ZeroFox Intelligence Flash Report - Cl0p Claims Responsibility for Zero-Day Exploitation
|by Alpha Team

ZeroFox Intelligence Flash Report - Cl0p Claims Responsibility for Zero-Day Exploitation
Product Serial: F-2024-12-17a
TLP:CLEAR
In this Flash Report, ZeroFox researchers report on the claiming of recent zero-day exploitation and data theft attacks by the ransomware and digital extortion collective Cl0p.
Standing Intelligence Requirements

For the most up-to-date list of ZeroFox’s Intelligence Requirements, please visit:
https://cloud.zerofox.com/intelligence/advisories/14956
Link to Download
View the full report here
Key Findings
- On December 15, 2024, the ransomware group Cl0p reportedly claimed responsibility for a recent spate of data theft attacks that targeted organizations using Cleo managed file transfer (MFT) software solutions.
- In October 2024, Cleo divulged a vulnerability tracked as CVE-2024-50623 that permitted unrestricted file uploads and downloads. A second vulnerability was discovered in December 2024 (tracked as CVE-2024-55956).
- While ZeroFox cannot verify Cl0p’s claims, they are likely true given that the collective has not historically sought unwarranted attention. At the time of writing, the extent of the attacks and any ongoing extortion activity is unclear.
- If Cl0p’s claims are legitimate, there is a roughly even chance that additional organizations will be compromised in the coming weeks before they are named on the victim leak site to apply additional extortion pressure.
Tags: dark web, threat actor, vuln/exploit