Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Kroll’s retrospective review of logs from compromised MOVEit Transfer environments found activity resembling earlier probing as far back as July 2021, with similar activity again in April 2022. The evidence supports the possibility that actors later associated with the Clop campaign were testing or exploring MOVEit before the 2023 attacks. It does not prove when they discovered the vulnerability, that every earlier event was an exploit, or that the finished 2023 exploit existed in 2021.

What the earlier MOVEit logs show

Kroll identified activity in affected client environments that resembled MOVEit Transfer exploitation in July 2021. BleepingComputer reported that the commands matched activity issued manually against MOVEit servers. Kroll also found similar activity in multiple client environments in April 2022, which it described as consistent with testing access and retrieving information to identify organizations.

These are retrospective findings: investigators found the older activity while responding to the 2023 attacks. They point to possible pre-campaign probing, but logs alone cannot establish what operators knew or intended at the time.

How the evidence fits the 2023 campaign timeline

Date What investigators reported What it establishes
July 2021 Kroll found similar activity in logs; BleepingComputer reported that the commands resembled manual commands against MOVEit Transfer servers. Earlier activity consistent with probing or testing—not proof of a completed exploit or a precise discovery date.
April 2022 Kroll observed similar activity in multiple client environments, consistent with testing access and retrieving information to identify organizations. Further evidence of possible exploration before the 2023 campaign.
May 15–16 and May 22, 2023 Kroll described a scale-up in automated activity shortly before the main exploitation wave. A later activity phase distinct from the older log findings.
May 27, 2023 Mandiant reported this as the earliest exploitation of CVE-2023-34362 it had observed, involving web-shell deployment and data theft. The earliest date Mandiant observed in its investigation, not necessarily the first exploitation anywhere.
May 31 and June 2, 2023 Progress announced the vulnerability on May 31; Mandiant reported that CISA added it to the Known Exploited Vulnerabilities catalog on June 2. Public disclosure and catalog dates, not the start of the earlier activity.
June 7, 2023 CISA and the FBI published a joint advisory about the campaign. A public government advisory issued after exploitation had been observed.

The timeline does not describe one uninterrupted exploit operating from 2021 through 2023. The early log artifacts, inferred testing, increased automated activity in May 2023, and observed mass exploitation are separate evidence points.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What MOVEit vulnerability was exploited?

MOVEit Transfer is Progress Software’s managed file-transfer product. CVE-2023-34362 was a SQL-injection vulnerability. Mandiant observed attackers exploit it to deploy a web shell and steal data; its analysis discusses LEMURLOOT, a web shell tailored to MOVEit Transfer. The campaign targeted information held in file-transfer systems. Mandiant also noted that some samples could retrieve Azure storage configuration and credentials.

How confidently can the activity be attributed to Clop?

Attribution labels vary by source and should be kept distinct. BleepingComputer reported Kroll’s findings as activity by the Clop ransomware group. Mandiant initially attributed the 2023 campaign to UNC4857, then said it merged UNC4857 into FIN11 based on overlaps in targeting, infrastructure, certificates, and data-leak-site activity. The CISA/FBI advisory calls the group CL0P, also known as TA505.

Those labels reflect the respective sources’ analyses; they do not mean every tracking name is universally interchangeable. Nor do the earlier logs by themselves settle who carried out each event. The defensible conclusion is that the activity is consistent with pre-campaign probing by actors later associated with the MOVEit campaign.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What the finding means for organizations

A public disclosure date is not a reliable boundary for when suspicious activity may have begun. Organizations investigating historical MOVEit exposure should base conclusions on retained logs, technical indicators, and a qualified incident-response assessment rather than assuming activity began only when the vulnerability was publicly announced. Mandiant published incident containment, hardening, logging, and hunting guidance, while CISA and the FBI issued a joint advisory. For current response decisions, use current official guidance rather than treating a 2023 report as a current vulnerability notice.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.