The world of cybersecurity has been stirred up recently by the MOVEit Transfer cyberattack. Revealed publicly on June 5, 2023, by the Clop ransomware group, this zero-day vulnerability (CVE-2023-34362) in the MOVEit Transfer secure file transfer web application has opened doors for cybercriminals to gain unauthenticated access to MOVEit Transfer servers.
What Is the MOVEit Transfer Cyberattack?
The MOVEit Transfer vulnerability allows threat actors to upload a web shell and exfiltrate data. The Clop ransomware group, which took responsibility for exploiting the vulnerability, has been found to be experimenting with the exploitation since as early as 2021. This type of long-term planning and knowledge base underscores the complexity of the MOVEit Transfer cyberattack and the high level of sophistication of modern cybercriminals.
How Does It Work?
The MOVEit Transfer cyberattack centers around interaction between two legitimate components of MOVEit Transfer: moveitisapi/moveitisapi.dll and guestaccess.aspx. Once the attackers gain access, they deploy a human2.aspx web shell, which allows them to control the server remotely and exfiltrate data1.
Interestingly, the Clop threat actors have been observed to pull back an Organization ID, a unique identifier for each MOVEit Transfer user. This allows the attackers to categorize the entities they could access, facilitating victim categorization and data inventorying on a per-exfiltration operation basis.
Who Has Been Affected?
The MOVEit Transfer vulnerability has impacted a wide range of companies, with a surge of activity related to the vulnerability observed just before the public announcement of the vulnerability by Progress Software on May 31, 20231. Evidence of similar activity has been found in multiple client environments as early as July 2021, indicating that the attackers were testing access to organizations via automated means and pulling back information from the MOVEit Transfer servers to identify which organizations they were accessing.
How Can Businesses Protect Themselves?
In the face of sophisticated cyberattacks like the MOVEit Transfer cyberattack, organizations must employ robust cybersecurity measures. Regularly updating and patching software, educating employees about potential threats, and working with cybersecurity experts are some of the key steps businesses can take to protect themselves.
Conclusion
Cybersecurity threats are becoming increasingly sophisticated, and the MOVEit Transfer cyberattack is a stark reminder of this reality. If your company is worried about its cybersecurity posture, it’s time to take action.
At Wizard Cyber, we provide bespoke & powerful managed solutions to protect enterprises against all forms of cybercrime. Our team of cyber security experts are always ready to answer any questions or concerns you might have about our products or managed services. If you’re worried about your business’ cyber security and would like some advice or guidance, we’re here to help.
To speak with one of our experts and find out how our services can benefit your organization, book a meeting with us today.


