
23.07.2026 oracle-ebscl0pzero-dayextortionmass-exploitation
In late September 2025, executives at dozens of organizations suddenly received extortion emails from the Cl0p brand, claiming their Oracle E-Business Suite (EBS) environments had been breached and data stolen. The group had exploited a zero-day vulnerability in Oracle’s E-Business Suite software, and starting in late September 2025, executives at dozens of organizations began receiving extortion emails claiming a breach of their EBS systems. The real forensic shock came only once investigators started reconstructing the timeline. Google and Mandiant’s joint investigation found that exploitation activity dated back to as early as July 2025, possibly linked to what is now tracked as CVE-2025-61882. CVE-2025-61882 was therefore exploited as a zero-day for at least two months before patches became available — a window threat actors actively monitored and exploited.
For incident responders, that means anyone starting an investigation only after the public extortion wave is effectively staring at two-month-old compromise traces — assuming any logs still exist.
Technically, Cl0p’s chain is particularly unfriendly to classic forensics. The attacks exploit a server-side chain using SSRF and CRLF injection to force EBS servers to fetch and execute malicious XSL payloads, achieving remote code execution without disk-based artifacts. That’s a nightmare for post-mortem analysis: without persistent files on disk, investigators are pushed almost entirely toward network logs, HTTP access logs, and volatile memory artifacts — data sources that many on-premise EBS deployments retain neither long enough nor granularly enough.
On top of that, attackers leveraged compromised mailboxes to abuse EBS local-account password-reset flows, bypassing SSO/MFA protections to steal credentials and exfiltrate sensitive data. That shifts the forensic focus: web application logs alone won’t cut it — email gateway logs, password-reset events, and authentication anomalies outside the standard MFA path all need to feed into the timeline. Post-compromise, Cl0p staged data for extortion or deployed ransomware to disrupt operations.
Attribution here is messy. CrowdStrike believes with moderate confidence that a Russia-linked group tracked as Graceful Spider is mass exploiting the vulnerability, a group known to conduct attacks alongside Cl0p. The vulnerability had already been exploited in the wild since at least August 9, 2025, with a proof-of-concept exploit published by the group Scattered LAPSUS$ Hunters. Multiple threat clusters apparently shared the same exploit tooling — a pattern that increasingly complicates forensic attribution.
Legal counsel and incident response teams agree that patching alone is not enough. Organizations that had not implemented the July 2025 patches need to conduct a comprehensive DFIR investigation to identify potential compromise, including evidence of backdoors, webshells, credential manipulation, and data exfiltration tools. Concretely, organizations should verify they’ve applied patches for CVE-2025-61882 and CVE-2025-61884, conduct forensic investigations to determine if they were compromised during the zero-day exploitation window, and prepare incident response plans that account for public disclosure by attackers.
This case illustrates why ERP platforms like EBS are such attractive targets in the first place: Oracle EBS is a widely used enterprise resource planning platform, managing business data like customer records, HR files, and financial information. Organizations running such systems shouldn’t wait for the extortion email to arrive. The right moment to check is now: are July/August logs still retained? Is there any sign of anomalous password-reset activity? And is forensic readiness mature enough to reconstruct a fileless RCE that happened two months in the past?
← Back to overview