Microsoft says the Clop ransomware group is exploiting a zero-day in IT support tool SysAid in “limited” attacks to access corporate servers and deploy Clop
blog post coming ASAP😜 Big thanks to @gleeda @HuskyHacksMK @DaveKleinatland @calebjstewart and the whole @HuntressLabs crew helping dig into this one! [image] @swiftonsecurity : I'm endlessly fascinated by, and looking for, factors malware panics on. In this case, it lists all processes, looks for Sophos, and if you're running it, gives up. That's the only vendor they do that for. So weird. https://www.sysaid.com/... @sophosxops : From @SysAid's write up about active attacks attributed to Cl0p. “- Checks all running processes for any process beginning with the name “Sophos” [and only Sophos] and if found, exits. - If no matching processes are found, starts the user.exe malware.” https://www.sysaid.com/... [image] Daniel Stepanic / @danielstepanic : Heads up! Our team is observing post-compromise activity by #TA505 from 0-day used last week targeting IT service management product, SysAid On-Premise. Raj Samani / @raj_samani : Our latest @rapid7 analysis details CVE-2023-47426, a zero-day path traversal vulnerability affecting on-premise SysAid servers. Including IoCs and @velocidex artifact: https://www.rapid7.com/... [image] @msftsecintel : Organizations using SysAid should apply the patch and look for any signs of exploitation prior to patching, as Lace Tempest will likely use their access to exfiltrate data and deploy Clop ransomware. https://www.sysaid.com/... Caitlin Condon / @catc0n : A small bit of potentially good news on the new SysAid 0day (CVE-2023-47246) — it looks like there are only a few hundred servers exposed to the internet. https://www.rapid7.com/... Lindsey O'Donnell Welch / @lindseyod123 : In the attacks that Microsoft and SysAid have seen, the attackers exploited the vulnerability to upload a webshell and other files to the target system. https://duo.com/... Jon Greig / @jgreigj : Clop is back, now exploiting a new zero-day in SysAid IT support software. A patch has been released for CVE-2023-47246 @TheRecord_Media #SysAid #MoveIt #Clop https://therecord.media/... @msftsecintel : Lace Tempest (which overlaps with threat actors tracked by other researchers as FIN11 and TA505) similarly exploited a 0-day vulnerability in MOVEit Transfer in June: https://twitter.com/... @zoomeye_team : 🚨🚨A 0day vulnerability exploited by SysAid On-Prem Software in the wild was discovered by the Microsoft Threat Intelligence Team @sysaid CVE-2023-47246 #ZoomEyeDork app:"SysAid On-Prem Software" About 860 results,mainly distributed in Italy,the United States and other... LinkedIn: Peter Fogarty : Russian digital extortion gang behind a raft of attacks on file transfer applications is now targeting a newly patched vulnerability in SysAid IT help desk support software …
Context & Ripple Effects
The SysAid incident extends a pattern already visible in Clop's exploitation of a zero-day in MOVEit, which was linked to breaches at 122 organizations and data theft affecting roughly 15 million people in related coverage. Clop's earlier MOVEit zero-day campaign made file-transfer and enterprise-management software a demonstrated route to broad corporate exposure.
Microsoft attributes the SysAid activity to Lace Tempest, while SysAid has issued a patch for CVE-2023-47246. The reported attacks are described as limited, but the vulnerability sits on an on-premises support platform with direct relevance to corporate server access.
First-order effects
- SysAid On-Prem customers must patch CVE-2023-47246 and investigate for unauthorized server access and ransomware deployment; unpatched installations face the immediate exposure described by Microsoft.
- SysAid must manage incident response and customer remediation around a flaw in a tool trusted to administer enterprise IT environments.
Second-order effects
- Security teams are likely to prioritize monitoring and hardening of externally reachable IT administration tools, particularly after Microsoft's identification of active SysAid exploitation.
- The overlap Microsoft notes among Lace Tempest, FIN11, and TA505 gives defenders a broader set of threat-activity associations to incorporate into detection and response efforts.
Third-order effects
- If repeated exploitation of enterprise support and transfer products persists, software buyers will increasingly treat vendor patch speed, exposure management, and incident transparency as procurement criteria rather than operational afterthoughts.
- The pattern reinforces a shift from ransomware as an endpoint-only problem toward ecosystem defense: a compromise of a centrally deployed business tool can create a high-leverage path into many organizations.
The trend: Ransomware operators are concentrating on zero-days in widely deployed enterprise infrastructure, where one vulnerable management product can provide direct access to corporate environments.