SophiaX
🔍
LIVE
· New victim: Portable Intelligence Inc www.portable-intelligence.com serviced by an IT company Computer... — blacknevas· New victim: Riker Danzig Scherer Hyland & Perretti — SilentRansomGroup· New victim: Hightech Signs — kairos· New victim: Riker Danzig LLP — SilentRansomGroup· New victim: gamaus.com — incransom· New KEV: CVE-2026-72898 · Metabase· New KEV: CVE-2026-20349 · Cisco· New KEV: CVE-2026-68820 · Microsoft· New KEV: CVE-2026-8037 · Progress· New KEV: CVE-2026-63077 · JetBrains· New victim: 3,979 new IOCs ingested in last 24h Portable Intelligence Inc www.portable-intelligence.com serviced by an IT company Computer... — blacknevas· New victim: Riker Danzig Scherer Hyland & Perretti — SilentRansomGroup· New victim: Hightech Signs — kairos· New victim: Riker Danzig LLP — SilentRansomGroup· New victim: gamaus.com — incransom· New KEV: CVE-2026-72898 · Metabase· New KEV: CVE-2026-20349 · Cisco· New KEV: CVE-2026-68820 · Microsoft· New KEV: CVE-2026-8037 · Progress· New KEV: CVE-2026-63077 · JetBrains· 3,979 new IOCs ingested in last 24h

Clop

💰 eCrimeMotivation: financialLast active: 2026-08-07First seen: 2026-05-01
11
linked CVEs
Also known as
Cl0p
Targeted industries
Business ServicesHealthcare
Targeted regions
US
Observed for the first time in Febuary 2019, variant from CryptoMix Family, itself a variation from CryptXXX and CryptoWall family
Source: misp_galaxy · Collected: 2026-08-11
⚡ Vulnerabilities & Exploits11 CVEs
threat_actor_cve → cves / exploits.cve_ids
CVE-2025-55182
suspected

A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 including the following packages: react-server-dom-parcel, react-server-dom-turbopack, and react-server-dom-webpack. The vulnerable code unsafely deserializes payloads from HTTP requests to Server Function endpoints.

CVSS 10.0
KEVransomware
CVE-2025-11371
suspected

Gladinet CentreStack and Triofox contains a files or directories accessible to external parties vulnerability that allows unintended disclosure of system files.

KEV
CVE-2025-14611
suspected

Gladinet CentreStack and TrioFox contain a hardcoded cryptographic keys vulnerability for their implementation of the AES cryptoscheme. This vulnerability degrades security for public exposed endpoints that may make use of it and may offer arbitrary local file inclusion when provided a specially crafted request without authentication.

KEV
CVE-2025-30406
suspected

Gladinet CentreStack and Triofox contains a use of hard-coded cryptographic key vulnerability in the way that the application manages keys used for ViewState integrity verification. Successful exploitation allows an attacker to forge ViewState payloads for server-side deserialization, allowing for remote code execution.

KEV
CVE-2025-31151
suspected

CVE-2025-59287
suspected

Microsoft Windows Server Update Service (WSUS) contains a deserialization of untrusted data vulnerability that allows for remote code execution.

KEV
CVE-2023-22518
suspected

Atlassian Confluence Data Center and Server contain an improper authorization vulnerability that can result in significant data loss when exploited by an unauthenticated attacker. There is no impact on confidentiality since the attacker cannot exfiltrate any data.

KEVransomware
CVE-2023-43117
suspected

CVE-2023-46604
suspected

Apache ActiveMQ contains a deserialization of untrusted data vulnerability that may allow a remote attacker with network access to a broker to run shell commands by manipulating serialized class types in the OpenWire protocol to cause the broker to instantiate any class on the classpath.

KEVransomware
CVE-2025-31161
suspected

CrushFTP contains an authentication bypass vulnerability in the HTTP authorization header that allows a remote unauthenticated attacker to authenticate to any known or guessable user account (e.g., crushadmin), potentially leading to a full compromise.

KEVransomware
CVE-2023-34362
suspected

Progress MOVEit Transfer contains a SQL injection vulnerability that could allow an unauthenticated attacker to gain unauthorized access to MOVEit Transfer's database. Depending on the database engine being used (MySQL, Microsoft SQL Server, or Azure SQL), an attacker may be able to infer information about the structure and contents of the database in addition to executing SQL statements that alter or delete database elements.

KEVransomware
🔍 Detection Coverage13 Sigma
Derived from linked CVEs — not a direct actor match
highvia CVE-2025-30406
Suspicious Process Spawned by CentreStack Portal AppPool
windows
highvia CVE-2025-55182
Linux Suspicious Child Process from Node.js - React2Shell
linux
highvia CVE-2025-55182
Windows Suspicious Child Process from Node.js - React2Shell
windows
highvia CVE-2025-59287
Exploitation Activity of CVE-2025-59287 - WSUS Deserialization
windows
highvia CVE-2025-59287
Exploitation Activity of CVE-2025-59287 - WSUS Suspicious Child Process
windows
highvia CVE-2023-22518
CVE-2023-22518 Exploitation Attempt - Suspicious Confluence Child Process (Linux)
linux
mediumvia CVE-2023-22518
CVE-2023-22518 Exploitation Attempt - Suspicious Confluence Child Process (Windows)
windows
mediumvia CVE-2023-22518
CVE-2023-22518 Exploitation Attempt - Vulnerable Endpoint Connection (Proxy)
mediumvia CVE-2023-22518
CVE-2023-22518 Exploitation Attempt - Vulnerable Endpoint Connection (Webserver)
mediumvia CVE-2025-31161
Suspicious CrushFTP Child Process
windows
highvia CVE-2023-34362
Potential MOVEit Transfer CVE-2023-34362 Exploitation - File Activity
windows
highvia CVE-2023-34362
MOVEit CVE-2023-34362 Exploitation Attempt - Potential Web Shell Request
mediumvia CVE-2023-34362
Potential MOVEit Transfer CVE-2023-34362 Exploitation - Dynamic Compilation Via Csc.EXE
windows
🧬 YaraComing soon
🛰️ Infrastructure & IOCs5
ip146.70.134.502025-12-18
urlhttp://185.196.11.207:8000/conqueror.exe2025-12-18
sha256e9fa82d92d826c6a1c38165fe6bd610d3b80cd5d53ec65ac3fe94393be64b5a52025-12-18
ip185.196.11.2072025-12-18
ip147.124.216.2052025-12-18