HomeSecurityRansomware Cl0p Exploits New 0-Day Vulnerabilities

Cl0p Ransomware Exploits New 0-Day Vulnerabilities

The Cl0p ransomware group, active since early 2019, has emerged as one of the most dangerous threats in cybersecurity. With over 1,025 confirmed victims and more than $500 million in extortion profits, this Russian-linked group systematically targets corporate and private networks worldwide, strategically avoiding CIS countries.

See also: CL0P Ransomware attacks telecom and healthcare sectors

Cl0p ransomware
Cl0p Ransomware Exploits New 0-Day Vulnerabilities

The group takes its name from the “.cl0p” file extension it adds after encryption, although the term also translates as “cobwebs” in Russian, reflecting its ongoing nature of hacking systems.

The latest campaign by the Cl0p ransomware group presents a sophisticated approach to zero-day exploitation, specifically leveraging CVE-2025-61882, a critical vulnerability discovered in Oracle E-Business Suite. This ERP application, widely used for order management, procurement, and supply chain operations in businesses worldwide, is an attractive target for attackers seeking rapid network penetration and data exfiltration.

The vulnerability was first observed in June 2025, but has become increasingly active in recent months. Analysts noted that the exploit infrastructure shows significant technical progress. While investigating the initial breach indicators shared by Oracle in October 2025, researchers discovered two outbound IP addresses that are directly linked to active attacks.

Through detailed fingerprint analysis and scanning with tools like Shodan and FOFA, analysts uncovered 96 distinct IP addresses that share identical SSL certificate fingerprints to the original attack infrastructure. This clustering revealed the group's operational patterns and network preferences across multiple geographic regions.

See also: Clop ransomware – Cleo attacks: New list of victims

Cl0p Ransomware Exploits New 0-Day Vulnerabilities
Cl0p Ransomware Exploits New 0-Day Vulnerabilities

The most striking technical discovery concerns Clop’s deliberate infrastructure reuse strategy. Researchers found that 41 IP subnets from the current Oracle EBS exploit were previously used during the MOVit vulnerability attacks in 2023 (CVE-2023-34362). This pattern suggests that the group maintains permanent hosting relationships and strategically rotates infrastructure rather than creating entirely new networks between campaigns.

Analysis of the 96 identified IPs shows geographic distribution patterns, with Germany leading the way with 16 addresses, followed by Brazil (13) and Panama (12). However, the underlying ASN infrastructure reveals concentrated use by Russia-based providers, despite geo-differentiation efforts designed to circumvent traditional IP-based blocking strategies.

Further investigation revealed that the Cl0p ransomware group uses sophisticated subnetting techniques, with 77.8 percent of identified subnets showing repeated use across multiple attack campaigns. Hosting provider analysis revealed Alviva Holdings Limited as the primary infrastructure provider, hosting 15 identified addresses. This consistent reuse pattern provides defenders with valuable information for threat hunting and network monitoring.

See also: Cleo attacks: Clop ransomware gang blackmails 66 companies

Cl0p Ransomware Exploits New 0-Day Vulnerabilities
Cl0p Ransomware Exploits New 0-Day Vulnerabilities

The combination of zero-day exploitability, persistent infrastructure reuse, and geographic specialization shows why Cl0p remains one of the most effective ransomware operations currently active in the threat landscape.

Selecting the team

☁️ Keep safe copies with Proton Drive

Encrypted cloud storage from Proton — protect your files from ransomware, corruption, and data loss with end-to-end encryption.

  • ✔ End-to-end encrypted files & backups
  • ✔ Version history — recover files after ransomware
  • ✔ Free space — sync across all devices
Get started for free with Proton Drive →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS