MOVEit Transfer

Progress MOVEit Transfer was compromised through a pre-authentication SQL injection in its web application. Attackers used the injection to access the backend database and to deploy a web shell (the LEMURLOOT human2.aspx family) that enabled further data access and command execution. Because MOVEit is internet-facing and holds transfer data for many organizations, a single campaign exfiltrated data from thousands of downstream victims.

text
MOVEit chain:
- Unauthenticated SQL injection in the MOVEit Transfer web app
- Database access (users, transfer metadata, encrypted secrets)
- Deployment of a web shell for persistence and command execution

Exploitation notes#

  • The entry point is unauthenticated and internet-reachable, which is why it scaled to a supply-chain extortion event.
  • The web-shell stage (human2.aspx) provided durable access and bulk file download from the appliance.
  • Fingerprint MOVEit by its web interface and version markers before engaging; the detail here places the chain in the MFT context.

References#

Cookie Consent

We use cookies to enhance your experience. Learn more