published
- Maintained framework record
- Why Used
- Source-bound cybercrime and Clop-related ransomware campaign context for TA505.
- Source
- TA505, Group G0092
- #
- 8
- Tier
- Tier 5 - Framework
- Publisher
- MITRE ATT&CK
- Published
- Maintained framework record
- Why Used
- Framework reference for exploitation of the internet-facing MOVEit application.
- #
- 9
- Tier
- Tier 5 - Framework
- Publisher
- MITRE ATT&CK
- Published
- Maintained framework record
- Why Used
- Framework reference for the LEMURLOOT web-shell behavior documented by CISA/FBI and Mandiant.
- Source
- T1505.003 - Web Shell
- #
- 10
- Tier
- Tier 0 - Government retrospective
- Publisher
- CISA / NSA / FBI and partners
- Published
- November 12, 2024
- Why Used
- Retrospective government confirmation that CVE-2023-34362 was among the vulnerabilities routinely exploited in 2023 and remained a high-priority lesson for edge and public-facing application defense.
| # | Tier | Publisher | Published | Why Used | Source |
|---|---|---|---|---|---|
| 1 | Tier 0 - Government advisory | CISA / FBI | June 7, 2023 | Primary public campaign record for the active-exploitation timeline, CL0P assessment, LEMURLOOT and human2.aspx indicators, techniques, and recommended response. | #StopRansomware: CL0P Ransomware Gang Exploits CVE-2023-34362 MOVEit Vulnerability |
| 2 | Tier 0 - Government vulnerability record | NIST NVD | May 2023; maintained record | Authoritative CVE description, affected-version context, vendor references, and CISA KEV indication. | CVE-2023-34362 |
| 3 | Tier 0 - Vendor advisory | Progress Software | May 31, 2023 | Vendor remediation and product-specific guidance for the original critical MOVEit Transfer vulnerability. | MOVEit Transfer Critical Vulnerability - 31 May 2023 |
| 4 | Tier 0 - Government prioritization | CISA | June 2, 2023 | KEV inclusion and active-exploitation prioritization context. | Known Exploited Vulnerabilities Catalog - CVE-2023-34362 |
| 5 | Tier 1 - Primary incident-response research | Mandiant / Google Threat Intelligence | June 2, 2023; updated June 2023 | Primary incident-response observations for exploitation beginning May 27, rapid data theft, LEMURLOOT functionality and filenames, account manipulation, Azure Blob credential access, affected industries, and campaign attribution evolution. | Zero-Day Exploitation of MOVEit Transfer |
| 6 | Tier 0 - Vendor patch record | Progress Software | Updated July 5, 2023 | Vendor chronology for the May 31, June 9, and June 15/16 patches covering CVE-2023-34362, CVE-2023-35036, and CVE-2023-35708, including the vendor's then-current exploitation boundary for the later CVEs. | MOVEit Transfer and MOVEit Cloud Vulnerabilities Customer FAQ |
| 7 | Tier 0 - Authoritative framework | MITRE ATT&CK | Maintained framework record | Source-bound cybercrime and Clop-related ransomware campaign context for TA505. | TA505, Group G0092 |
| 8 | Tier 5 - Framework | MITRE ATT&CK | Maintained framework record | Framework reference for exploitation of the internet-facing MOVEit application. | T1190 - Exploit Public-Facing Application |
| 9 | Tier 5 - Framework | MITRE ATT&CK | Maintained framework record | Framework reference for the LEMURLOOT web-shell behavior documented by CISA/FBI and Mandiant. | T1505.003 - Web Shell |
| 10 | Tier 0 - Government retrospective | CISA / NSA / FBI and partners | November 12, 2024 | Retrospective government confirmation that CVE-2023-34362 was among the vulnerabilities routinely exploited in 2023 and remained a high-priority lesson for edge and public-facing application defense. | 2023 Top Routinely Exploited Vulnerabilities |
