Ransomware

Dozens of Cleo hack victims extorted by Clop ransomware

2d illustration ransomware computer virus

Sixty-six organizations purportedly compromised in attacks involving the exploitation of a zero-day vulnerability impacting various Cleo managed file transfer platforms were warned by the Clop ransomware gang to have their names publicly disclosed should they refuse to engage in ransom payment negotiations within 48 hours after Christmas Eve, BleepingComputer reports.

More companies are expected to have been breached as a result of the attacks, with the figure noted by Clop to indicate the number of firms that have not yet responded to its private communications that include a link to a secure chat channel for negotiations.

Some of the organizations impacted by Clop could also be determined by verifying the threat group's clues and the owners of publicly exposed Cleo servers, according to Macnica researcher Yutaka Sejiyama.

Such a development continues Clop ransomware's targeting of vulnerable MFTs, having previously compromised organizations in intrusions exploiting MOVEit, Fortra GoAnywhere, and Accellion FTA zero-days.

An In-Depth Guide to Ransomware

Get essential knowledge and practical strategies to protect your organization from ransomware attacks.

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds