---
title: "Threat Intel Content Update: 12/23/24"
description: Tidal Cyber's threat intelligence content updates for the week of 12/23/24 Cleo MFT Mass Zero-Day Exploitation, SafePay Ransomware
---

[Threat Intelligence Content Updates ](https://www.tidalcyber.com/threat-updates)

# [Threat Intel Content Update: 12/23/24](https://www.tidalcyber.com/threat-updates/threat-intel-content-updated-12/23/24)

 Written by [Tidal Cyber](https://www.tidalcyber.com/threat-updates/author/tidal-cyber) | Dec 23, 2024 6:43:46 PM

#### Cleo MFT Mass Zero-Day Exploitation, SafePay Ransomware

****Threat Content Highlights****

Threat Profiles, Objects, & Tags

- - “Trending & Emerging Threats” weekly update: **Cleo MFT Mass Zero-Day Exploitation** 
          - Threat Profile updated following initial release last week. Actors continue to perform mass exploitation of zero-day vulnerabilities (CVE-2024-55956 & CVE-2024-50623) in Cleo managed file transfer ("MFT") products.
          - 12/23/2024: Additional Technique and Software Relationships added to the [Cleo Exploits Campaign object](https://app.tidalcyber.com/campaigns/2c957f94-8b61-49b9-b914-74a06f8b91cd?tab=2) based on review of additional threat reporting. FIN11 (Group) and Cobalt Strike (Software) added to the Threat Profile based on [recent indications from Mandiant](https://www.cybersecuritydive.com/news/mandiant-cleo-exploits-october/736042/) that the [Cl0p](https://app.tidalcyber.com/software/5321aa75-924c-47ae-b97a-b36f023abf2a?tab=2) extortion group is linked to this mass exploitation activity.
    - Monthly Threat Profile updates: “Major & Emerging Ransomware & Extortion Threats” and “Tidal Trending Techniques”  
        
          - New content added for SafePay Ransomware, a newcomer to the trending ransomware profile. The group ranked fourth in terms of claimed victims last month (32) and has [been seen](https://www.huntress.com/blog/its-not-safe-to-pay-safepay) using [various legitimate tools](https://app.tidalcyber.com/tags/t/e1af18e3-3224-4e4c-9d0f-533768474508) ahead of its main objective of encrypting victim systems.

[View full post](https://www.tidalcyber.com/threat-updates/threat-intel-content-updated-12/23/24)

```json
{
  "@context" : "http://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "Tidal Cyber"
  },
  "dateModified" : "2024-12-23T18:43:46.447Z",
  "datePublished" : "2024-12-23T18:43:46Z",
  "headline" : "Threat Intel Content Update: 12/23/24",
  "image" : {
    "@type" : "ImageObject",
    "height" : 500,
    "url" : "https://21164103.fs1.hubspotusercontent-na1.net/hubfs/21164103/Threat%20Intelligence%20Content%20Update%20Social.jpg",
    "width" : 900
  },
  "mainEntityOfPage" : "https://www.tidalcyber.com/threat-updates/threat-intel-content-updated-12/23/24",
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "height" : 60,
      "url" : "/hs/hsstatic/content_shared_assets/static-1.4092/img/default-amp-logo.png",
      "width" : 60
    },
    "name" : "Threat Intelligence Content Updates"
  }
}
```