{"id":8709,"date":"2025-11-25T10:03:55","date_gmt":"2025-11-25T10:03:55","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/11\/25\/canon-allegedly-breached-by-clop-ransomware-via-oracle-e-business-suite-0-day-hack\/"},"modified":"2025-11-25T10:03:55","modified_gmt":"2025-11-25T10:03:55","slug":"canon-allegedly-breached-by-clop-ransomware-via-oracle-e-business-suite-0-day-hack","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/11\/25\/canon-allegedly-breached-by-clop-ransomware-via-oracle-e-business-suite-0-day-hack\/","title":{"rendered":"Canon Allegedly Breached by Clop Ransomware via Oracle E-Business Suite 0-Day Hack"},"content":{"rendered":"<p>    Canon Allegedly Breached by Clop Ransomware via Oracle E-Business Suite 0-Day Hack<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>Canon has officially confirmed that it was targeted during the widespread hacking campaign exploiting a critical zero-day vulnerability in <a href=\"https:\/\/cybersecuritynews.com\/oracle-e-business-suite-hack\/\" target=\"_blank\" rel=\"noreferrer noopener\">Oracle E-Business Suite (EBS)<\/a>.<\/p>\n<p>The attack, orchestrated by the notorious Clop ransomware gang, has impacted dozens of major organizations worldwide. The group listed Canon on its dark web leak site, publishing the company\u2019s domain alongside other alleged victims.<\/p>\n<p>While the listing on the leak site raised concerns about a massive data breach, Canon clarified that the impact was contained. The camera and imaging giant stated that the compromise affected only a specific environment within one of its subsidiaries.<\/p>\n<p>According to the company, the attackers did not encrypt the broader network or disrupt global operations, which distinguishes this incident from the devastating Maze ransomware attack Canon suffered in 2020.<\/p>\n<p>Canon\u2019s security team detected the intrusion and immediately isolated the affected systems. In a statement shared with SecurityWeek, the company emphasized that the breach did not spread beyond a web server operated by a Canon U.S.A., Inc. subsidiary.<\/p>\n<p>The rapid containment likely prevented the theft of sensitive customer data or intellectual property, which the Clop group often seeks for extortion.\u200b<\/p>\n<p>\u201cWe have confirmed that the incident only affected the web server, and we have already taken security measures and resumed service,\u201d Canon said. \u201cIn addition, we are continuing to investigate further to ensure that there is no other impact\u201d.\u200b<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-the-oracle-ebs-zero-day-exploit\"><strong>The Oracle EBS Zero-Day Exploit<\/strong><\/h2>\n<p>The vulnerability used in this campaign is tracked as <a href=\"https:\/\/cybersecuritynews.com\/oracle-e-business-suite-hack\/\" target=\"_blank\" rel=\"noreferrer noopener\">CVE-2025-61882<\/a>, a critical security flaw in Oracle E-Business Suite. This zero-day allowed unauthenticated attackers to execute arbitrary code remotely on vulnerable servers.<\/p>\n<p>Security researchers discovered that Clop affiliates, tracked as Graceful Spider, began exploiting this flaw as early as August 2025 to plant web shells and exfiltrate data before Oracle could issue a patch in October.\u200b<\/p>\n<figure class=\"wp-block-table\">\n<table class=\"has-fixed-layout\">\n<thead>\n<tr>\n<th>Detail<\/th>\n<th>Description<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td><strong>CVE ID<\/strong><\/td>\n<td>CVE-2025-61882<\/td>\n<\/tr>\n<tr>\n<td><strong>CVSS Score<\/strong><\/td>\n<td>9.8 (Critical)<\/td>\n<\/tr>\n<tr>\n<td><strong>Affected Product<\/strong><\/td>\n<td>Oracle E-Business Suite (EBS)<\/td>\n<\/tr>\n<tr>\n<td><strong>Affected Versions<\/strong><\/td>\n<td>12.2.3 through 12.2.14<\/td>\n<\/tr>\n<tr>\n<td><strong>Vulnerability Type<\/strong><\/td>\n<td>Unauthenticated Remote Code Execution (RCE)<\/td>\n<\/tr>\n<tr>\n<td><strong>Exploit Vector<\/strong><\/td>\n<td>Network (No user interaction required)<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/figure>\n<p>This incident is part of a larger \u201cmove-it-style\u201d extortion wave where Clop leveraged the zero-day to breach nearly 30 organizations. Instead of deploying encryption malware immediately, the group focused on data theft and subsequently sent extortion emails to executives starting in late <a href=\"https:\/\/cybersecuritynews.com\/hackers-targeting-oracle-e-business-suite\/\" target=\"_blank\" rel=\"noreferrer noopener\">September 2025<\/a>.<\/p>\n<p>These emails threatened to leak stolen documents unless a ransom was paid. The group\u2019s leak site currently lists domains, including Canon, suggesting these entities were successfully compromised during the automated exploitation phase.\u200b<\/p>\n<p><strong>Indicators of Compromise (IoCs)<\/strong><\/p>\n<figure class=\"wp-block-table\">\n<table class=\"has-fixed-layout\">\n<thead>\n<tr>\n<th>Indicator Type<\/th>\n<th>Value<\/th>\n<th>Description<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td><strong>IPv4 Address<\/strong><\/td>\n<td>200.107.207.26<\/td>\n<td>Malicious command and control (C2) IP<\/td>\n<\/tr>\n<tr>\n<td><strong>IPv4 Address<\/strong><\/td>\n<td>185.181.60.11<\/td>\n<td>Observed exploitation source IP<\/td>\n<\/tr>\n<tr>\n<td><strong>SHA256 Hash<\/strong><\/td>\n<td>76b6d36e04e367a2334c445b51e1ecce97e4c614e88dfb4f72b104ca0f31235d<\/td>\n<td>Malicious zip archive containing exploit tools<\/td>\n<\/tr>\n<tr>\n<td><strong>SHA256 Hash<\/strong><\/td>\n<td>6fd538e4a8e3493dda6f9fcdc96e814bdd14f3e2ef8aa46f0143bff34b882c1b<\/td>\n<td>Python script used for server-side exploitation<\/td>\n<\/tr>\n<tr>\n<td><strong>File Name<\/strong><\/td>\n<td>FileUtils.java<\/td>\n<td>Malicious web shell downloader<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/figure>\n<p>Security teams are advised to scan their Oracle EBS environments for these indicators and apply the official patches immediately to prevent further unauthorized access.\u200b<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 94%,rgb(169,184,195) 100%)\"><strong>Follow us on <a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>, <a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>, and <a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">X<\/a> for daily cybersecurity updates. <a href=\"https:\/\/cybersecuritynews.com\/contact-us\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Contact us<\/a> to feature your stories.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/canon-breached-clop-ransomware-oracle-ebs-hack\/\">Canon Allegedly Breached by Clop Ransomware via Oracle E-Business Suite 0-Day Hack<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Guru Baran<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/canon-breached-clop-ransomware-oracle-ebs-hack\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Canon Allegedly Breached by Clop Ransomware via Oracle E-Business Suite 0-Day Hack Canon has officially confirmed that it was targeted during the widespread hacking campaign exploiting a critical zero-day vulnerability in Oracle E-Business Suite (EBS). The attack, orchestrated by the notorious Clop ransomware gang, has impacted dozens of major organizations worldwide. The group listed Canon [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[701,1636,129,63],"tags":[130],"class_list":["post-8709","post","type-post","status-publish","format-standard","hentry","category-cyber-attack","category-cyber-attack-news","category-cyber-security","category-cyber-security-news","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/8709"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=8709"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/8709\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=8709"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=8709"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=8709"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}