Addressing CL0P Extortion Campaign Targeting Oracle EBS CVE-2025-61882
October 5, 2025 · Cybereason · Severity: HIGH
Cybereason is investigating a CL0P ransomware group extortion campaign targeting vulnerabilities in Oracle E-Business Suite (EBS). The campaign exploits CVE-2025-61882, a remotely exploitable vulnerability that allows unauthorized access and remote code execution without authentication. Oracle released patches for this and other vulnerabilities in July 2025, but CL0P leveraged the flaw to infiltrate on-premise, customer-managed EBS systems, enumerate data, and conduct exfiltration from late July through early September 2025. By late September, CL0P launched email extortion campaigns targeting EBS users, demanding contact to avoid public exposure of stolen data. The campaign has raised significant concerns due to the widespread use of Oracle EBS in enterprise environments and the severity of the vulnerability. Cybereason’s ongoing forensic investigations indicate that CL0P began exploiting the vulnerability as early as August 9, 2025, though this timeline may evolve. Oracle confirmed CVE-2025-61882 on October 5, 2025, emphasizing its critical nature. As of October 4, CL0P has not publicly named new victims, but the group has provided proof of data exfiltration to some targets. This incident underscores the importance of timely patching and heightened vigilance against ransomware threats targeting enterprise software.
Overview and What Cybereason Knows So Far
- July 2025, Oracle releases security updates including 309 patches, which included nine that addressed flaws/vulnerabilities in Oracle E-Business Suite (EBS).
- July 2025 (end of) through September 2025 (beginning of), Cybereason has assessed based on emerging evidence and ongoing forensic investigations, that CL0P orchestrated an Intrusion Path that allowed for unauthorized access to on-premise, customer-managed Oracle E-Business Suite (EBS) solutions, enumerated accessible and stored data, and conducted data exfiltration.
- September 2025 (end of) through October 2025 (beginning of), a widespread orchestrated email extortion campaigns emerged targeting users of on-premise, customer-managed Oracle E-Business Suite (EBS) and requesting contact with CL0P in order to not expose data allegedly exfiltrated.
- October 2025 (beginning of), Cybereason is aware of ongoing investigations in which CL0P has provided proof of data. CL0P does not appear to have named new victims associated with this incident as of October 4, 2025.
- October 5, 2025, Oracle confirms CVE-2025-61882 in Oracle E-Business Suite (EBS). This vulnerability was remotely exploitable without authentication (i.e., it can be exploited over a network without the need for a username and password). Successful exploitation can lead to remote code execution (RCE).
- October 7, 2025, Cybereason confirms earliest evidence of threat actor activity occurred August 9, but is subject to change based on ongoing investigations.
Key Takeaways
- Check the Cybereason blog for additional updates. Cybereason is continuing to investigate.
- Last update: Oct 7, 11am EST Overview and What Cybereason Knows So Far July 2025, Oracle releases security updates including 309 patches, which inclu.