13 November 2023

Ransomware gang behind MOVEit hacks caught exploiting a SysAid 0Day


Ransomware gang behind MOVEit hacks caught exploiting a SysAid 0Day

A new malicious campaign is taking advantage of a zero-day vulnerability in the popular SysAid IT helpdesk software to deploy the Clop ransomware, Microsoft has warned.

Tracked by Microsoft as Lace Tempest (aka DEV-0950, FIN11 and TA505), the threat actor is believed to be an affiliate of the Clop ransomware gang, previously linked to a large-scale hacking campaign that exploited a zero-day vulnerability (CVE-2023-34362) in Progress Software's MOVEit file transfer app, which is used by thousands of organizations around the world to deploy ransomware. The MOVEit campaign is said to have impacted more than 2,500 organizations and over 70 million individuals.

The new campaign involves CVE-2023-47246, a path traversal issue in the SysAid software that can lead to remote code execution. Microsoft’s threat intelligence team said that Lace Tempest issued commands via the SysAid software to deliver a malware loader for the Gracewire malware, which is typically followed by human-operated activity, including lateral movement, data theft, and ransomware deployment.

“Organizations using SysAid should apply the patch and look for any signs of exploitation prior to patching, as Lace Tempest will likely use their access to exfiltrate data and deploy Clop ransomware,” the tech giant advised.


Back to the list

Latest Posts

Cyber Security Week in Review: November 1, 2024

Cyber Security Week in Review: November 1, 2024

In brief: Hackers are exploiting critical zero-day flaw in PTZ cameras, the Dstat.cc DDoS service disrupted by law enforcement, and more.
1 November 2024
North Korean hackers caught collaborating with Play ransomware

North Korean hackers caught collaborating with Play ransomware

The theory is that Andariel is either working as an affiliate of Play ransomware or serving as an initial access broker.
31 October 2024
Large-scale phishing campaign targeting Ukraine's taxpayers

Large-scale phishing campaign targeting Ukraine's taxpayers

The attack deploys the Litemanager RMT, which provides unauthorized access to the infected computer.
30 October 2024