Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Kroll Threat Intelligence found evidence that Cl0p was testing ways to exploit MOVEit Transfer as early as July 2021—nearly two years before the group began exploiting the flaw at scale in May 2023. Kroll assessed with high confidence that the attackers had a working exploit in 2021, based on its review of affected clients’ IIS logs. That earlier timeline is Kroll’s assessment reported by Dark Reading, not a finding in the later FBI/CISA advisory.

What the nearly two-year timeline means

The July 2021 date marks reported testing, not the start of the public campaign. Dark Reading reported that Kroll investigators found evidence of Cl0p experimenting with MOVEit exploitation at that time and assessed with high confidence that the group already had a working exploit. Kroll’s observations came from IIS logs belonging to clients later affected by the attacks.

The FBI and CISA advisory places the start of exploitation of CVE-2023-34362 on May 27, 2023, according to open-source information. The agencies confirm the 2023 campaign; they do not establish the earlier testing date.

What Kroll reportedly observed

When Reported activity
July 2021 Kroll found evidence of Cl0p experimenting with MOVEit exploitation and assessed with high confidence that it had a working exploit, according to Dark Reading.
April 2022 Kroll reportedly saw another wave of activity, using an automated mechanism to probe multiple organizations and collect information.
May 2023 Kroll reportedly observed final testing shortly before mass exploitation; the attackers appeared to extract MOVEit organization identifiers.
May 27, 2023 FBI/CISA says CL0P began exploiting CVE-2023-34362 on this date, according to open-source information.
June 7, 2023 FBI and CISA released their joint advisory on the campaign and mitigation measures.

What the MOVEit vulnerability allowed

MOVEit Transfer is managed file-transfer software used by organizations. CVE-2023-34362 was a previously unknown SQL injection vulnerability in its web application. During the campaign, attackers compromised internet-facing MOVEit Transfer applications with the LEMURLOOT web shell, which they used to interact with the application and steal data from underlying MOVEit databases.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall

The FBI/CISA advisory describes affected product versions in the context of the 2023 incident. That historical list is not a current patch-status guide; organizations should consult Progress Software’s current security information for their deployed version rather than rely on an old affected-version list.

Why the group waited is not established

The reported evidence supports a long gap between testing and the May 2023 campaign, but it does not establish why Cl0p waited. Dark Reading described possible explanations, including competing activity and circumstances within the group, as hypotheses from Kroll analysts—not proven motives. The observations show that testing and later exploitation occurred at different times; they do not reveal a definitive decision-making process.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What organizations can take from the campaign

The FBI/CISA advisory’s mitigations apply broadly to organizations operating internet-facing systems, including managed file-transfer services. Prioritize measures that reduce exposure and make unusual activity easier to detect:

  • Maintain an inventory of internet-facing assets and the data they handle.
  • Limit administrative access to people who need it, and monitor exposed ports and services.
  • Apply software patches and updates promptly; conduct vulnerability assessments to identify gaps.
  • Segment networks to limit the reach of a compromised application.
  • Log and investigate abnormal network and application activity, and keep endpoint protection current.
  • Validate security controls against the threat behaviors mapped in the advisory to MITRE ATT&CK.

The advisory also notes that FBI and CISA do not endorse commercial products. Cl0p’s MOVEit activity followed earlier zero-day campaigns involving Accellion FTA in 2020–2021 and Fortra/Linoma GoAnywhere MFT in early 2023, a reminder that organizations should treat internet-facing file-transfer systems as assets requiring active inventory, patching, and monitoring.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Sources

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.