MOVEit Transfer Mass Zero-Day Extortion Campaign
Key Facts
- Legal Status: INVESTIGATION in U.S. District Court for the District of Massachusetts.
- Primary Target Sector: Government, Financial Services, Healthcare, Technology.
- Documented Financial Loss: $1.2 billion.
- 3 verified MITRE ATT&CK techniques substantiated with verbatim court excerpts.
Case Summary
Executive Summary for Board Members & Leadership
Plain-English Root Cause
Pre-authenticated SQL injection vulnerability (CVE-2023-34362) in the web application interface of Progress Software MOVEit Transfer managed file transfer servers, allowing remote database access and arbitrary code execution.
Operational & Financial Fallout
Compromised over 2,700 organizations and exposed personal records of over 95 million individuals worldwide. High-impact victims included the BBC, British Airways, Siemens Energy, Shell, UCLA, and multiple US federal agencies including the Department of Energy, resulting in collective breach response and liability costs exceeding $10 billion.
3 Critical Boardroom Questions
- 1. Do 100% of our external portals enforce phishing-resistant hardware MFA?
- 2. Can compromised endpoint credentials traverse laterally to domain controllers or cloud storage?
- 3. Have our air-gapped immutable recovery backups been restored and tested within the last 90 days?
Attack Anatomy & Incident Execution
Forensic analysis of initial intrusion vector, step-by-step kill chain, operational blast radius, and defensive controls.
Pre-authenticated SQL injection vulnerability (CVE-2023-34362) in the web application interface of Progress Software MOVEit Transfer managed file transfer servers, allowing remote database access and arbitrary code execution.
Adversary Kill Chain Flow
5 Documented PhasesAdversaries submitted crafted HTTP requests bypassing input sanitization to inject SQL commands into the MOVEit database session.
The SQL injection created an administrative session that wrote a custom web shell named human2.aspx into the web root directory.
LEMURLOOT received inbound HTTP headers, querying MySQL/MS-SQL databases for active Azure blob storage credentials, user tables, and file metadata.
Automated scripts systematically downloaded sensitive tenant files from disk and cloud storage buckets through the web shell.
Cl0p extorted victim organizations on their Tor leak site without encrypting underlying servers, threatening public release of exfiltrated data.
Compromised over 2,700 organizations and exposed personal records of over 95 million individuals worldwide. High-impact victims included the BBC, British Airways, Siemens Energy, Shell, UCLA, and multiple US federal agencies including the Department of Energy, resulting in collective breach response and liability costs exceeding $10 billion.
Procedural & Incident Timeline
Cl0p ransomware operators execute mass automated exploitation of MOVEit Transfer installations.
Progress Software releases security advisory and patch for critical zero-day CVE-2023-34362.
Dozens of government agencies and Fortune 500 companies file breach disclosures.
Substantiated MITRE ATT&CK Techniques
| Technique ID | Technique Name & Tactic | Primary Source Evidence Excerpt | Locator | Verification |
|---|---|---|---|---|
| T1190 | Exploit Public-Facing Application Initial Access | "Threat actors submitted crafted HTTP requests containing SQL injection payloads to internet-facing moveitisapi.dll endpoints to bypass authentication and execute arbitrary database queries." | CISA Advisory AA23-158A | reviewed |
| T1505.003 | "Upon achieving remote access, the actors dropped a customized .NET webshell named human2.aspx into the wwwroot directory, designed to dump azure and local database files." | Mandiant Incident Response Report on CVE-2023-34362 | reviewed | |
| T1567.002 | "Extracted archives were compressed into multipart ZIP files and exfiltrated to adversary-controlled cloud servers prior to publishing extortion notices on Tor leak sites." | CISA Advisory AA23-158A | reviewed |