The Clop ransomware has confirmed that it is behind the recent Cleo data theft attacks. The group said it used zero-day exploits to breach corporate networks and steal data.

Cleo is the developer of the managed file transfer platforms Cleo Harmony, VLTrader and LexiCom. Many companies use these platforms to securely exchange files between business partners and customers.
In October, Cleo fixed a vulnerability (CVE-2024-50623) that allowed unrestricted file uploads and downloads, leading to remote code execution.
However, cybersecurity firm Huntress discovered last week that the initial update was incomplete and attackers were still exploiting it (via a workaround) to carry out data theft.
See also: November 2024: Increased Akira & RansomHub ransomware activity
When exploiting this vulnerability, threat actors uploaded a JAVA backdoor to steal data, execute commands, and gain further access to the compromised network.
On Friday, CISA confirmed that the CVE-2024-50623 vulnerability in the Cleo Harmony, VLTrader, and LexiCom software is being used in ransomware attacks.
Clop ransomware group claims responsibility for Cleo attacks
Initially, it was said that the Cleo attacks were carried out by a new ransomware gang called Termite. However, the data-stealing attacks were quite similar to previous attacks carried out by the Clop ransomware gang.
BleepingComputer has reportedly contacted the Clop ransomware group, which confirmed that it is behind the recent Cleo vulnerability exploit as well as the exploitation of the original CVE-2024-50623 flaw (which was patched in October).
“As for CLEO, it was our project – which was successfully completed.
For the information we store, we adhere to all security measures. If the data belongs to government agencies, institutions, medical organizations, then we will immediately delete this data without hesitation... we comply with our regulations.
with love © CL0P^_”
See also: Electrica Group Romania: Lynx ransomware behind the attack
The gang also announced that it is deleting data related to previous attacks and will only deal with new companies breached in the Cleo attacks.
☁️ Keep safe copies with Proton Drive
Encrypted cloud storage from Proton — protect your files from ransomware, corruption, and data loss with end-to-end encryption.
- ✔ End-to-end encrypted files & backups
- ✔ Version history — recover files after ransomware
- ✔ Free space — sync across all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
“Dear companies,
Due to recent events (CLEO attack) all links to all companies' data will be disabled and the data will be permanently deleted from the servers. We will only deal with new companies," reads a new message from CL0P^ on the data leak site.

BleepingComputer reportedly asked the Clop ransomware group when the attacks began, how many companies were affected, and whether there is any connection to the new Termite ransomware gang. However, it did not receive any answers.
See also: Sichuan Silence accused of ransomware attacks
Protection against attacks and data theft
To protect our devices, it is important to implement several security measures. Regularly updating software and operating systems ensures that the latest security patches are applied, reducing vulnerabilities. Using strong, unique passwords for accounts and enabling two-factor authentication adds an extra layer of protection. Installing reliable antivirus software and firewalls can help detect and mitigate potential threats. In addition, avoiding suspicious links, emails, and websites reduces the risk of falling victim to phishing attacks. It is also important to regularly back up data in the event of a security breach. In the event of a cyberattack, having backups can minimize the impact and potential loss of sensitive information. Finally, being aware of common hacking techniques and staying informed about recent breaches can help us identify and prevent potential security risks.
By implementing these measures, we can better protect our devices and personal information from hackers.
source: www.bleepingcomputer.com
