/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Microsoft says the Clop ransomware group is exploiting a zero-day in IT support tool SysAid in “limited” attacks to access corporate servers and deploy Clop

blog post coming ASAP😜 Big thanks to @gleeda @HuskyHacksMK @DaveKleinatland @calebjstewart and the whole @HuntressLabs crew helping dig into this one! [image] @swiftonsecurity : I'm endlessly fascinated by, and looking for, factors malware panics on. In this case, it lists all processes, looks for Sophos, and if you're running it, gives up. That's the only vendor they do that for. So weird. https://www.sysaid.com/... @sophosxops : From @SysAid's write up about active attacks attributed to Cl0p. “- Checks all running processes for any process beginning with the name “Sophos” [and only Sophos] and if found, exits. - If no matching processes are found, starts the user.exe malware.” https://www.sysaid.com/... [image] Daniel Stepanic / @danielstepanic : Heads up! Our team is observing post-compromise activity by #TA505 from 0-day used last week targeting IT service management product, SysAid On-Premise. Raj Samani / @raj_samani : Our latest @rapid7 analysis details CVE-2023-47426, a zero-day path traversal vulnerability affecting on-premise SysAid servers. Including IoCs and @velocidex artifact: https://www.rapid7.com/... [image] @msftsecintel : Organizations using SysAid should apply the patch and look for any signs of exploitation prior to patching, as Lace Tempest will likely use their access to exfiltrate data and deploy Clop ransomware. https://www.sysaid.com/... Caitlin Condon / @catc0n : A small bit of potentially good news on the new SysAid 0day (CVE-2023-47246) — it looks like there are only a few hundred servers exposed to the internet. https://www.rapid7.com/... Lindsey O'Donnell Welch / @lindseyod123 : In the attacks that Microsoft and SysAid have seen, the attackers exploited the vulnerability to upload a webshell and other files to the target system. https://duo.com/... Jon Greig / @jgreigj : Clop is back, now exploiting a new zero-day in SysAid IT support software. A patch has been released for CVE-2023-47246 @TheRecord_Media #SysAid #MoveIt #Clop https://therecord.media/... @msftsecintel : Lace Tempest (which overlaps with threat actors tracked by other researchers as FIN11 and TA505) similarly exploited a 0-day vulnerability in MOVEit Transfer in June: https://twitter.com/... @zoomeye_team : 🚨🚨A 0day vulnerability exploited by SysAid On-Prem Software in the wild was discovered by the Microsoft Threat Intelligence Team @sysaid CVE-2023-47246 #ZoomEyeDork app:"SysAid On-Prem Software" About 860 results,mainly distributed in Italy,the United States and other... LinkedIn: Peter Fogarty : Russian digital extortion gang behind a raft of attacks on file transfer applications is now targeting a newly patched vulnerability in SysAid IT help desk support software …

BleepingComputer Bill Toulas

Discussion

  • @msftsecintel @msftsecintel on x
    Microsoft has discovered exploitation of a 0-day vulnerability in the SysAid IT support software in limited attacks by Lace Tempest, a threat actor that distributes Clop ransomware. Microsoft notified SysAid about the issue (CVE-2023-47246), which they immediately patched.
  • @msftsecintel @msftsecintel on x
    After exploiting the vulnerability, Lace Tempest issued commands via the SysAid software to deliver a malware loader for the Gracewire malware. This is typically followed by human-operated activity, including lateral movement, data theft, and ransomware deployment.
  • @sophosxops @sophosxops on x
    From @SysAid's write up about active attacks attributed to Cl0p. “- Checks all running processes for any process beginning with the name “Sophos” [and only Sophos] and if found, exits. - If no matching processes are found, starts the user.exe malware.” https://www.sysaid.com/... …
  • @danielstepanic Daniel Stepanic on x
    Heads up! Our team is observing post-compromise activity by #TA505 from 0-day used last week targeting IT service management product, SysAid On-Premise.
  • @_johnhammond John Hammond on x
    We've recreated a proof-of-concept for the SysAid CVE-2023-47246 remote code execution and compromise — blog post coming ASAP😜 Big thanks to @gleeda @HuskyHacksMK @DaveKleinatland @calebjstewart and the whole @HuntressLabs crew helping dig into this one! [image]
  • @swiftonsecurity @swiftonsecurity on x
    I'm endlessly fascinated by, and looking for, factors malware panics on. In this case, it lists all processes, looks for Sophos, and if you're running it, gives up. That's the only vendor they do that for. So weird. https://www.sysaid.com/...
  • @raj_samani Raj Samani on x
    Our latest @rapid7 analysis details CVE-2023-47426, a zero-day path traversal vulnerability affecting on-premise SysAid servers. Including IoCs and @velocidex artifact: https://www.rapid7.com/... [image]
  • @msftsecintel @msftsecintel on x
    Organizations using SysAid should apply the patch and look for any signs of exploitation prior to patching, as Lace Tempest will likely use their access to exfiltrate data and deploy Clop ransomware. https://www.sysaid.com/...
  • @catc0n Caitlin Condon on x
    A small bit of potentially good news on the new SysAid 0day (CVE-2023-47246) — it looks like there are only a few hundred servers exposed to the internet. https://www.rapid7.com/...
  • @lindseyod123 Lindsey O'Donnell Welch on x
    In the attacks that Microsoft and SysAid have seen, the attackers exploited the vulnerability to upload a webshell and other files to the target system. https://duo.com/...
  • @jgreigj Jon Greig on x
    Clop is back, now exploiting a new zero-day in SysAid IT support software. A patch has been released for CVE-2023-47246 @TheRecord_Media #SysAid #MoveIt #Clop https://therecord.media/...
  • @msftsecintel @msftsecintel on x
    Lace Tempest (which overlaps with threat actors tracked by other researchers as FIN11 and TA505) similarly exploited a 0-day vulnerability in MOVEit Transfer in June: https://twitter.com/...
  • @zoomeye_team @zoomeye_team on x
    🚨🚨A 0day vulnerability exploited by SysAid On-Prem Software in the wild was discovered by the Microsoft Threat Intelligence Team @sysaid CVE-2023-47246 #ZoomEyeDork app:"SysAid On-Prem Software" About 860 results,mainly distributed in Italy,the United States and other...