Microsoft says the Clop ransomware group is exploiting a zero-day in IT support tool SysAid in “limited” attacks to access corporate servers and deploy Clop
blog post coming ASAP😜 Big thanks to @gleeda @HuskyHacksMK @DaveKleinatland @calebjstewart and the whole @HuntressLabs crew helping dig into this one! [image] @swiftonsecurity : I'm endlessly fascinated by, and looking for, factors malware panics on. In this case, it lists all processes, looks for Sophos, and if you're running it, gives up. That's the only vendor they do that for. So weird. https://www.sysaid.com/... @sophosxops : From @SysAid's write up about active attacks attributed to Cl0p. “- Checks all running processes for any process beginning with the name “Sophos” [and only Sophos] and if found, exits. - If no matching processes are found, starts the user.exe malware.” https://www.sysaid.com/... [image] Daniel Stepanic / @danielstepanic : Heads up! Our team is observing post-compromise activity by #TA505 from 0-day used last week targeting IT service management product, SysAid On-Premise. Raj Samani / @raj_samani : Our latest @rapid7 analysis details CVE-2023-47426, a zero-day path traversal vulnerability affecting on-premise SysAid servers. Including IoCs and @velocidex artifact: https://www.rapid7.com/... [image] @msftsecintel : Organizations using SysAid should apply the patch and look for any signs of exploitation prior to patching, as Lace Tempest will likely use their access to exfiltrate data and deploy Clop ransomware. https://www.sysaid.com/... Caitlin Condon / @catc0n : A small bit of potentially good news on the new SysAid 0day (CVE-2023-47246) — it looks like there are only a few hundred servers exposed to the internet. https://www.rapid7.com/... Lindsey O'Donnell Welch / @lindseyod123 : In the attacks that Microsoft and SysAid have seen, the attackers exploited the vulnerability to upload a webshell and other files to the target system. https://duo.com/... Jon Greig / @jgreigj : Clop is back, now exploiting a new zero-day in SysAid IT support software. A patch has been released for CVE-2023-47246 @TheRecord_Media #SysAid #MoveIt #Clop https://therecord.media/... @msftsecintel : Lace Tempest (which overlaps with threat actors tracked by other researchers as FIN11 and TA505) similarly exploited a 0-day vulnerability in MOVEit Transfer in June: https://twitter.com/... @zoomeye_team : 🚨🚨A 0day vulnerability exploited by SysAid On-Prem Software in the wild was discovered by the Microsoft Threat Intelligence Team @sysaid CVE-2023-47246 #ZoomEyeDork app:"SysAid On-Prem Software" About 860 results,mainly distributed in Italy,the United States and other... LinkedIn: Peter Fogarty : Russian digital extortion gang behind a raft of attacks on file transfer applications is now targeting a newly patched vulnerability in SysAid IT help desk support software …
Microsoft has discovered exploitation of a 0-day vulnerability in the SysAid IT support software in limited attacks by Lace Tempest, a threat actor that distributes Clop ransomware. Microsoft notified SysAid about the issue (CVE-2023-47246), which they immediately patched.
After exploiting the vulnerability, Lace Tempest issued commands via the SysAid software to deliver a malware loader for the Gracewire malware. This is typically followed by human-operated activity, including lateral movement, data theft, and ransomware deployment.
From @SysAid's write up about active attacks attributed to Cl0p. “- Checks all running processes for any process beginning with the name “Sophos” [and only Sophos] and if found, exits. - If no matching processes are found, starts the user.exe malware.” https://www.sysaid.com/... …
Heads up! Our team is observing post-compromise activity by #TA505 from 0-day used last week targeting IT service management product, SysAid On-Premise.
We've recreated a proof-of-concept for the SysAid CVE-2023-47246 remote code execution and compromise — blog post coming ASAP😜 Big thanks to @gleeda @HuskyHacksMK @DaveKleinatland @calebjstewart and the whole @HuntressLabs crew helping dig into this one! [image]
I'm endlessly fascinated by, and looking for, factors malware panics on. In this case, it lists all processes, looks for Sophos, and if you're running it, gives up. That's the only vendor they do that for. So weird. https://www.sysaid.com/...
Organizations using SysAid should apply the patch and look for any signs of exploitation prior to patching, as Lace Tempest will likely use their access to exfiltrate data and deploy Clop ransomware. https://www.sysaid.com/...
A small bit of potentially good news on the new SysAid 0day (CVE-2023-47246) — it looks like there are only a few hundred servers exposed to the internet. https://www.rapid7.com/...
In the attacks that Microsoft and SysAid have seen, the attackers exploited the vulnerability to upload a webshell and other files to the target system. https://duo.com/...
Clop is back, now exploiting a new zero-day in SysAid IT support software. A patch has been released for CVE-2023-47246 @TheRecord_Media #SysAid #MoveIt #Clop https://therecord.media/...
Lace Tempest (which overlaps with threat actors tracked by other researchers as FIN11 and TA505) similarly exploited a 0-day vulnerability in MOVEit Transfer in June: https://twitter.com/...
🚨🚨A 0day vulnerability exploited by SysAid On-Prem Software in the wild was discovered by the Microsoft Threat Intelligence Team @sysaid CVE-2023-47246 #ZoomEyeDork app:"SysAid On-Prem Software" About 860 results,mainly distributed in Italy,the United States and other...