LEMURLOOT is a custom web shell used in the 2023 mass exploitation of Progress MOVEit Transfer, most prominently in operations attributed to the Clop extortion ecosystem, including reporting that links the activity to TA505 and FIN11/Snakefly. It is tailored specifically for compromised MOVEit Transfer servers and was deployed after exploitation of the critical SQL injection vulnerability CVE-2023-34362. The malware was used against internet-facing managed file transfer systems across multiple sectors and geographies, enabling rapid theft of sensitive data from victim environments.
The web shell is implemented for the ASP.NET/MOVEit environment and has been described as a C# web shell. It masqueraded as a legitimate MOVEit component to reduce suspicion and was designed to authenticate operator requests before executing commands. Its functionality focused on post-compromise access to MOVEit data stores and application settings rather than broad interactive administration. Reported capabilities include retrieving records from underlying MOVEit databases, downloading files managed by the platform, extracting Azure storage configuration and credentials from application settings, and creating or deleting a specially named user account to maintain access. Reporting also indicates it could support command execution and persistence on affected systems.
Operationally, LEMURLOOT was deployed immediately after successful exploitation of MOVEit Transfer and in some intrusions was followed by data theft within minutes. The malware supported large-scale exfiltration from compromised file-transfer appliances and associated databases, aligning with Clop’s shift from traditional file encryption toward data theft and extortion. In the MOVEit campaign, victims included enterprises, government entities, healthcare organizations, financial organizations, media organizations, and other large institutions that relied on MOVEit Transfer for external file exchange.
LEMURLOOT is best understood as a purpose-built post-exploitation web shell associated with opportunistic but highly organized mass exploitation of public-facing file transfer infrastructure. Its design reflects a narrow objective: persistent access to MOVEit Transfer instances for efficient enumeration and exfiltration of stored files, database contents, and related configuration data that could expand the scope of theft.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
They exploited this vulnerability by installing a webshell known as LEMURLOOT.
Clop ransomware specifically targets the MOVEIT Transfer vulnerability... The threat actors took advantage of a SQL injection vulnerability present in the web application of MOVEIT Transfer. They exploited this vulnerability by installing a webshell known as LEMURLOOT. | They exploited this vulnerability by installing a webshell known as LEMURLOOT.
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The CL0P group deployed a C# web shell named LEMURLOOT to steal data from MOVEit Transfer databases.
According to a joint advisory issued by the U.S. Federal Bureau of Investigation (FBI) and the Cybersecurity and Infrastructure Security Agency (CISA), the attackers exploited the vulnerability to install a web shell called Lemurloot (JS.Malscript!g1) on affected systems. This was then used to steal data from underlying databases.
According to a joint advisory issued by the U.S. Federal Bureau of Investigation (FBI) and the Cybersecurity and Infrastructure Security Agency (CISA), the attackers exploited the vulnerability to install a web shell called Lemurloot (JS.Malscript!g1) on affected systems. This was then used to steal data from underlying databases.
Following exploitation of the vulnerability, the threat actors are deploying a newly discovered LEMURLOOT web shell with filenames that masquerade as human.aspx... LEMURLOOT provides functionality tailored to execute on a system running MOVEit Transfer software...
16 distinct techniques documented for this family, organized by ATT&CK tactic.
Lemurloot was designed specifically to target the MOVEit Transfer platform... and can create, insert, or delete a particular user.
Lemurloot was designed specifically to target the MOVEit Transfer platform... and can create, insert, or delete a particular user.
SQL injection attacks allow attackers to ... allow the complete disclosure of all data on the system...
LEMURLOOT can also steal Azure Storage Blob information, including credentials, from the MOVEit Transfer application settings, suggesting that actors exploiting this vulnerability may be stealing files from Azure in cases where victims are storing appliance data in Azure Blob storage.
110 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A C# web shell used by the CL0P/TA505 ransomware group to steal data from MOVEit Transfer databases.
A custom web shell deployed on compromised MOVEit Transfer servers to provide persistent access, enable command execution, and support data exfiltration during exploitation of CVE-2023-34362.
A web shell designed specifically to target the MOVEit Transfer platform. It authenticates incoming HTTPS requests via a hard-coded password, downloads files from the MOVEit Transfer database, extracts Azure system settings, retrieves records, and can create, insert, or delete a particular user. It returns stolen data in a comfile format.
Custom ASP.NET web shell deployed after exploiting MOVEit Transfer/Cloud (CVE-2023-34362) to provide persistent access on compromised servers; observed as an .aspx web shell (e.g., 'human2.aspx') with password control via a custom HTTP header.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.