RansomwareCybereason Blog·10 months ago
Addressing CL0P Extortion Campaign Targeting Oracle EBS CVE-2025-61882
The CL0P ransomware group has conducted a widespread extortion campaign targeting on-premises Oracle E-Business Suite deployments, exploiting CVE-2025-61882—a critical, unauthenticated remote code execution vulnerability—to gain unauthorized access and exfiltrate data between July and September 2025. Beginning in late September through early October, CL0P launched coordinated email extortion threats against affected organizations, with evidence suggesting threat actor activity dating back to at least August 9, 2025, and the group providing proof of stolen data to some targets during ongoing investigations.