Google Mandiant and GTIG are investigating suspected Cl0p ransomware activity targeting Oracle E-Business Suite data theft and extortion. The threat involves mass data breaches, large ransom demands, and links to the FIN11 group, emphasizing the rising danger of cyberattacks on enterprise systems. #Cl0p #FIN11 #OracleE-BusinessSuite
Keypoints
- The Cl0p ransomware group is suspected of hacking Oracle E-Business Suite and demanding large ransoms.
- Attackers exploited default password reset vulnerabilities to steal user credentials.
- Both verified and suspected data breaches include stolen financial and operational information.
- FIN11, a financially motivated threat group, is linked to the compromised accounts used in extortion campaigns.
- Researchers advise organizations to investigate for indicators of compromise and prevent further attacks.