CASE DOSSIER investigation

MOVEit Transfer Mass Zero-Day Extortion Campaign

Docket: CISA Advisory AA23-158A Court: U.S. District Court for the District of Massachusetts Opened: 2023-05-31 Sector: Government, Financial Services, Healthcare, Technology

Key Facts

Status
INVESTIGATION
Legal disposition
Loss Amount
$1.2 billion
Estimated aggregate forensic investigation, breach notification, and class litigation costs.
Techniques
3
Verified mappings
Defendants
0
Named in charges
  • Legal Status: INVESTIGATION in U.S. District Court for the District of Massachusetts.
  • Primary Target Sector: Government, Financial Services, Healthcare, Technology.
  • Documented Financial Loss: $1.2 billion.
  • 3 verified MITRE ATT&CK techniques substantiated with verbatim court excerpts.
Export structured case data and MITRE ATT&CK Navigator layer:

Case Summary

Mass cyber extortion campaign exploiting a zero-day SQL injection vulnerability (CVE-2023-34362) in Progress Software MOVEit Transfer appliances, exfiltrating personal records of over 90 million individuals across 2,700 organizations without encrypting files.
BOARDROOM EXECUTIVE BRIEF

Executive Summary for Board Members & Leadership

Plain-English Root Cause

Pre-authenticated SQL injection vulnerability (CVE-2023-34362) in the web application interface of Progress Software MOVEit Transfer managed file transfer servers, allowing remote database access and arbitrary code execution.

Operational & Financial Fallout

Compromised over 2,700 organizations and exposed personal records of over 95 million individuals worldwide. High-impact victims included the BBC, British Airways, Siemens Energy, Shell, UCLA, and multiple US federal agencies including the Department of Energy, resulting in collective breach response and liability costs exceeding $10 billion.

3 Critical Boardroom Questions

  • 1. Do 100% of our external portals enforce phishing-resistant hardware MFA?
  • 2. Can compromised endpoint credentials traverse laterally to domain controllers or cloud storage?
  • 3. Have our air-gapped immutable recovery backups been restored and tested within the last 90 days?
Disposition: INVESTIGATION
Technical Threat Intelligence

Attack Anatomy & Incident Execution

Forensic analysis of initial intrusion vector, step-by-step kill chain, operational blast radius, and defensive controls.

Ground Zero / Infiltration Vector

Pre-authenticated SQL injection vulnerability (CVE-2023-34362) in the web application interface of Progress Software MOVEit Transfer managed file transfer servers, allowing remote database access and arbitrary code execution.

Adversary Kill Chain Flow

5 Documented Phases
1
Initial Ingress Pre-Auth SQL Injection Ingress (CVE-2023-34362)
MITRE ATT&CK T1190 →

Adversaries submitted crafted HTTP requests bypassing input sanitization to inject SQL commands into the MOVEit database session.

Artifacts & Tooling: CVE-2023-34362 exploit payload MOVEit guest session forgery
2
Persistence Web Shell Insertion (LEMURLOOT)
MITRE ATT&CK T1505.003 →

The SQL injection created an administrative session that wrote a custom web shell named human2.aspx into the web root directory.

Artifacts & Tooling: human2.aspx web shell MOVEit file upload endpoint
3
Credential & Data Discovery Automated Database Metadata Extraction
MITRE ATT&CK T1005 →

LEMURLOOT received inbound HTTP headers, querying MySQL/MS-SQL databases for active Azure blob storage credentials, user tables, and file metadata.

Artifacts & Tooling: Database queries for Azure blob keys MOVEit database table dumps
4
Exfiltration Mass File Staging & Streaming Exfiltration
MITRE ATT&CK T1567 →

Automated scripts systematically downloaded sensitive tenant files from disk and cloud storage buckets through the web shell.

Artifacts & Tooling: Automated HTTP file streaming Gzip compressed payloads
5
Extortion Impact Dark Web Shaming & Tor Extortion
MITRE ATT&CK T1651 →

Cl0p extorted victim organizations on their Tor leak site without encrypting underlying servers, threatening public release of exfiltrated data.

Artifacts & Tooling: Cl0p Tor leak publication Extortion ransom notices
Real-World Blast Radius & Operational Fallout

Compromised over 2,700 organizations and exposed personal records of over 95 million individuals worldwide. High-impact victims included the BBC, British Airways, Siemens Energy, Shell, UCLA, and multiple US federal agencies including the Department of Energy, resulting in collective breach response and liability costs exceeding $10 billion.

Defensive Engineering Takeaways
Recommended Hardening Controls
✓ Isolate Managed File Transfer (MFT) solutions behind Web Application Firewalls (WAF) and zero-trust reverse proxies.
✓ Enforce egress filtering on file transfer servers to prevent unauthorized data streams to foreign IP addresses.
✓ Implement file integrity monitoring (FIM) on web server document roots to detect rogue .aspx or .php files.
✓ Adopt strict patch cadence for critical public-facing enterprise appliances.

Procedural & Incident Timeline

2023-05-27 incident

Cl0p ransomware operators execute mass automated exploitation of MOVEit Transfer installations.

2023-05-31 advisory

Progress Software releases security advisory and patch for critical zero-day CVE-2023-34362.

2023-06-07 disclosure

Dozens of government agencies and Fortune 500 companies file breach disclosures.

Substantiated MITRE ATT&CK Techniques

Technique ID Technique Name & Tactic Primary Source Evidence Excerpt Locator Verification
T1190 Exploit Public-Facing Application
Initial Access
"Threat actors submitted crafted HTTP requests containing SQL injection payloads to internet-facing moveitisapi.dll endpoints to bypass authentication and execute arbitrary database queries." CISA Advisory AA23-158A reviewed
T1505.003
"Upon achieving remote access, the actors dropped a customized .NET webshell named human2.aspx into the wwwroot directory, designed to dump azure and local database files." Mandiant Incident Response Report on CVE-2023-34362 reviewed
T1567.002
"Extracted archives were compressed into multipart ZIP files and exfiltrated to adversary-controlled cloud servers prior to publishing extortion notices on Tor leak sites." CISA Advisory AA23-158A reviewed

Cite & Embed This Case Record

Public Domain / CC0
Bluebook Legal Citation:
Cyberattack Case Library, MOVEit Transfer Mass Zero-Day Extortion Campaign, No. CISA Advisory AA23-158A (U.S. District Court for the District of Massachusetts 2023), https://cybercaselibrary.com/cases/moveit-transfer-mass-data-extortion/
Embeddable Incident Card (HTML):
<iframe src="https://cybercaselibrary.com/embed/case/moveit-transfer-mass-data-extortion" width="100%" height="220" style="border:none; border-radius:6px;" loading="lazy"></iframe>