{
  "id": "case-moveit-extortion",
  "slug": "moveit-transfer-mass-data-extortion",
  "title": "MOVEit Transfer Mass Zero-Day Extortion Campaign",
  "summary": "Mass cyber extortion campaign exploiting a zero-day SQL injection vulnerability (CVE-2023-34362) in Progress Software MOVEit Transfer appliances, exfiltrating personal records of over 90 million individuals across 2,700 organizations without encrypting files.",
  "case_number": "CISA Advisory AA23-158A",
  "court": "U.S. District Court for the District of Massachusetts",
  "district": "D. Mass.",
  "country": "United States",
  "opened_at": "2023-05-31",
  "status": "investigation",
  "victim_sector": "Government, Financial Services, Healthcare, Technology",
  "victim_country": "United States",
  "loss_amount_usd": 1200000000,
  "loss_amount_note": "Estimated aggregate forensic investigation, breach notification, and class litigation costs.",
  "first_seen_at": "2023-05-27T00:00:00Z",
  "last_updated_at": "2026-10-02T10:00:00Z",
  "actor_slug": "cl0p",
  "defendant_slugs": [],
  "cves": [
    "CVE-2023-34362"
  ],
  "techniques": [
    {
      "technique_id": "T1190",
      "evidence_excerpt": "Threat actors submitted crafted HTTP requests containing SQL injection payloads to internet-facing moveitisapi.dll endpoints to bypass authentication and execute arbitrary database queries.",
      "evidence_locator": "CISA Advisory AA23-158A",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "CISA Advisory: CL0P Ransomware Gang Exploits MOVEit Vulnerability",
      "source_url": "https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-158a",
      "technique_name": "Exploit Public-Facing Application",
      "tactic": "Initial Access"
    },
    {
      "technique_id": "T1505.003",
      "evidence_excerpt": "Upon achieving remote access, the actors dropped a customized .NET webshell named human2.aspx into the wwwroot directory, designed to dump azure and local database files.",
      "evidence_locator": "Mandiant Incident Response Report on CVE-2023-34362",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "Mandiant Intelligence Advisory",
      "source_url": "https://www.mandiant.com"
    },
    {
      "technique_id": "T1567.002",
      "evidence_excerpt": "Extracted archives were compressed into multipart ZIP files and exfiltrated to adversary-controlled cloud servers prior to publishing extortion notices on Tor leak sites.",
      "evidence_locator": "CISA Advisory AA23-158A",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "CISA Advisory AA23-158A",
      "source_url": "https://www.cisa.gov"
    }
  ],
  "events": [
    {
      "event_type": "incident",
      "event_date": "2023-05-27",
      "description": "Cl0p ransomware operators execute mass automated exploitation of MOVEit Transfer installations."
    },
    {
      "event_type": "advisory",
      "event_date": "2023-05-31",
      "description": "Progress Software releases security advisory and patch for critical zero-day CVE-2023-34362."
    },
    {
      "event_type": "disclosure",
      "event_date": "2023-06-07",
      "description": "Dozens of government agencies and Fortune 500 companies file breach disclosures."
    }
  ],
  "attack_anatomy": {
    "ground_zero": "Pre-authenticated SQL injection vulnerability (CVE-2023-34362) in the web application interface of Progress Software MOVEit Transfer managed file transfer servers, allowing remote database access and arbitrary code execution.",
    "blast_radius": "Compromised over 2,700 organizations and exposed personal records of over 95 million individuals worldwide. High-impact victims included the BBC, British Airways, Siemens Energy, Shell, UCLA, and multiple US federal agencies including the Department of Energy, resulting in collective breach response and liability costs exceeding $10 billion.",
    "kill_chain": [
      {
        "phase": "Initial Ingress",
        "title": "Pre-Auth SQL Injection Ingress (CVE-2023-34362)",
        "description": "Adversaries submitted crafted HTTP requests bypassing input sanitization to inject SQL commands into the MOVEit database session.",
        "technical_artifacts": [
          "CVE-2023-34362 exploit payload",
          "MOVEit guest session forgery"
        ],
        "mitre_technique_id": "T1190"
      },
      {
        "phase": "Persistence",
        "title": "Web Shell Insertion (LEMURLOOT)",
        "description": "The SQL injection created an administrative session that wrote a custom web shell named human2.aspx into the web root directory.",
        "technical_artifacts": [
          "human2.aspx web shell",
          "MOVEit file upload endpoint"
        ],
        "mitre_technique_id": "T1505.003"
      },
      {
        "phase": "Credential & Data Discovery",
        "title": "Automated Database Metadata Extraction",
        "description": "LEMURLOOT received inbound HTTP headers, querying MySQL/MS-SQL databases for active Azure blob storage credentials, user tables, and file metadata.",
        "technical_artifacts": [
          "Database queries for Azure blob keys",
          "MOVEit database table dumps"
        ],
        "mitre_technique_id": "T1005"
      },
      {
        "phase": "Exfiltration",
        "title": "Mass File Staging & Streaming Exfiltration",
        "description": "Automated scripts systematically downloaded sensitive tenant files from disk and cloud storage buckets through the web shell.",
        "technical_artifacts": [
          "Automated HTTP file streaming",
          "Gzip compressed payloads"
        ],
        "mitre_technique_id": "T1567"
      },
      {
        "phase": "Extortion Impact",
        "title": "Dark Web Shaming & Tor Extortion",
        "description": "Cl0p extorted victim organizations on their Tor leak site without encrypting underlying servers, threatening public release of exfiltrated data.",
        "technical_artifacts": [
          "Cl0p Tor leak publication",
          "Extortion ransom notices"
        ],
        "mitre_technique_id": "T1651"
      }
    ],
    "defensive_takeaways": [
      "Isolate Managed File Transfer (MFT) solutions behind Web Application Firewalls (WAF) and zero-trust reverse proxies.",
      "Enforce egress filtering on file transfer servers to prevent unauthorized data streams to foreign IP addresses.",
      "Implement file integrity monitoring (FIM) on web server document roots to detect rogue .aspx or .php files.",
      "Adopt strict patch cadence for critical public-facing enterprise appliances."
    ]
  }
}