Do these 3 things before closing this tab:
1Clear out junk files and repair common Windows errors2Fix the driver behind crashes, sound loss and screen glitches3Repair Windows errors before they cause bigger problemsKroll Threat Intelligence found evidence that Cl0p was testing ways to exploit MOVEit Transfer as early as July 2021—nearly two years before the group began exploiting the flaw at scale in May 2023. Kroll assessed with high confidence that the attackers had a working exploit in 2021, based on its review of affected clients’ IIS logs. That earlier timeline is Kroll’s assessment reported by Dark Reading, not a finding in the later FBI/CISA advisory.
What the nearly two-year timeline means
The July 2021 date marks reported testing, not the start of the public campaign. Dark Reading reported that Kroll investigators found evidence of Cl0p experimenting with MOVEit exploitation at that time and assessed with high confidence that the group already had a working exploit. Kroll’s observations came from IIS logs belonging to clients later affected by the attacks.
The FBI and CISA advisory places the start of exploitation of CVE-2023-34362 on May 27, 2023, according to open-source information. The agencies confirm the 2023 campaign; they do not establish the earlier testing date.
What Kroll reportedly observed
| When | Reported activity |
|---|---|
| July 2021 | Kroll found evidence of Cl0p experimenting with MOVEit exploitation and assessed with high confidence that it had a working exploit, according to Dark Reading. |
| April 2022 | Kroll reportedly saw another wave of activity, using an automated mechanism to probe multiple organizations and collect information. |
| May 2023 | Kroll reportedly observed final testing shortly before mass exploitation; the attackers appeared to extract MOVEit organization identifiers. |
| May 27, 2023 | FBI/CISA says CL0P began exploiting CVE-2023-34362 on this date, according to open-source information. |
| June 7, 2023 | FBI and CISA released their joint advisory on the campaign and mitigation measures. |
What the MOVEit vulnerability allowed
MOVEit Transfer is managed file-transfer software used by organizations. CVE-2023-34362 was a previously unknown SQL injection vulnerability in its web application. During the campaign, attackers compromised internet-facing MOVEit Transfer applications with the LEMURLOOT web shell, which they used to interact with the application and steal data from underlying MOVEit databases.
Free tools Windows power users keep installed
One-click scans. No signup required.
#1 Best Overall
The FBI/CISA advisory describes affected product versions in the context of the 2023 incident. That historical list is not a current patch-status guide; organizations should consult Progress Software’s current security information for their deployed version rather than rely on an old affected-version list.
Why the group waited is not established
The reported evidence supports a long gap between testing and the May 2023 campaign, but it does not establish why Cl0p waited. Dark Reading described possible explanations, including competing activity and circumstances within the group, as hypotheses from Kroll analysts—not proven motives. The observations show that testing and later exploitation occurred at different times; they do not reveal a definitive decision-making process.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.What organizations can take from the campaign
The FBI/CISA advisory’s mitigations apply broadly to organizations operating internet-facing systems, including managed file-transfer services. Prioritize measures that reduce exposure and make unusual activity easier to detect:
- Maintain an inventory of internet-facing assets and the data they handle.
- Limit administrative access to people who need it, and monitor exposed ports and services.
- Apply software patches and updates promptly; conduct vulnerability assessments to identify gaps.
- Segment networks to limit the reach of a compromised application.
- Log and investigate abnormal network and application activity, and keep endpoint protection current.
- Validate security controls against the threat behaviors mapped in the advisory to MITRE ATT&CK.
The advisory also notes that FBI and CISA do not endorse commercial products. Cl0p’s MOVEit activity followed earlier zero-day campaigns involving Accellion FTA in 2020–2021 and Fortra/Linoma GoAnywhere MFT in early 2023, a reminder that organizations should treat internet-facing file-transfer systems as assets requiring active inventory, patching, and monitoring.
Windows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallOutdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchQuick Recap
Best Value
Sources
- Dark Reading: Kroll’s account of the earlier MOVEit testing.
- FBI/CISA joint advisory AA23-158A, released June 7, 2023.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

