{
  "type": "bundle",
  "id": "bundle--0f5fdf73-630f-58cb-8377-25145b705eb4",
  "objects": [
    {
      "type": "identity",
      "spec_version": "2.1",
      "id": "identity--4d2a86e8-cdc5-52ec-8a68-5c16cbbcdeaf",
      "created": "2026-09-18T12:00:00Z",
      "modified": "2026-09-18T12:00:00Z",
      "x_ally_original_id": "org:5f790b37-9134-5b79-a0f0-10652abab82a",
      "name": "Progress Software",
      "identity_class": "organization"
    },
    {
      "type": "incident",
      "spec_version": "2.1",
      "id": "incident--449bae65-5d2f-505b-8624-34708ef20395",
      "created": "2026-09-18T12:00:00Z",
      "modified": "2026-09-18T12:00:00Z",
      "x_ally_original_id": "brh:1da20ac8-0461-5f70-b424-5c50e9e3c2e1",
      "name": "MOVEit Transfer mass-exploitation campaign"
    },
    {
      "type": "incident",
      "spec_version": "2.1",
      "id": "incident--dda97bdf-3295-5509-8fe5-fdce8529de5b",
      "created": "2026-09-18T12:00:00Z",
      "modified": "2026-09-18T12:00:00Z",
      "x_ally_original_id": "inc:d4e06b52-01bd-54eb-bb8a-4dca0af3545c",
      "name": "MOVEit Transfer mass-exploitation campaign"
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--37dbcf5a-f290-5067-80f3-f847f3737d0e",
      "created": "2026-09-18T12:00:00Z",
      "modified": "2026-09-18T12:00:00Z",
      "x_ally_original_id": "clm:7e0e0a06-5cd0-5934-b19b-78fe8ecc9d46",
      "relationship_type": "affected-organization",
      "source_ref": "incident--dda97bdf-3295-5509-8fe5-fdce8529de5b",
      "target_ref": "identity--4d2a86e8-cdc5-52ec-8a68-5c16cbbcdeaf",
      "confidence": 100,
      "external_references": [
        {
          "source_name": "CISA and FBI",
          "url": "https://www.cisa.gov/sites/default/files/2023-06/aa23-158a-stopransomware-cl0p-ransomware-gang-exploits-moveit-vulnerability_0.pdf",
          "external_id": "cit:2ed4d157-29b4-5b1c-a904-a98f5c8854e9",
          "x_ally_stance": "supports",
          "x_ally_snapshot_id": "snp:sha256:a5c37031e414cb73600c62cc70846a4c3a12daa3a8fee1eae4fc44d3ebc29626"
        }
      ]
    },
    {
      "type": "x-ally-claim",
      "spec_version": "2.1",
      "id": "x-ally-claim--2bb769b4-8820-55ea-8fff-6f40ea03e183",
      "created": "2026-09-19T12:00:00Z",
      "modified": "2026-09-19T12:00:00Z",
      "x_ally_original_id": "clm:8542f614-9133-5085-b7db-8fe8539cadc3",
      "confidence": 90,
      "external_references": [
        {
          "source_name": "CISA and FBI",
          "url": "https://www.cisa.gov/sites/default/files/2023-06/aa23-158a-stopransomware-cl0p-ransomware-gang-exploits-moveit-vulnerability_0.pdf",
          "external_id": "cit:80a5ec46-291f-50af-8d2d-5c355aad17e4",
          "description": "In addition, the authoring authorities of this CSA recommend network defenders apply the following mitigations to limit potential adversarial use of common system and network discovery techniques and to reduce the impact and risk of compromise by ransomware or data extortion actors: • Implement a recovery plan to maintain and retain multiple copies of sensitive or proprietary data and servers in a physically separate, segmented, and secure location (i.e., hard drive, storage device, the cloud). • Maintain offline backups of data and regularly maintain backup and restoration (daily or weekly at minimum).",
          "x_ally_stance": "supports",
          "x_ally_snapshot_id": "snp:sha256:a5c37031e414cb73600c62cc70846a4c3a12daa3a8fee1eae4fc44d3ebc29626"
        }
      ],
      "x_ally_claim_object": {
        "kind": "value",
        "datatype": "string",
        "value": "The retained source describes system restoration or operational recovery work."
