Attackers exploited CVE-2023-34362, a critical SQL injection vulnerability in Progress Software’s MOVEit Transfer, to gain unauthorized access and steal organizational data. ReliaQuest observed exploitation beginning at least May 27, 2023, ahead of disclosure on May 31, but did not initially attribute the activity. Subsequent Kroll investigations identified threat actors primarily associated with CLOP exploiting the flaw during May and June. Affected releases included MOVEit Transfer 2023.0.0 and the 2022.1.x, 2022.0.x, 2021.1.x, and 2021.0.x families; Progress released patches and mitigation guidance.
Kroll identified two exfiltration methods: the predominant approach used a dropped web shell to inject a session or create a malicious account, then reauthenticated to transfer files through MOVEit. A second approach, seen in approximately 5% of Kroll’s global MOVEit engagements, used web-shell capabilities and MOVEit APIs to decrypt and exfiltrate files, supported by Python automation; multiple instances sent data to 5.34.180.205. Application-mediated transfers generated database log entries, while direct web-shell theft could lack corresponding logs unless MOVEit logging was enabled, making database logs alone insufficient to exclude data theft. Response guidance included disabling HTTP and HTTPS access, removing unauthorized files and accounts, resetting credentials, and applying patches.

See which actors are running it and whether you're in range.
7 events from the most recent confirmed update back to the earliest known activity.
KonBriefing reported at least 131 organizations affected by Clop's MOVEit campaign as of June 28, 2023, with stolen personal information affecting millions of individuals. Reported victims included UCLA, New York City's Department of Education, government agencies, and financial institutions affected through compromised service provider PBI Research Services.
CVE-2023-34362 was discovered and disclosed on May 31, 2023, affecting multiple MOVEit Transfer release families. Successful exploitation could enable unauthorized access, potential privilege escalation, and access to or modification of database contents.
ReliaQuest observed exploitation of CVE-2023-34362 beginning at least May 27, 2023. Reports cited by ReliaQuest described attackers using the vulnerability to exfiltrate organizational data.
Kroll developed an automated approach to decrypt MOVEit data encrypted at rest during dead-box incident response. The capability supported attorney review, eDiscovery, and breach-notification processes.
Investigating MOVEit exploitation in May and June 2023, Kroll identified application-mediated file transfers and a second, direct web-shell method present in approximately 5% of its engagements, with the investigated activity primarily associated with CLOP. Kroll analyzed a CLOP Python automation script and observed direct exfiltration to 5.34.180.205; this method could leave no corresponding database log entries unless MOVEit logging was enabled.
ReliaQuest deployed threat-hunting packages on customer networks identified as using MOVEit and established detection rules for exploitation. It also updated its intelligence feeds with newly identified indicators of compromise.
Progress Software released patches for all supported MOVEit Transfer versions and mitigation guidance for CVE-2023-34362. The guidance included disabling HTTP and HTTPS access, removing unauthorized files and accounts, resetting credentials, and applying patches.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
3 references tracked. Mallory keeps watching after this page renders.
bankinfosecurity.com
Open sourcekroll.com
Open sourcereliaquest.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.