The notorious Clop ransomware gang, also tracked as Graceful Spider, has escalated its latest extortion campaign by listing Oracle Corporation on its dark web leak site.
The group claims to have successfully breached the tech giant’s internal systems using a critical zero-day vulnerability in Oracle E-Business Suite (EBS), designated as CVE-2025-61882.
This marks a significant development in supply chain attacks, with Oracle potentially falling victim to a flaw in its own software.
Massive Supply Chain Attack Exploiting CVE-2025-61882
The attack centers on an unauthenticated remote code execution (RCE) vulnerability in Oracle E-Business Suite, a widely deployed enterprise resource planning application used for order management, procurement, and logistics functions.
Clop affiliates began exploiting this critical flaw as early as August 2025, months before Oracle released a security patch in October 2025.
The vulnerability was initially observed in June 2025 but became increasingly active in subsequent months.
The exploit chain specifically targets the OA_HTML/SyncServlet endpoint to bypass authentication, then injects a malicious XSLT template via OA_HTML/RF.jsp to execute arbitrary commands.
This pre-authentication nature allowed attackers to compromise servers without valid credentials, granting them complete control over sensitive ERP data.
| Vulnerability Detail | Technical Specification |
|---|---|
| CVE ID | CVE-2025-61882 |
| Affected Product | Oracle E-Business Suite (Versions 12.2.3 – 12.2.14) |
| Vulnerability Type | Unauthenticated Remote Code Execution (RCE) |
| CVSS Score | 9.8 (Critical) |
| Exploit Vector | Authentication Bypass via SyncServlet & XSLT Injection |
| Patch Status | Patched (October 2025 Security Alert) |
Evidence from Clop’s leak site reveals Oracle Corporation alongside major entities, including MAZDA.COM, HUMANA.COM, and the Washington Post.
The listing of Oracle itself suggests the vendor may have been compromised through its own software vulnerability, potentially exposing internal corporate data.
Victims are reportedly receiving extortion emails from addresses like support@pubstorm[.]com, threatening to release financial and personal records unless ransom demands are met.
THE RAVEN FILE security researchers uncovered 96 distinct IP addresses sharing identical SSL certificate fingerprints with the initial attack infrastructure.
Analysis revealed that 41 subnet IPs used in the current Oracle EBS exploitation were previously used during the 2023 MOVEit vulnerability attacks (CVE-2023-34362), indicating persistent infrastructure reuse.
The geographic distribution shows Germany leading with 16 addresses, followed by Brazil (13) and Panama (12), though the underlying infrastructure relies heavily on Russian-based providers.
With over 1,025 confirmed victims and more than $500 million in extorted funds since 2019, Clop remains one of the most dangerous ransomware operations currently active in the threat landscape.
Find this Story Interesting! Follow us on Google News, LinkedIn and X to Get More Instant Updates