惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

人人都是产品经理
人人都是产品经理
博客园_首页
博客园 - 三生石上(FineUI控件)
V
Visual Studio Blog
Hugging Face - Blog
Hugging Face - Blog
美团技术团队
小众软件
小众软件
T
Tailwind CSS Blog
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
月光博客
月光博客
有赞技术团队
有赞技术团队
WordPress大学
WordPress大学
博客园 - 【当耐特】
Apple Machine Learning Research
Apple Machine Learning Research
罗磊的独立博客
V
V2EX
酷 壳 – CoolShell
酷 壳 – CoolShell
IT之家
IT之家
量子位
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
Recent Announcements
Recent Announcements
M
MIT News - Artificial intelligence
阮一峰的网络日志
阮一峰的网络日志
The GitHub Blog
The GitHub Blog

Intel 471 Blog

TeamPCP Supply Chain Attacks Turning Geopolitical Tension into Actionable Intelligence CVE-2025-68613: Zerobot botnet exploits critical vulnerability impacting n8n AI orchestration platform Introducing Cyber Threat Exposure Bundle: A Unified Approach to External Risk CVE-2026-20127: Critical Cisco SD-WAN vulnerability exploited in wild Handala Threat Group OpenClaw: A viral AI assistant and a magnet for infostealer malware and ClickFix trickery Israeli, US strikes against Iran triggers a surge in hacktivist activity CVE-2026-1731: Finding a critical RCE in an age of AI-driven vulnerability research Born to bypass MFA: Taking down Tycoon 2FA The UK Cyber Security Resilience Bill How AI and the human advantage beat tomorrow’s threats Winter Olympics 2026: Hacktivism Surges Ahead of Protests and Suspected Sabotage How Threat Hunting and “Good” Metrics Help The Business Likely fake ransomware operator 0APT causes panic — Our analysis Hunting APTs: from state policy to TTPs CrazyHunter Ransomware DevMan Ransomware Introducing HUNTER Tuning: a New Tool for Driving Behavioral Threat Hunt Detections Battling check fraud in the U.S. Gootloader Malware Update Shai-Hulud Worm 2.0 New FvncBot Android banking trojan targets Poland White Paper Preview: Black "Fraud Day” and Beyond — The Key Cyber Threats Facing the Retail Sector this Holiday Season Threat hunting case study: Detecting IAB activity Using deception to extract cyber threat intelligence Lynx Ransomware Qilin Ransomware Group ClickFix: Tricking users into installing infostealers Cybercrime Takedowns: Trust, Partnerships and Focus
Decoding CVE-2023-34362: Unmasking the MOVEit Transfer Vu...
Intel 471 · 2023-06-08 · via Intel 471 Blog

What is CVE-2023-34362?

CVE-2023-34362 is a critical zero-day vulnerability discovered in MOVEit Transfer, a managed file transfer (MFT) software developed by Progress Software. Used widely for secure file transfers, MOVEit Transfer counts approximately 1,700 software companies as users, including the US Department of Homeland Security. This vulnerability is a SQL injection flaw, opening the gates for unauthorized access and manipulation of the database and its content.

Threat Summary

The Lace Tempest group, notorious for ransomware operations and operating the Clop extortion site, has been attributed by Microsoft for exploiting the CVE-2023-34362 vulnerability. The exploitation leads to the deployment of a web shell named "human2.aspx", inserted into the "wwwroot" directory. This web shell is capable of listing all folders, files, and users within MOVEit, downloading any file within the software, and establishing an administrative backdoor user, allowing attackers to maintain persistence. The aftermath of this exploitation has been alarming, with mass exploitation and data exfiltration observed by Mandiant, a leading cybersecurity firm.

Technical Overview

Once the SQL injection vulnerability is successfully exploited, the attackers deploy the web shell "human2.aspx" in the "wwwroot" directory. This web shell is a tool of persistence, helping the attackers maintain access and evade detection by inserting an administrative backdoor user and adding a new admin user account session named "Health Check Service." Various malicious actions can be executed based on the value of the 'X-siLock-Step1', 'X-siLock-Step1', and 'X-siLock-Step3' network request headers.

The exploitation has resulted in significant data exfiltration, indicating widespread attacks. The attackers managed to exploit the vulnerability even before Progress Software could release patches, making it essential for impacted organizations to thoroughly review their environments for any indicators of compromise.

Given the risk, it is strongly advised that organizations using MOVEit Transfer take immediate mitigation measures, including installing patches, monitoring for signs of exploitation, and conducting thorough investigations. This includes checking for the presence of the "human2.aspx" web shell, unusual outbound network transfers, and the unauthorized "Health Check Service" user account.

To arm yourself against such a threat and to leverage the power of knowledge, why not consider getting the free hunting content for this vulnerability? Our dedicated detection engineering and research teams at Cyborg Security are actively developing Hunt Packages to aid in the detection of this threat. Sign up for a free account here, and gain access to hunting content for this vulnerability, along with other insightful resources. Stay a step ahead in your cybersecurity journey.

GET THE FREE HUNT PACKAGES!

CHECK OUT OTHER EMERGING THREATS >