Threat reportRansomwareTL-2026-3070
Cl0p Ransomware MFT Attack Pattern: Multi-Year Zero-Day Campaigns Against File Transfer and Enterprise Software (2020-2025)
Cl0p Ransomware MFT Attack Pattern (TL-2026-3070), also tracked as Cl0p MFT campaigns, is a high-severity ransomware operation, first published 2026-10-09. It is attributed to Cl0p with high confidence, affects Progress Software MOVEit Transfer, references 11 CVEs (CVE-2023-34362, CVE-2021-35211, CVE-2023-0669), maps to 9 MITRE ATT&CK techniques (T1190, T1213, T1505.003), and is covered by 9 detection rules and 16 indicators of compromise.
- Severity
- HIGHAssessed severity
- CVEs
- 11Referenced vulnerabilities
- Techniques
- 9MITRE ATT&CK
- Actors
- 1Cl0p
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 16Indicators of compromise
Key facts for TL-2026-3070
- Threat ID
- TL-2026-3070
- Also known as
- Cl0p MFT campaigns, Cl0p Til you Drop
- Severity
- HIGH
- Status
- ACTIVE
- Category
- RANSOMWARE
- First published
- Last reviewed
- Attribution
- Cl0p
- Attribution confidence
- HIGH
- Motivation
- FINANCIAL
- Target sectors
- technology, finance, government administration, health, education, legal, retail, telecoms
- Target regions
- North America, Europe, Global
- Detection rules
- 9
- Indicators of compromise
- 16
Malware and tooling in Cl0p Ransomware MFT Attack Pattern
Malware and tooling: Clop, DEWMODE, LEMURLOOT, Mimikatz, SysAid
How Cl0p Ransomware MFT Attack Pattern works
Team Cymru's analysis of the financially motivated Cl0p group describes a repeatable playbook across nine campaigns built mostly on zero-days in managed file transfer and enterprise software (Accellion FTA, Serv-U, GoAnywhere MFT, MOVEit Transfer, Cleo, Oracle EBS, Gladinet CentreStack). Key patterns are long pre-attack scanning, heavy infrastructure rotation across 79 ASNs, 10-14 month dormancy between campaigns, and Q4 clustering.
Team Cymru (Eli Woodward, published 2026-08-12, presented at FIRSTCON Denver 2026) analyzed six years of Cl0p activity and found that the group repeatedly targets internet-facing applications that process, store, or transfer files. Of nine confirmed campaigns, seven target managed file transfer (MFT) products; PaperCut MF/NG (print management) and SysAid (ITSM) are the exceptions. The source title cites ten campaigns while its body enumerates nine. Campaigns include Accellion FTA (2020), SolarWinds Serv-U (2021, CVE-2021-35211), Fortra GoAnywhere MFT (January 2023, CVE-2023-0669), Progress MOVEit Transfer (May 2023, CVE-2023-34362), PaperCut (CVE-2023-27350), SysAid (CVE-2023-47246), Cleo Harmony/VLTrader/LexiCom (December 2024, CVE-2024-50623 and CVE-2024-55956), Oracle E-Business Suite (July-September 2025, CVE-2025-61882), and Gladinet CentreStack (from 2025-11-27).
Exploitation mechanics vary by product but follow a pattern. In MOVEit, SQL injection reached via /moveitisapi/moveitisapi.dll led to deployment of the LEMURLOOT web shell (placed at /human2.aspx) and exfiltration of stored files. Team Cymru highlights that the web shell invoked the application's own key-management function (GetBaseKeyProvider()) to decrypt files, making encryption at rest irrelevant because the decrypting capability sat on the same compromised component. In Gladinet CentreStack, public reporting (Security Affairs/Huntress) describes an unauthenticated local file inclusion (CVE-2025-11371) used to retrieve the machine key from Web.config, followed by ViewState deserialization for remote code execution (see also CVE-2025-30406). The Oracle EBS campaign saw reconnaissance from July 2025, exploitation from August, and extortion emails on 2025-09-29, so victims learned of compromise roughly two months after exploitation.
