zerofox logo
Advisories

ZeroFox Intelligence Flash Report - Ransomware Collectives Set to Exploit SysAid Zero-Day Vulnerability

|by Alpha Team

banner image

ZeroFox Intelligence Flash Report - Ransomware Collectives Set to Exploit SysAid Zero-Day Vulnerability

Product Serial: F-2023-11-10a

TLP:CLEAR

In this Intelligence Flash Report, ZeroFox researchers report on the SysAid zero-day vulnerability (tracked as CVE-2023-47246) being actively exploited by financially-motivated threat actors to deploy ransomware.

Standing Intelligence Requirements

Deep Dark Web and Criminal Underground DDW

For the most up-to-date list of ZeroFox’s Intelligence Requirements, please visit:

https://cloud.zerofox.com/intelligence/advisories/14956

Link to Download

View the full report here.

Key Findings

  • On November 8, 2023, IT Service Management Solution (ITSM) organization SysAid disclosed a zero-day vulnerability targeting its on-premises software, which has led to an unknown amount of ransomware attacks.
  • Initial exploitation has been attributed to financially-motivated group Lace Tempest, which is associated with ransomware collective Cl0p. Cl0p has conducted at least two prominent ransomware campaigns in 2023, both targeting managed file transfer solutions (MFTs).

Tags: tlp:clear,  dark web,  vulnerability/exploit,  all industries, DDW Ransomware