LEMURLOOT is a C# ASP.NET web shell purpose-built for compromising Progress MOVEit Transfer managed file transfer applications on Windows servers. It was deployed during the widespread exploitation of the previously unknown SQL injection vulnerability CVE-2023-34362 beginning in May 2023. The campaign was associated with the financially motivated Clop extortion operation and attributed by Mandiant to FIN11, affecting public- and private-sector organizations across multiple industries and countries.
LEMURLOOT imports MOVEit libraries to interact with the application's databases, configuration, users, and stored files. It can enumerate file and folder metadata, retrieve and exfiltrate files, extract Azure Blob Storage configuration and credentials, and use MOVEit's native key-management functionality to decrypt stored files. It can also create and delete privileged application accounts, enabling persistent access that may survive a web-server rebuild if the compromised database remains intact. Operator requests are authenticated through a password supplied in an HTTP header, commands are conveyed through additional headers, and returned data is gzip-compressed. The web shell masquerades as a legitimate MOVEit component and returns an HTTP not-found response to unauthenticated requests to conceal its presence. Its primary operational role is rapid data theft supporting extortion rather than file encryption.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Applied to MOVEit CVE-2023-34362: the SQL injection targeted /moveitisapi/moveitisapi.dll — blocked at WAF. The LEMURLOOT web shell was planted as /human2.aspx — unreachable.
They exploited this vulnerability by installing a webshell known as LEMURLOOT.
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Internet-facing MOVEit Transfer web applications were infected with a web shell named LEMURLOOT, which was then used to steal data from underlying MOVEit Transfer databases.
According to a joint advisory issued by the U.S. Federal Bureau of Investigation (FBI) and the Cybersecurity and Infrastructure Security Agency (CISA), the attackers exploited the vulnerability to install a web shell called Lemurloot (JS.Malscript!g1) on affected systems. This was then used to steal data from underlying databases.
According to a joint advisory issued by the U.S. Federal Bureau of Investigation (FBI) and the Cybersecurity and Infrastructure Security Agency (CISA), the attackers exploited the vulnerability to install a web shell called Lemurloot (JS.Malscript!g1) on affected systems. This was then used to steal data from underlying databases.
Following exploitation of the vulnerability, the threat actors are deploying a newly discovered LEMURLOOT web shell with filenames that masquerade as human.aspx... LEMURLOOT provides functionality tailored to execute on a system running MOVEit Transfer software...
18 distinct techniques documented for this family, organized by ATT&CK tactic.
Lemurloot was designed specifically to target the MOVEit Transfer platform... and can create, insert, or delete a particular user.
Lemurloot was designed specifically to target the MOVEit Transfer platform... and can create, insert, or delete a particular user.
SQL injection attacks allow attackers to ... allow the complete disclosure of all data on the system...
LEMURLOOT can also steal Azure Storage Blob information, including credentials, from the MOVEit Transfer application settings, suggesting that actors exploiting this vulnerability may be stealing files from Azure in cases where victims are storing appliance data in Azure Blob storage.
116 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
16 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
MOVEit Transfer web shell that authenticates operator requests using hardcoded header values, accesses database tables, enumerates folders, downloads stored files, and removes execution traces.
Previously referenced custom backdoor/web shell associated with Clop mass exploitation activity.
Custom web shell previously used by the Clop gang following exploitation of MOVEit Transfer vulnerabilities.
A custom web shell previously deployed by Clop following exploitation of CVE-2023-34362.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.