Clop ransomware lists victims of Cleo cyberattack


  • Hackers were recently found to be abusing a flaw in multiple Cleo software tools.
  • The Cl0p ransomware gang claimed responsibility for the attack
  • The group has begun listing victims on its website.

Prolific ransomware threat actor Cl0p has added partial names of some of the companies that were successfully attacked for bugs in the Cleo software. This is probably part of his pressure tactic, as he tries to extort money from his victims.

In early December of this year, news emerged that several managed file transfer tools from the same developer called Cleo Software were being abused to launch attacks and possibly steal data. At the time, cybersecurity researchers at Huntress claimed that LexiCom, VLTransfer, and Harmony were vulnerable to CVE-2024-50623, an unrestricted file upload and download vulnerability that could lead to remote code execution.

Leave a Comment

Your email address will not be published. Required fields are marked *