LEMURLOOT is a custom web shell associated with the Clop extortion operation and purpose-built for Progress MOVEit Transfer. It was deployed during the large-scale exploitation of CVE-2023-34362, a SQL injection vulnerability in internet-facing MOVEit Transfer systems, and was used to steal data from underlying MOVEit databases and related storage settings. The malware is commonly described as an ASP.NET or C# web shell masquerading as a legitimate MOVEit component in order to blend into the application environment.
LEMURLOOT supports authenticated remote interaction through specially crafted HTTP headers and is designed to operate directly against MOVEit application and database functionality. Reported capabilities include enumerating files and folders, retrieving records, downloading files, extracting Azure storage configuration and credentials from application settings, and creating or deleting a MOVEit user account to maintain access. Some reporting also notes command execution and persistent access on compromised MOVEit servers. Responses and stolen data may be compressed, and the implant is tailored to the MOVEit platform rather than functioning as a generic web shell.
The malware is strongly linked to Clop, also tracked as CL0P and associated in reporting with FIN11, Snakefly, and TA505. Its deployment fits Clop’s established pattern of mass exploitation of managed file transfer products followed by installation of custom web shells for rapid data theft and extortion. Similar Clop operations previously used DEWMODE against Accellion FTA, while LEMURLOOT was central to the MOVEit campaign that affected organizations across government and private sectors globally. The primary objective observed for LEMURLOOT was large-scale exfiltration of sensitive enterprise data to support extortion rather than destructive impact.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Les TTPs correspondent au schéma établi de Clop : exploitation de masse suivie de web shells personnalisés (précédents : DEWMODE pour CVE-2021-27101, LEMURLOOT pour CVE-2023-34362)
They exploited this vulnerability by installing a webshell known as LEMURLOOT.
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Les TTPs correspondent au schéma établi de Clop : exploitation de masse suivie de web shells personnalisés (précédents : DEWMODE pour CVE-2021-27101, LEMURLOOT pour CVE-2023-34362)
According to a joint advisory issued by the U.S. Federal Bureau of Investigation (FBI) and the Cybersecurity and Infrastructure Security Agency (CISA), the attackers exploited the vulnerability to install a web shell called Lemurloot (JS.Malscript!g1) on affected systems. This was then used to steal data from underlying databases.
According to a joint advisory issued by the U.S. Federal Bureau of Investigation (FBI) and the Cybersecurity and Infrastructure Security Agency (CISA), the attackers exploited the vulnerability to install a web shell called Lemurloot (JS.Malscript!g1) on affected systems. This was then used to steal data from underlying databases.
Following exploitation of the vulnerability, the threat actors are deploying a newly discovered LEMURLOOT web shell with filenames that masquerade as human.aspx... LEMURLOOT provides functionality tailored to execute on a system running MOVEit Transfer software...
16 distinct techniques documented for this family, organized by ATT&CK tactic.
Lemurloot was designed specifically to target the MOVEit Transfer platform... and can create, insert, or delete a particular user.
Lemurloot was designed specifically to target the MOVEit Transfer platform... and can create, insert, or delete a particular user.
SQL injection attacks allow attackers to ... allow the complete disclosure of all data on the system...
LEMURLOOT can also steal Azure Storage Blob information, including credentials, from the MOVEit Transfer application settings, suggesting that actors exploiting this vulnerability may be stealing files from Azure in cases where victims are storing appliance data in Azure Blob storage.
116 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
13 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Previously referenced custom backdoor/web shell associated with Clop mass exploitation activity.
Custom web shell previously used by the Clop gang following exploitation of MOVEit Transfer vulnerabilities.
A custom web shell previously deployed by Clop following exploitation of CVE-2023-34362.
A C# web shell used by the CL0P/TA505 ransomware group to steal data from MOVEit Transfer databases.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.