← Back to Feed

Addressing CL0P Extortion Campaign Targeting Oracle EBS CVE-2025-61882

CVE-2025-61882

October 5, 2025 · Cybereason · Severity: HIGH

Cybereason is investigating an ongoing extortion campaign orchestrated by the CL0P ransomware group targeting vulnerabilities in Oracle E-Business Suite (EBS). The campaign began in late July 2025, shortly after Oracle released security updates that included patches for nine vulnerabilities in EBS. CL0P exploited a specific vulnerability, CVE-2025-61882, which allowed remote code execution without authentication, enabling unauthorized access to on-premise, customer-managed EBS systems. The group exfiltrated data and launched email extortion campaigns starting in late September, demanding contact to prevent public exposure of the stolen data. Oracle confirmed the vulnerability on October 5, 2025, and Cybereason identified the earliest evidence of threat actor activity on August 9, though investigations are ongoing. The campaign primarily affects organizations using on-premise Oracle E-Business Suite solutions, particularly those that failed to apply the July 2025 security patches. CL0P has not disclosed new victims as of October 4, but has provided proof of data exfiltration to some targets. The exploitation of CVE-2025-61882 highlights the critical importance of timely patch management, as the vulnerability allows attackers to execute remote code without credentials. This incident underscores the growing sophistication of ransomware groups and the potential for widespread disruption to businesses reliant on Oracle EBS. Organizations are urged to apply patches immediately and monitor for signs of compromise to mitigate risks associated with this campaign.

Cybereason is continuing to investigate. Check the Cybereason blog for additional updates. 
 
Last update: Oct 7, 11am EST
 
 

Overview and What Cybereason Knows So Far

  • July 2025, Oracle releases security updates including 309 patches, which included nine that addressed flaws/vulnerabilities in Oracle E-Business Suite (EBS).
  • July 2025 (end of) through September 2025 (beginning of), Cybereason has assessed based on emerging evidence and ongoing forensic investigations, that CL0P orchestrated an Intrusion Path that allowed for unauthorized access to on-premise, customer-managed Oracle E-Business Suite (EBS) solutions, enumerated accessible and stored data, and conducted data exfiltration.
  • September 2025 (end of) through October 2025 (beginning of), a widespread orchestrated email extortion campaigns emerged targeting users of on-premise, customer-managed Oracle E-Business Suite (EBS) and requesting contact with CL0P in order to not expose data allegedly exfiltrated.
  • October 2025 (beginning of), Cybereason is aware of ongoing investigations in which CL0P has provided proof of data. CL0P does not appear to have named new victims associated with this incident as of October 4, 2025.
  • October 5, 2025, Oracle confirms CVE-2025-61882 in Oracle E-Business Suite (EBS). This vulnerability was remotely exploitable without authentication (i.e., it can be exploited over a network without the need for a username and password). Successful exploitation can lead to remote code execution (RCE).
  • October 7, 2025, Cybereason confirms earliest evidence of threat actor activity occurred August 9, but is subject to change based on ongoing investigations. 

Key Takeaways

  • Addressing CL0P Extortion Campaign Targeting Oracle EBS CVE- — HIGH severity involving CVE-2025-61882
  • Security advisory with actionable remediation guidance
  • Apply vendor patches and monitor for exploitation activity
☕ Buy a Coffee