{"id":9337,"date":"2025-12-19T10:00:31","date_gmt":"2025-12-19T10:00:31","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/12\/19\/clop-ransomware-group-exploiting-gladinet-centrestack-servers-to-steal-data\/"},"modified":"2025-12-19T10:00:31","modified_gmt":"2025-12-19T10:00:31","slug":"clop-ransomware-group-exploiting-gladinet-centrestack-servers-to-steal-data","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/12\/19\/clop-ransomware-group-exploiting-gladinet-centrestack-servers-to-steal-data\/","title":{"rendered":"Clop Ransomware Group Exploiting Gladinet CentreStack Servers to Steal Data"},"content":{"rendered":"<p>    Clop Ransomware Group Exploiting Gladinet CentreStack Servers to Steal Data<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>The Clop ransomware group has launched a new data extortion campaign targeting Internet-facing Gladinet CentreStack file servers, marking another chapter in the threat actor\u2019s pattern of exploiting file transfer solutions.<\/p>\n<p>The campaign appears to leverage multiple security weaknesses in CentreStack and its sister product Triofox, including recently discovered vulnerabilities that allow attackers to gain unauthorized access to sensitive corporate data.<\/p>\n<p>Recent port scan data suggests that over 200 unique IP addresses are running systems with the \u201cCentreStack \u2013 Login\u201d HTTP title, making them potential targets for the Clop group.<\/p>\n<p>The attackers are exploiting either a <a href=\"https:\/\/cybersecuritynews.com\/apple-critical-zero-day-flaw-patched\/\" target=\"_blank\" rel=\"noreferrer noopener\">zero-day<\/a> or an unknown n-day vulnerability to compromise these systems.<\/p>\n<p>Curated Intelligence analysts <a href=\"https:\/\/www.linkedin.com\/posts\/curatedintelligence_psa-incident-responders-from-the-curated-activity-7407480091133231104-C6hv\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">noted<\/a> that incident responders from their community have encountered this new extortion campaign across multiple organizations, raising concerns about the widespread impact of these attacks.<\/p>\n<p>This <a href=\"https:\/\/cybersecuritynews.com\/smartapesg-campaign-leverages-clickfix-technique\/\" target=\"_blank\" rel=\"noreferrer noopener\">campaign<\/a> follows Clop\u2019s established playbook of targeting file transfer servers. The group has previously compromised platforms such as Oracle EBS, Cleo FTP, MOVEit, CrushFTP, SolarWinds Serv-U, PaperCut, and GoAnywhere.<\/p>\n<p>The focus on CentreStack represents an expansion of their targeting strategy, exploiting systems commonly used by businesses for secure file storage and sharing.<\/p>\n<p>Two critical vulnerabilities have been <a href=\"https:\/\/www.linkedin.com\/posts\/curatedintelligence_psa-incident-responders-from-the-curated-activity-7407480091133231104-C6hv\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">identified<\/a> in the CentreStack and Triofox products. The first, CVE-2025-11371, is an unauthenticated local file inclusion flaw that allows attackers to retrieve the machine key from the application Web.config file.<\/p>\n<p>Using directory traversal techniques, threat actors can access any file on the server by exploiting the vulnerable endpoint at \/storage\/t.dn.<\/p>\n<p>The second vulnerability, CVE-2025-14611, involves hardcoded cryptographic keys in the AES implementation that enable attackers to decrypt access tickets and forge their own.<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-technical-breakdown-of-the-attack-chain\"><strong>Technical Breakdown of the Attack Chain<\/strong><\/h2>\n<p>The exploitation begins when attackers target the CentreStack server through the vulnerable \/storage\/t.dn endpoint.<\/p>\n<p>By manipulating the query parameter with directory traversal sequences, they retrieve the Web.config file containing hardcoded machine keys. A sample request looks like this:-<\/p>\n<pre class=\"wp-block-code\"><code>GET \/storage\/t.dn s=..\\..\\..\\Program+Files+(x86)\\Gladinet+Cloud+Enterprise\\root\\Web.config&amp;sid=1<\/code><\/pre>\n<p>Once the machine key is obtained, attackers perform ViewState deserialization attacks to achieve remote code execution.<\/p>\n<p>The hardcoded cryptographic keys in CVE-2025-14611 further enable them to create persistent access tickets with timestamps set to the year 9999, effectively granting indefinite access to the compromised system.<\/p>\n<p>These techniques allow the Clop group to <a href=\"https:\/\/cybersecuritynews.com\/aws-sns-abused\/\" target=\"_blank\" rel=\"noreferrer noopener\">exfiltrate data<\/a> without authentication, making detection and prevention challenging for affected organizations.<\/p>\n<p>Organizations running CentreStack or Triofox should immediately update to version 16.12.10420.56791 and rotate their machine keys.<\/p>\n<p>Administrators should also review web server logs for suspicious GET requests containing \u201cvghpI7EToZUDIZDdprSubL3mTZ2,\u201d which represents the encrypted path to the Web.config file.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 91%,rgb(169,184,195) 100%)\"><strong>Follow us on\u00a0<a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>,\u00a0<a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>,\u00a0and\u00a0<a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">X<\/a>\u00a0to Get MorWe Instant Updates<\/strong>,\u00a0<strong>Set CSN as a Preferred Source in\u00a0<a href=\"https:\/\/www.google.com\/preferences\/source?q=cybersecuritynews.com\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google<\/a>.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/clop-ransomware-group\/\">Clop Ransomware Group Exploiting Gladinet CentreStack Servers to Steal Data<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Tushar Subhra Dutta<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/clop-ransomware-group\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Clop Ransomware Group Exploiting Gladinet CentreStack Servers to Steal Data The Clop ransomware group has launched a new data extortion campaign targeting Internet-facing Gladinet CentreStack file servers, marking another chapter in the threat actor\u2019s pattern of exploiting file transfer solutions. The campaign appears to leverage multiple security weaknesses in CentreStack and its sister product Triofox, [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,649],"tags":[130],"class_list":["post-9337","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-threats","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/9337"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=9337"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/9337\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=9337"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=9337"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=9337"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}