MOVEit is Progress Software’s managed file transfer application/platform that was widely exploited in a 2023 mass-compromise campaign centered on a SQL injection zero-day. The content describes this as a software vulnerability and supply-chain attack rather than a distinct malware family. The campaign is attributed to the Russian-speaking Clop/CL0P cybercriminal group, which exploited the zero-day around Memorial Day 2023 and, in at least some victim environments, deployed web shells on compromised MOVEit servers. Reported downstream impacts included data theft from thousands of organizations globally, with cited estimates of more than 2,700 affected organizations and nearly 96 million individuals. In the energy sector, the content states that downstream victims included utilities such as Entergy, Nevada Energy, Appalachian Power, and CenterPoint Energy through compromise of CLEAResult, and that an access broker using the aliases AntiBrok3rs/Nam3L3ss later leaked data tied to at least 15 energy-sector victims from the 2023 MOVEit attack. Mentioned stolen data types in one victim case included names, addresses, Social Security numbers, driver’s license information, financial account information, and patient health information. High-confidence indicators/behaviors directly mentioned in the content include exploitation of a MOVEit SQL injection zero-day and discovery of a web shell on affected MOVEit servers.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
New York regulators have fined Delta Dental $2.25 million for violations of state cyber requirements in the aftermath of an investigation into the dental insurer's 2023 MOVEit file transfer software hack.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
MOVEit is a managed file transfer application that was mass-exploited in 2023 via a zero-day SQL injection vulnerability, leading to data theft from affected organizations.
MOVEit is a managed file transfer application that was exploited via a zero-day SQL injection vulnerability, leading to web shell deployment and large-scale data theft from affected organizations.
A widely exploited file transfer vulnerability used by threat actors (notably Cl0P) to compromise organizations and exfiltrate data.
Managed file transfer platform referenced as the initial compromise point in a supply-chain attack that enabled downstream data theft and leak activity affecting energy-sector organizations.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.