Huntress published a rapid-response analysis of CVE-2023-34362, a critical zero-day SQL injection vulnerability in Progress MOVEit Transfer. The flaw allows unauthenticated attackers to gain administrative access, exfiltrate files, and achieve arbitrary code execution. Huntress fully recreated the attack chain, demonstrating Meterpreter shell access, privilege escalation to NT AUTHORITY\SYSTEM, and detonation of Cl0p ransomware. The attack deploys a webshell (human2.aspx) for persistence, though the webshell is not required for exploitation. Microsoft attributed the attacks to 'Lace Tempest,' the group behind the Cl0p ransomware gang. Mitigation guidance includes patching to specific versions or blocking HTTP/HTTPS traffic to MOVEit. Detection artifacts include YARA and Sigma rules, IIS log patterns, suspicious DLL files in ASP.NET temp directories, and process monitoring queries.

10m read timeFrom huntress.com
Post cover image
Table of contents
What it DoesTechnical Analysis and InvestigationDetection EffortsInvestigation TipsWhat You Should DoIndicators of Attack (IOAs)Resources and References