Breadcrumb

  • Home
  • Document server ransom attack.

Search form

Main navigation

  • Home

HOME | ALL NEWS

Document server ransom attack.

Thursday, 8 June, 2023 - 02:11

The so-called CLOP ransomware hacking group reportedly accessed the servers of file transfer company GoAnywhere and downloaded files belonging to customers. GoAnywhere is a file transfer system that allows users to upload and download files that are too large to transmit by e-mail. It is one of many such systems and, by extension, online document approvals systems.

"This joint (Federal Bureau of Investigation and Cyber Security and Information Security Agency) Cybersecurity Advisory is part of an ongoing #StopRansomware effort to publish warnings for network defenders that detail various ransomware variants and this effecting threats through ransomware threat. These #StopRansomware warnings include recently and historically observed tactics, techniques, and procedures and indicators of compromise to help organizations protect against ransomware. Visit stopransomware.gov to see all #StopRansomware warning notices and to learn more about other ransomware threats and no-cost resources." (edited)

According to open source information, The USA's Cyber Security and Information Security Agency says, beginning on 27 May, 2023, CL0P Ransomware Gang, also known as TA505, began exploiting a previously unknown SQL injection vulnerability (CVE-2023-34362) in Progress Software's managed file transfer (MFT) solution known as MOVEit Transfer. Internet-facing MOVEit Transfer web applications were infected with a web shell named LEMURLOOT, which was then used to steal data from underlying MOVEit Transfer databases. In similar spates of activity, TA505 conducted zero-day-exploit-driven campaigns against Accellion File Transfer Appliance (FTA) devices in 2020 and 2021, and Fortra/Linoma GoAnywhere MFT servers in early 2023.

The full notice and links to resources are here: https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-158a

This is important because many organisations, large and small, use online document transfer services and online document approvals services.

These are used by, for example, tax form preparers, law firms settling terms of a document and more. The confidential nature of the documents in such services is paramount.

A D V E R T I S E M E N T

Footer menu

  • Weekly Digest (opens in new tab)
  • Images attribution (opens in new tab)
  • Corporate, privacy, intellectual property and access (opens in new tab)
  • Advertising and Recommendations (opens in new tab)
  • Promote your business (opens in new tab)
  • Enquiries (opens in new tab)


 

BOT AND SCRAPER ACCESS DENIED

 


 

Built with Drupal     |     Hosted by Siteground     |     Template by Alaa Haddad     

Design by Vortex Centrum Limited    |     Some services provided by Google Workspace    

Posters and other merch by ProjectLXX   |   Privacy and security services by Surfshark and Firetrust. 


Nothing in this website is intended to be or shall be taken as legal advice. 

You should always seek advice from a practitioner experienced in this area. 


Everything on this website is copyright Nigel Morris-Cotterill and/or Vortex Centrum Limited for itself or one of its business units. No downloading, printing or other means of replicating or reusing is permitted. In particular, all bot access is denied and all scraping of content will result in the legal action set forth in the terms and conditions in this site. For legal, cookies and privacy see vortexcentrum.com.

Copyright 1999- © 2026 Vortex Centrum Limited - All rights reserved. Bot access denied.