Cl0p has systematically targeted internet-facing managed file transfer and related enterprise applications, often using zero-day exploits, pre-attack reconnaissance, and reused infrastructure across campaigns such as MOVEit, Oracle E-Business Suite, and Centrestack. The report finds that Cl0p’s seasonal Q4 activity, long reconnaissance windows, and architectural weaknesses in MFT systems create strong defensive opportunities through WAF allowlisting, log retention, and retro-hunting. #Cl0p #MOVEit #OracleEBusinessSuite #Centrestack
Keypoints
- Cl0p has focused across nine campaigns on internet-facing managed file transfer and adjacent enterprise systems, including Accellion FTA, GoAnywhere MFT, MOVEit Transfer, Cleo MFT, Oracle E-Business Suite, and Centrestack.
- The group shows strategic specialization, having deployed novel exploits in seven of nine campaigns rather than opportunistic attacks.
- Campaign timing is highly patterned, with long dormant periods and a strong preference for Q4 activity, especially around major holidays.
- Cl0p often conducts reconnaissance months or even years before exploitation, as seen in the MOVEit and Oracle E-Business Suite cases.
- Infrastructure reuse exists, but most observed ASNs are single-use, meaning historical IOC-only detection will miss much of the activity.
- The report recommends WAF allowlisting, long log retention, seasonal monitoring, and retro-hunting after any new MFT vulnerability disclosure.
- Centrestack was the most recent confirmed campaign, with initial compromise on Thanksgiving Day 2025 and attacker infrastructure later observed hosting a Centrestack instance in early 2026.
MITRE Techniques
- [T1190 ] Exploit Public-Facing Application – Cl0p compromises internet-facing MFT and enterprise applications by targeting exposed web apps and services (‘internet-facing application that processes, stores, or transfers files’ and ‘the attack chain progressed from SQL injection to web shell deployment’).
- [T1071.001 ] Application Layer Protocol: Web Protocols – The group conducts probing and exploitation through HTTP/HTTPS web traffic against exposed application endpoints (‘automated probing of MOVEit API endpoints’ and ‘traffic targeting Centrestack devices’).
- [T1595.002 ] Active Scanning: Vulnerability Scanning – Cl0p performs advance reconnaissance against target infrastructure long before exploitation (‘conducting reconnaissance activity against MOVEit infrastructure extending back approximately two years’ and ‘suspicious traffic targeting Oracle EBS’).
- [T1059.005 ] Command and Scripting Interpreter: Visual Basic – The LEMURLOOT web shell executed on the compromised server to carry out post-exploitation actions (‘the web shell invoked MOVEit’s native GetBaseKeyProvider() function’).
- [T1505.003 ] Server Software Component: Web Shell – Cl0p deployed LEMURLOOT as a web shell on MOVEit to maintain access and enable decryption (‘web shell deployment (LEMURLOOT)’).
- [T1003 ] OS Credential Dumping – Not explicitly described as credential dumping, but the report indicates attacker use of application-held secret material to recover protected data via the compromised app (‘the attacker inherits the application’s own ability to decrypt stored data’).
- [T1027 ] Obfuscated Files or Information – The use of varied infrastructure and alternate IPs for follow-on exploitation helps conceal operational continuity (‘exploitation from alternate infrastructure’ and ‘overlapping infrastructure for both activities’).
Indicators of Compromise
- [IP addresses ] Pre-attack scanning and exploitation infrastructure for MOVEit, GoAnywhere, Oracle EBS, and Centrestack – 45.129.137[.]232, 92.118.36[.]233, and 200.107.207[.]26
- [IP addresses ] Alternate exploitation and attacker traffic during Oracle EBS and Centrestack activity – 161.97.99[.]49, 147.124[.]x.x, and other 1 more item
- [Domains ] Extortion and notification domains used after Oracle EBS compromise – pubstorm.com, pubstorm.net
- [File paths ] Exploited or blocked application endpoints in MOVEit attacks – /moveitisapi/moveitisapi.dll, /human2.aspx
- [ASNs ] Hosting and reconnaissance infrastructure associated with Cl0p operations – AS215929 (Data Campus), AS215829 (Smart Digital Ideas DOO), and other 1 more item
- [File / application names ] Targeted products and components frequently referenced in the campaigns – MOVEit Transfer, Centrestack/TrioFox, and LEMURLOOT
Read more: https://www.team-cymru.com/post/cl0p-ransomware-mft-attack-pattern-threat-intelligence