LEMURLOOT is a custom web shell used in the 2023 mass exploitation of Progress MOVEit Transfer, primarily associated with the Clop extortion operation, also tracked as FIN11, TA505, and Snakefly. It was deployed after exploitation of the critical SQL injection vulnerability CVE-2023-34362 against internet-facing MOVEit Transfer systems. The malware is tailored specifically for MOVEit Transfer and was used to obtain persistent access, interact with the application’s underlying database, and rapidly steal data from compromised environments.
Implemented as an ASP.NET/C# web shell, LEMURLOOT masqueraded as a legitimate MOVEit component to reduce suspicion. It authenticated operator requests through custom HTTP headers and exposed functionality for retrieving files and metadata from MOVEit, querying records, extracting configuration data, and accessing Azure storage settings and related credentials when present. Reported capabilities also include creating and deleting application users, including creation of an administrator account used to preserve access. In multiple incidents, operators exfiltrated large volumes of data within minutes of deployment.
LEMURLOOT formed part of a broader Clop campaign focused on data theft and extortion rather than file encryption. Victims spanned government and private-sector organizations across multiple industries and geographies, reflecting MOVEit Transfer’s role as a widely deployed managed file transfer platform. The malware’s design, narrow platform targeting, and database-aware functionality distinguish it from generic web shells and align it with Clop’s repeated exploitation of file-transfer products for large-scale exfiltration operations.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The most significant incident was the 2023 MOVEit Transfer zero day (CVE-2023-34362), a SQL injection vulnerability exploited by the CL0P/TA505 ransomware group beginning May 27, 2023, before Progress disclosed it on May 31, 2023. | The CL0P group deployed a C# web shell named LEMURLOOT to steal data from MOVEit Transfer databases.
5 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The CL0P group deployed a C# web shell named LEMURLOOT to steal data from MOVEit Transfer databases.
According to a joint advisory issued by the U.S. Federal Bureau of Investigation (FBI) and the Cybersecurity and Infrastructure Security Agency (CISA), the attackers exploited the vulnerability to install a web shell called Lemurloot (JS.Malscript!g1) on affected systems. This was then used to steal data from underlying databases.
According to a joint advisory issued by the U.S. Federal Bureau of Investigation (FBI) and the Cybersecurity and Infrastructure Security Agency (CISA), the attackers exploited the vulnerability to install a web shell called Lemurloot (JS.Malscript!g1) on affected systems. This was then used to steal data from underlying databases.
Attackers have exploited the SQLi vulnerability to deploy a custom ASP.NET web shell (LEMURLOOT) to achieve persistence on victim networks to allow for further attack.
Following exploitation of the vulnerability, the threat actors are deploying a newly discovered LEMURLOOT web shell with filenames that masquerade as human.aspx... LEMURLOOT provides functionality tailored to execute on a system running MOVEit Transfer software...
16 distinct techniques documented for this family, organized by ATT&CK tactic.
Lemurloot was designed specifically to target the MOVEit Transfer platform... and can create, insert, or delete a particular user.
Lemurloot was designed specifically to target the MOVEit Transfer platform... and can create, insert, or delete a particular user.
SQL injection attacks allow attackers to ... allow the complete disclosure of all data on the system...
LEMURLOOT can also steal Azure Storage Blob information, including credentials, from the MOVEit Transfer application settings, suggesting that actors exploiting this vulnerability may be stealing files from Azure in cases where victims are storing appliance data in Azure Blob storage.
110 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A C# web shell used by the CL0P/TA505 ransomware group to steal data from MOVEit Transfer databases.
A custom web shell deployed on compromised MOVEit Transfer servers to provide persistent access, enable command execution, and support data exfiltration during exploitation of CVE-2023-34362.
A web shell designed specifically to target the MOVEit Transfer platform. It authenticates incoming HTTPS requests via a hard-coded password, downloads files from the MOVEit Transfer database, extracts Azure system settings, retrieves records, and can create, insert, or delete a particular user. It returns stolen data in a comfile format.
Custom ASP.NET web shell deployed after exploiting MOVEit Transfer/Cloud (CVE-2023-34362) to provide persistent access on compromised servers; observed as an .aspx web shell (e.g., 'human2.aspx') with password control via a custom HTTP header.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.