The Cl0p extortion group continued broad data-theft campaigns by exploiting managed file-transfer and file-sharing platforms, with reporting tying the gang to attacks involving Cleo LexiCom, VLTrader, and Harmony through CVE-2024-50623 and to a separate campaign targeting CentreStack file servers. Security researchers said the Cleo flaw allowed remote file upload and download and could lead to remote code execution, while Huntress reported active exploitation and warned that Cleo's patch in version 5.8.0.21 might be bypassed. Cl0p publicly claimed dozens of organizations affected by the Cleo breach and gave victims short deadlines to respond to ransom demands, consistent with the group's long-running pattern of stealing data before threatening publication on its leak site.
The campaign's impact appeared to spread across sectors and geographies, including a report alleging that a New Zealand poultry producer was listed as a Cl0p victim. The activity fits Cl0p's established playbook of exploiting high-value file-transfer software vulnerabilities, as previously seen in the Accellion FTA and MOVEit mass-compromise waves, then pressuring organizations through leak-site postings and negotiation channels. The latest reporting indicates Cl0p remained focused on opportunistic exploitation of internet-facing file exchange systems to drive large-scale extortion operations rather than relying solely on traditional ransomware encryption.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
8 events from the most recent confirmed update back to the earliest known activity.
A LinkedIn post from Curated Intelligence identified a Cl0p extortion campaign targeting CentreStack file servers, indicating another active intrusion vector associated with the group.
Cyber Daily published a report alleging that a New Zealand poultry producer had been hacked by Cl0p, marking a newly disclosed victim claim tied to the group's activity.
Cyberint says Huntress reported active exploitation of the Cleo vulnerability and released a proof of concept, while researchers warned that the vendor patch in Cleo version 5.8.0.21 could be bypassed.
Cyberint describes a renewed Cl0p campaign tied to exploitation of Cleo LexiCom, VLTrader, and Harmony via CVE-2024-50623, a zero-day enabling remote file upload and download that can lead to remote code execution.
According to Cyberint, 27 victims were published by Cl0p in 2024, a sharp drop from the prior year's breach volume.
Cyberint reports that 2023 saw 384 successful breaches attributed to Cl0p, highlighting the scale of the group's operations that year.
The Cyberint reference states that Cl0p has been active since at least 2019 and is widely assessed as a successor to CryptoMix.
On December 24, Cl0p claimed that 66 companies affected by the Cleo breach had 48 hours to respond to ransom demands, adding that the total number of victims could be higher because only contacted but unresponsive firms were listed.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
cyberdaily.au
Open sourcecyberint.com
Open sourcelinkedin.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.