Notorious Ransomware Group Targets Executives Via Oracle Apps

The new campaign targeting Oracle applications highlights ongoing threats to corporate IT infrastructure

1 min read
[Representational Photo: Getty Images]

Executives at major organizations are facing extortion threats from a notorious ransomware group claiming to have stolen data via Oracle Corp.’s widely used E-Business Suite applications, according to a Google cybersecurity executive and sources familiar with the matter, Bloomberg reports.

The group, believed to be affiliated with the criminal network Cl0p, began sending extortion emails on or before September 29, said Genevieve Stark, head of cybercrime at Google Threat Intelligence Group. The emails, originating from hundreds of compromised third-party accounts, allege that sensitive data has been stolen.

Oracle’s E-Business Suite runs critical business operations, including financial systems, supply chain management, and customer relationship management. While the emails contain sloppy English and grammar, their style is consistent with previous Cl0p campaigns. At least one of the email addresses used had been linked to Cl0p affiliates, and the messages included contact details listed on the group’s own website.

Alphabet Inc.’s Google said it does not yet have sufficient evidence to verify the extortion claims. The sources did not disclose which organizations were targeted or whether any victims had paid ransom demands. Oracle did not respond to requests for comment.

Cl0p is notorious for deploying sophisticated malware to lock company files and demand ransom payments. In 2023, the group exploited vulnerabilities in MOVEit, a file-transfer software used to transmit sensitive data, claiming to have obtained information from hundreds of organizations, including Shell Plc, British Airways, and the British Broadcasting Corp.

In June 2023, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) issued a warning about Cl0p, describing it as “one of the largest phishing and malspam distributors worldwide” and estimating that it had compromised more than 3,000 organizations in the U.S. and 8,000 globally.

The new campaign targeting Oracle applications highlights ongoing threats to corporate IT infrastructure and underscores the continuing sophistication of ransomware groups in targeting high-value enterprises.

Sri Lanka Guardian

The Sri Lanka Guardian is an online web portal founded in August 2007 by a group of concerned Sri Lankan citizens including journalists, activists, academics and retired civil servants. We are independent and non-profit. Email: editor@slguardian.org

Latest from Blog