A critical pre-authentication flaw in Progress MOVEit Transfer, CVE-2023-34362, was actively exploited to compromise internet-facing managed file-transfer servers and steal customer data. The vulnerability allowed SQL injection over HTTP/HTTPS, enabling attackers to manipulate the database, establish privileged sessions, deploy the human2.aspx ASPX webshell, and access or exfiltrate stored files. Microsoft attributed the campaign to Lace Tempest, associated with the Cl0p extortion ecosystem; Cl0p subsequently demanded that victims make contact or face publication of stolen data.
Technical analysis found that duplicate HTTP-header smuggling could bypass MOVEitISAPI.dll transaction restrictions and set attacker-controlled session variables. Those values reached vulnerable guest-access code, permitting creation of a sysadmin session, acquisition of an API token, and a path to remote code execution through resumable-upload metadata and unsafe .NET BinaryFormatter deserialization. Organizations were urged to apply Progress updates, restrict HTTP/HTTPS exposure until patched, hunt for human2.aspx, the Health Check Service account or session, and X-siLock-* headers, preserve logs, rotate relevant storage credentials, and rebuild compromised servers from trusted backups because patching alone does not remove persistence.

See which actors are running it and whether you're in range.
11 events from the most recent confirmed update back to the earliest known activity.
Rapid7 reported exploitation across multiple customer environments, including the human2.aspx webshell in the MOVEit wwwroot directory. The webshell used an X-siLock-Comment header check and appeared across multiple victims, indicating automated exploitation.
Progress Software issued a security bulletin for a critical MOVEit Transfer SQL-injection vulnerability, subsequently tracked as CVE-2023-34362, and published mitigations and fixed versions.
Evidence showed human2.aspx backdoors had been uploaded to public MOVEit sites since May 28, while Rapid7 confirmed data exfiltration dating to at least that date.
Rapid7 confirmed indicators of compromise associated with the MOVEit Transfer zero-day dating back to at least May 27, 2023.
Researchers detailed a chain using duplicate-header smuggling to reach unsanitized session variables and SQL injection, then creating an active sysadmin session and abusing BinaryFormatter deserialization in resumable-upload metadata to achieve remote code execution.
Microsoft attributed the MOVEit Transfer zero-day campaign to Lace Tempest, a threat actor previously linked to the Cl0p ransomware, data-theft, and extortion ecosystem.
Progress disclosed and patched CVE-2023-36934, CVE-2023-36932, and CVE-2023-36933.
Progress disclosed a third MOVEit Transfer vulnerability, assigned CVE-2023-35708.
Progress released a patch for CVE-2023-35036, a second SQL-injection issue affecting all MOVEit Transfer versions. It was not known to be exploited in the wild at the time.
The Cl0p gang posted a leak-site message directing victims to contact the group by June 14 to negotiate payment for deletion of stolen data.
Progress advised MOVEit users to download patches only through Progress knowledge-base articles rather than third-party sources.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 29 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
5 references tracked. Mallory keeps watching after this page renders.
slcyber.io
Open sourceslcyber.io
Open sourcerapid7.com
Open sourcetrustedsec.com
Open sourcehuntress.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.