Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
ransomware-group-operationactively-exploited-vulnerabilityinternet-facing-service-vulnerabilitydata-exfiltration-method

Oracle E-Business Suite Zero-Day Exploited by Clop Ransomware Group

Updated 3mo agoFirst seen Oct 28, 20252 sources

Clop ransomware group exploited a zero-day vulnerability in Oracle E-Business Suite (EBS), tracked as CVE-2025-61882, to compromise major organizations including Schneider Electric, Emerson, Harvard University, and others. The vulnerability allowed unauthenticated remote access to Oracle Concurrent Processing, enabling attackers to exfiltrate large volumes of sensitive data such as ERP records, financial documents, procurement workflows, and engineering files. Clop reportedly maintained access for months, exfiltrating 2.7 terabytes from Emerson and 116 gigabytes from Schneider Electric, with the breach going undetected by traditional monitoring tools.

Security experts warn that the impact extends beyond data theft, as attackers may leverage stolen information for extortion, supply chain exploitation, and credential harvesting. Oracle has released patches for CVE-2025-61882 and strongly urges all EBS customers to apply updates immediately. The campaign highlights the risks posed by trusted vendor dependencies and the potential for widespread disruption across critical infrastructure and operational technology supply chains. Attribution remains under investigation, with both Clop and the financially motivated FIN11 group suspected of involvement.

Share:
Oracle E-Business Suite Zero-Day Exploited by Clop Ransomware Group
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

6 events from the most recent confirmed update back to the earliest known activity.

6 EVENTS
Oct 28, 20258mo ago

Clop leak site adds Emerson and Schneider Electric

Emerson and Schneider Electric were reported as additional victims in the Oracle EBS zero-day campaign, with Clop's leak site allegedly listing 2.7 TB of data tied to Emerson and 116 GB tied to Schneider Electric. Their inclusion marked an escalation because both companies are tied to critical infrastructure and operational technology supply chains.

Google links Oracle EBS attacks to possible FIN11 involvement

Google Threat Intelligence Group assessed that FIN11 may be involved in the Oracle EBS attacks, while stopping short of definitive attribution. The suspected link was based on the campaign's overlap with Clop-associated activity and FIN11's history of financially motivated intrusions.

FBI warns about unpatched internet-facing Oracle EBS systems

The FBI Cyber Division issued an urgent warning that unpatched, internet-facing Oracle E-Business Suite instances were at risk from the ongoing exploitation campaign. The warning emphasized the need for immediate remediation.

Oracle releases patches for CVE-2025-61882

Oracle released security patches for the Oracle E-Business Suite zero-day and urged customers to apply them immediately. The fixes were issued in response to active exploitation of the vulnerability.

Clop-linked campaign claims initial Oracle EBS victims

Organizations including Harvard University, Wits University, Envoy Air, Pan American Silver, and Cox Enterprises were identified as possible or confirmed victims in the Oracle EBS exploitation campaign. Some victim data was reportedly already leaked as the campaign expanded.

Oracle EBS zero-day CVE-2025-61882 is actively exploited

Attackers began exploiting the critical Oracle E-Business Suite vulnerability CVE-2025-61882, which allows unauthenticated remote code execution over HTTP against internet-facing EBS systems. The flaw affects Oracle Concurrent Processing and enables compromise, data theft, and extortion.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

26 LINKEDOpen in app
Threat actors
2 linked
Malware
1 linked
Affected products
3 linked
Oracle E-Business SuiteMoveit TransferMoveit Transfer
Organizations
19 linked
Schneider ElectricEnvoy AirOracleFIN11Cl0pAmerican AirlinesPan American SilverProgress SoftwareEmerson Electric Co.Cox CommunicationsCleoHellcatHarvard UniversityBlumiraAmerican Steel CompanyGoogleFexix24FBI Cyber DivisionSuzu Labs
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.