Infrastructure and operational tempo: Team Cymru observed 79 ASNs used across campaigns, of which 53 (67%) were single-campaign and 26 (33%) were reused. The most frequently reused providers include Hostzealot (HZ-US/HZ-BG; seen in four of nine campaigns), Colocrossing, Datacampus, Datahome, Ghostnet and OVH. Reconnaissance preceded exploitation by up to roughly two years in the MOVEit case (45.129.137.232 probing in July 2021, 92.118.36.233 in April 2022). Dormancy between campaigns is typically 10-14 months, with a burst of four campaigns in ten months in 2023. Five of nine campaigns began October-December, and the Gladinet compromise began on Thanksgiving (2025-11-27). Cl0p does not use public forums or Telegram and, for CentreStack, used the pubstorm.com and pubstorm.net domains for email extortion. Other public reporting (Vectra) also lists DEWMODE web shell, Truebot, and Mimikatz in Cl0p's wider toolkit; these are not tied to specific campaigns in the primary source.
Defensive guidance from the source: enumerate every internet-facing MFT application including shadow IT; apply default-deny WAF allowlisting (about 15 legitimate URI paths) so non-allowlisted requests become high-confidence reconnaissance indicators; retain MFT logs 12-24 months and retro-hunt on every MFT zero-day disclosure; baseline URIs and egress volumes per device; tighten outbound thresholds and review frequency October-January; watchlist Cl0p-associated ASNs on a rolling 180-day basis; and separate internet-facing components from key material and file storage. Attribution remains financially motivated; some Oracle EBS extortion attribution was publicly disputed.
MITRE ATT&CK techniques used in TL-2026-3070
Initial Access
T1190 Exploit Public-Facing Application
Collection
T1213 Data from Information Repositories
Persistence
T1505.003 Server Software Component: Web Shell
Credential Access
T1552.001 Unsecured Credentials: Credentials In Files
Resource Development
T1583.003 Acquire Infrastructure: Virtual Private Server; T1587.004 Develop Capabilities: Exploits
Reconnaissance
T1595 Active Scanning; T1595.002 Active Scanning: Vulnerability Scanning
Impact
Affected products and versions in Cl0p Ransomware MFT Attack Pattern
- Progress Software — MOVEit Transfer
Vulnerable versions: Versions prior to the May 2023 fixes (CVE-2023-34362)
Fixed in: Vendor patched releases - Fortra — GoAnywhere MFT
Vulnerable versions: Unpatched instances (CVE-2023-0669)
Fixed in: Vendor patched releases - Cleo — Harmony, VLTrader, LexiCom
Vulnerable versions: Unpatched instances (CVE-2024-50623, CVE-2024-55956)
Fixed in: Vendor patched releases - Oracle — E-Business Suite
Vulnerable versions: Unpatched instances (CVE-2025-61882)
Fixed in: Oracle security alert patch - Gladinet — CentreStack / TriofoX
Vulnerable versions: Versions prior to the 2025-11-29 security update
Fixed in: Release of 2025-11-29 and later - SolarWinds — Serv-U
Vulnerable versions: Unpatched instances (CVE-2021-35211)
Fixed in: Vendor patched releases - Accellion — File Transfer Appliance (FTA)
Vulnerable versions: Legacy FTA (CVE-2021-27101)
Fixed in: Product end-of-life; vendor patches - PaperCut — MF/NG
Vulnerable versions: Unpatched instances (CVE-2023-27350)
Fixed in: Vendor patched releases - SysAid — On-premises ITSM
Vulnerable versions: Unpatched instances (CVE-2023-47246)
Fixed in: Vendor patched releases
Remediation for Cl0p Ransomware MFT Attack Pattern
Patches
- Apply vendor fixes: Progress MOVEit (CVE-2023-34362), Fortra GoAnywhere (CVE-2023-0669), Cleo (CVE-2024-50623, CVE-2024-55956), Oracle EBS (CVE-2025-61882), Gladinet CentreStack security update released 2025-11-29
Immediate actions
