Progress MOVEit Transfer was compromised through a pre-authentication SQL injection in its web application. Attackers used the injection to access the backend database and to deploy a web shell (the LEMURLOOT human2.aspx family) that enabled further data access and command execution. Because MOVEit is internet-facing and holds transfer data for many organizations, a single campaign exfiltrated data from thousands of downstream victims.
MOVEit chain:
- Unauthenticated SQL injection in the MOVEit Transfer web app
- Database access (users, transfer metadata, encrypted secrets)
- Deployment of a web shell for persistence and command execution
Exploitation notes#
- The entry point is unauthenticated and internet-reachable, which is why it scaled to a supply-chain extortion event.
- The web-shell stage (human2.aspx) provided durable access and bulk file download from the appliance.
- Fingerprint MOVEit by its web interface and version markers before engaging; the detail here places the chain in the MFT context.