operational Incidents & Breachescritical

Google Threat Intelligence Group and Mandiant document Oracle E-Business Suite zero-day extortion

Thu, Oct 9, 2025, 01:00 PM UTC·Oct 9, 2025· Private Sector (PRIVSEC)

Summary

Bottom line: an extortion campaign linked to the CL0P ecosystem exploited an Oracle E-Business Suite zero-day for mass data theft across dozens of customers. Enterprise resource planning platforms are now a primary mass-exploitation target, not a back-office concern.

Key claims· extracted from reporting

Heuristic extraction, verify against the original report before citing.

Tags· click to alert

Story timeline

4 updates · 91 days
  1. Oct 9, 2025·criticalcurrentGoogle Threat Intelligence Group / Mandiant
    Google Threat Intelligence Group and Mandiant document Oracle E-Business Suite zero-day extortion

Key takeaways

The three things worth remembering from this item.

  1. 1Bottom line: Google Threat Intelligence Group and Mandiant document Oracle E-Business Suite zero-day extortion[1]
  2. 2Cl0p activity is the driver here, and the objective is what should shape your response, not the tool names.[1][2]
  3. 3Defensively, the highest-leverage move is coverage for T1190 · Exploit Public-Facing Application, because it is a behavior class rather than an indicator.[1][2]

Concepts in this story

Each concept opens in layers: plain English, technical, then expert.

Cl0p

Criminal · High tempo

Cl0p is a Criminal linked hacking group. In plain terms, they break into managed file-transfer users, federal and state agencies, financial services and stay there. Their goal is to mass exploitation of file-transfer software for bulk extortion.

Why it matters
Criminal extortion is the most likely intrusion any US organization will actually face, and it now routinely disrupts hospitals, schools and local government.[1][2]
Common misconception
That ransomware is only an encryption problem. Data theft and extortion continue even when backups restore cleanly.
MITRE ATT&CK G1032 Cyber Kill ChainNIST CSF 2.0, Identify, Detect, Respond
Sources for this concept
  1. [1]Cl0p group profile· MITRE ATT&CK G1032
  2. [2]Google Threat Intelligence Group and Mandiant document Oracle E-Business Suite zero-day extortion· Google Threat Intelligence Group / Mandiant· 2025-10-09 13:00Z

T1190 · Exploit Public-Facing Application

Initial Access · used by 13 tracked groups

Exploit Public-Facing Application is how an attacker initial access works in practice. Edge devices and VPN appliances (Ivanti, Fortinet, Citrix, Cisco) exploited within hours of CVE disclosure.

Why it matters
This is a initial access behavior, so blocking it early removes an entire branch of the intrusion rather than one tool.[1][2]
Common misconception
That a technique ID is a detection. ATT&CK describes behavior; coverage still has to be built and tested per environment.
MITRE ATT&CK T1190 Tactic: Initial Access
Sources for this concept
  1. [1]T1190 · Exploit Public-Facing Application· MITRE ATT&CK T1190
  2. [2]Google Threat Intelligence Group and Mandiant document Oracle E-Business Suite zero-day extortion· Google Threat Intelligence Group / Mandiant· 2025-10-09 13:00Z

T1505.003 · Server Software Component: Web Shell

Persistence · used by 5 tracked groups

Server Software Component: Web Shell is how an attacker persistence works in practice. Web shells planted on perimeter devices and Exchange servers for durable re-entry.

Why it matters
This is a persistence behavior, so blocking it early removes an entire branch of the intrusion rather than one tool.[1][2]
Common misconception
That a technique ID is a detection. ATT&CK describes behavior; coverage still has to be built and tested per environment.
MITRE ATT&CK T1505.003 Tactic: Persistence
Sources for this concept
  1. [1]T1505.003 · Server Software Component: Web Shell· MITRE ATT&CK T1505.003
  2. [2]Google Threat Intelligence Group and Mandiant document Oracle E-Business Suite zero-day extortion· Google Threat Intelligence Group / Mandiant· 2025-10-09 13:00Z

T1567.002 · Exfiltration to Cloud Storage

Exfiltration · used by 7 tracked groups

Exfiltration to Cloud Storage is how an attacker exfiltration works in practice. Staged archives trickled out through OneDrive, Dropbox, and similar services.

Why it matters
This is a exfiltration behavior, so blocking it early removes an entire branch of the intrusion rather than one tool.[1][2]
Common misconception
That a technique ID is a detection. ATT&CK describes behavior; coverage still has to be built and tested per environment.
MITRE ATT&CK T1567.002 Tactic: Exfiltration
Sources for this concept
  1. [1]T1567.002 · Exfiltration to Cloud Storage· MITRE ATT&CK T1567.002
  2. [2]Google Threat Intelligence Group and Mandiant document Oracle E-Business Suite zero-day extortion· Google Threat Intelligence Group / Mandiant· 2025-10-09 13:00Z

T1486 · Data Encrypted for Impact

Impact · used by 9 tracked groups

Data Encrypted for Impact is how an attacker impact works in practice. Ransomware encryption paired with extortion leak sites.

Why it matters
This is a impact behavior, so blocking it early removes an entire branch of the intrusion rather than one tool.[1][2]
Common misconception
That a technique ID is a detection. ATT&CK describes behavior; coverage still has to be built and tested per environment.
MITRE ATT&CK T1486 Tactic: Impact
Sources for this concept
  1. [1]T1486 · Data Encrypted for Impact· MITRE ATT&CK T1486
  2. [2]Google Threat Intelligence Group and Mandiant document Oracle E-Business Suite zero-day extortion· Google Threat Intelligence Group / Mandiant· 2025-10-09 13:00Z
Sources for these takeaways
  1. [1]Google Threat Intelligence Group and Mandiant document Oracle E-Business Suite zero-day extortion· Google Threat Intelligence Group / Mandiant· 2025-10-09 13:00Z
  2. [2]Cl0p group profile· MITRE ATT&CK G1032
  3. [3]T1190 · Exploit Public-Facing Application· MITRE ATT&CK T1190

Knowledge check

Five questions. Answers explain the reasoning, not just the result.

Question 1 of 5

Which nexus is Cl0p attributed to in public reporting?

Question 2 of 5

Which sector is a primary target for Cl0p?

Question 3 of 5

Which ATT&CK tactic does T1190 (Exploit Public-Facing Application) belong to?

Question 4 of 5

Which ATT&CK tactic does T1505.003 (Server Software Component: Web Shell) belong to?

Question 5 of 5

Which ATT&CK tactic does T1567.002 (Exfiltration to Cloud Storage) belong to?

Answer all 5 to check.
Estimated mastery
First time on this material.
New · 0/100