- Enumerate all internet-facing MFT and file-transfer applications (on-premises and SaaS), including shadow IT
- Apply default-deny WAF allowlisting (about 15 legitimate URI paths) for MFT applications and block historical exploit paths such as /moveitisapi/moveitisapi.dll
- Retro-hunt full log history after every MFT zero-day disclosure for anomalous URIs and traffic from Cl0p-associated ASNs
- Block or alert on pubstorm.com, pubstorm.net and the listed Cl0p reconnaissance IPs
Workarounds
- Gladinet CentreStack: disable the temp handler in UploadDownloadProxy Web.config where the vendor advises it
- Restrict internet exposure of MFT admin and API paths to allowlisted sources
Longer-term hardening
- Retain MFT and web logs for a minimum of 12 months, preferably 24 months
- Separate internet-facing web components from encryption key material and file storage
- Baseline URI access patterns and hourly/daily outbound volumes per MFT device and tighten egress alerting October-January
- Maintain a rolling 180-day watchlist of Cl0p-associated hosting ASNs
CVEs associated with Cl0p Ransomware MFT Attack Pattern
CVE-2023-34362, CVE-2021-35211, CVE-2023-0669, CVE-2023-27350, CVE-2023-47246, CVE-2024-50623, CVE-2024-55956, CVE-2025-61882, CVE-2025-11371, CVE-2025-30406, CVE-2021-27101
Weaknesses (CWE) in Cl0p Ransomware MFT Attack Pattern
Timeline of Cl0p Ransomware MFT Attack Pattern
- Cl0p begins exploiting zero-days in Accellion FTA (mid-December 2020 to January 2021), the first MFT-focused campaign in the series.
- IP 45.129.137.232 observed probing MOVEit API endpoints in July 2021, roughly two years before the MOVEit campaign and concurrent with Serv-U operations.
- IP 92.118.36.233 observed scanning MOVEit in April 2022.
- Cl0p exploits Fortra GoAnywhere MFT zero-day (CVE-2023-0669) in January 2023, after a 14-month dormancy; about 130 organizations affected per public reporting.
- Cl0p exploits MOVEit Transfer SQL injection (CVE-2023-34362) in May 2023 and deploys the LEMURLOOT web shell, followed by PaperCut, SysAid and further 2023 campaigns.
- Cl0p exploits Cleo Harmony, VLTrader and LexiCom (CVE-2024-50623, CVE-2024-55956) in December 2024.
- IP 200.107.207.26 performs reconnaissance against Oracle E-Business Suite in July 2025 and returns in August for exploitation.
- Extortion emails sent to Oracle EBS customers (CVE-2025-61882) roughly two months after exploitation began; attribution to Cl0p partially disputed.
- Gladinet CentreStack compromises begin on Thanksgiving Day; scanning surge corroborated by Team Cymru from this date.
- Gladinet releases a critical security update on a Saturday.
- Public advisory on the CentreStack campaign published; Security Affairs coverage follows on 2025-12-19.
- Team Cymru publishes 'Cl0p Til you Drop', noting the next operational cycle may be approaching given the typical 10-14 month dormancy and Q4 clustering.
Sources cited for Cl0p Ransomware MFT Attack Pattern
- Cl0p Til you Drop - 6 Years, 10 Campaigns, 8 Zero-Days (Team Cymru, Eli Woodward)
- CLOP targets Gladinet CentreStack servers in large-scale extortion campaign (Security Affairs)
- Cl0p is back exploiting supply chains again (Vectra AI)
- Addressing CL0P Extortion Campaign Targeting Oracle EBS CVE-2025-61882 (Cybereason)
- Cl0p ransomware surge 2025: operational patterns and key mitigations (HivePro)
- Exploitation of CVE-2023-47246 (SecurityScorecard)
- Ransomware Spotlight: Clop (Trend Micro)
- NVD - CVE-2023-34362 (MOVEit Transfer SQL injection)
- NVD - CVE-2025-61882 (Oracle E-Business Suite)
Detection coverage for TL-2026-3070
As of 2026-10-09, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-3070 across Splunk SPL, Microsoft KQL and Sigma, covering 16 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.