Malichus is a Java backdoor observed in exploitation of Cleo Harmony, VLTrader, and LexiCom managed file transfer products during attacks involving the zero-day vulnerabilities CVE-2024-50623 and CVE-2024-55956. Reporting states that attackers uploaded Malichus to compromised Cleo systems after exploiting these flaws, including unauthenticated file-write issues in the /Synchronization endpoint. The malware is described as enabling data theft, command execution, and further access into compromised networks. Huntress identified Malichus as a new malware strain in this campaign. The activity has been linked in reporting to the Clop ransomware gang, also tracked as TA505/FIN11 and GOLD TAHOE, although some sources noted attribution was not definitively confirmed at the time. Malichus appears in tooling associated with GOLD TAHOE alongside SDBbot, Get2, GraceWire, TrueBot, FlawedAmmy, ServHelper, Cobalt Strike, and Clop. High-confidence context ties Malichus specifically to the late-2024 Cleo exploitation and follow-on data-theft/extortion activity affecting organizations using Cleo MFT products.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
While exploiting this vulnerability, the threat actors uploaded a JAVA backdoor dubbed "Malichus" that allows attackers to steal data, execute commands, and gain further access to the compromised network. | In October, Cleo disclosed a vulnerability tracked as CVE-2024-50623 that allowed unrestricted file uploads and downloads, leading to remote code execution... CISA confirmed that the critical CVE-2024-50623 security vulnerability in Cleo Harmony, VLTrader, and LexiCom file transfer software has been exploited in ransomware attacks.
The new vulnerability used in the December attacks is now tracked as CVE-2024-55956 and is fixed in Cleo Harmony, VLTrader, and LexiCom 5.8.0.24. While exploiting this vulnerability, the threat actors uploaded a JAVA backdoor dubbed 'Malichus'... Clop confirmed they are behind the recent exploitation of the Cleo CVE-2024-55956 vulnerability. | While exploiting this vulnerability, the threat actors uploaded a JAVA backdoor dubbed "Malichus" that allows attackers to steal data, execute commands, and gain further access to the compromised network.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
While exploiting this vulnerability, the threat actors uploaded a JAVA backdoor dubbed "Malichus" that allows attackers to steal data, execute commands, and gain further access to the compromised network.
6 distinct techniques documented for this family, organized by ATT&CK tactic.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A newly identified malware strain observed exploiting (or leveraging exploitation of) Cleo Harmony/VLTrader/LexiCom vulnerabilities to enable post-compromise activity; reported in the context of mass exploitation and ransomware-related intrusions.
A Java backdoor used in the Cleo exploitation chain to steal data, execute commands, and provide further access into compromised networks.
Tooling associated with GOLD TAHOE operations (specific functionality not described in the provided content).
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.