      }
    },
    {
      "type": "x-ally-claim",
      "spec_version": "2.1",
      "id": "x-ally-claim--a43e81e7-42f3-5399-8961-8f5db62ffd71",
      "created": "2026-09-19T12:00:00Z",
      "modified": "2026-09-19T12:00:00Z",
      "x_ally_original_id": "clm:7d7743d5-b7d8-5b29-b07b-69b60a75a92b",
      "confidence": 95,
      "external_references": [
        {
          "source_name": "CISA and FBI",
          "url": "https://www.cisa.gov/sites/default/files/2023-06/aa23-158a-stopransomware-cl0p-ransomware-gang-exploits-moveit-vulnerability_0.pdf",
          "external_id": "cit:11f9b31a-f33a-5159-97b5-1691c649e097",
          "description": "In May 2023, the CL0P ransomware group exploited a SQL injection zero-day vulnerability CVE-2023-34362 to install a web shell named LEMURLOOT on MOVEit Transfer web applications [T1190] [1].",
          "x_ally_stance": "supports",
          "x_ally_snapshot_id": "snp:sha256:a5c37031e414cb73600c62cc70846a4c3a12daa3a8fee1eae4fc44d3ebc29626"
        }
      ],
      "x_ally_claim_object": {
        "kind": "value",
        "datatype": "string",
        "value": "Cl0p ransomware group; zero-day SQL injection."
      }
    },
    {
      "type": "x-ally-claim",
      "spec_version": "2.1",
      "id": "x-ally-claim--df18dd78-b96d-5a59-8ee1-999dcebf72d7",
      "created": "2026-09-18T12:00:00Z",
      "modified": "2026-09-18T12:00:00Z",
      "x_ally_original_id": "clm:cee9daae-7b68-5a50-89f7-1bed758c1f14",
      "confidence": 100,
      "external_references": [
        {
          "source_name": "CISA and FBI",
          "url": "https://www.cisa.gov/sites/default/files/2023-06/aa23-158a-stopransomware-cl0p-ransomware-gang-exploits-moveit-vulnerability_0.pdf",
          "external_id": "cit:4e3298a3-259e-50cf-8908-c208dfb96e46",
          "x_ally_stance": "supports",
          "x_ally_snapshot_id": "snp:sha256:a5c37031e414cb73600c62cc70846a4c3a12daa3a8fee1eae4fc44d3ebc29626"
        }
      ],
      "x_ally_claim_object": {
        "kind": "value",
        "datatype": "string",
        "value": "The reviewed source documents the moveit transfer mass-exploitation campaign involving Progress Software."
      }
    },
    {
      "type": "x-ally-claim",
      "spec_version": "2.1",
      "id": "x-ally-claim--e0a87b90-558c-5035-8870-bb409ed0448f",
      "created": "2026-09-19T12:00:00Z",
      "modified": "2026-09-19T12:00:00Z",
      "x_ally_original_id": "clm:b39aacbc-d6c8-5313-b025-3b727cfcb2c4",
      "confidence": 90,
      "external_references": [],
      "x_ally_claim_object": {
        "kind": "iri",
        "value": "https://attack.mitre.org/techniques/T1486/"
      }
    },
    {
      "type": "x-ally-claim",
      "spec_version": "2.1",
      "id": "x-ally-claim--f67e4b3b-030f-5aec-88c1-79f0da92bef8",
      "created": "2026-09-19T12:00:00Z",
      "modified": "2026-09-19T12:00:00Z",
      "x_ally_original_id": "clm:c1253545-58a0-5b19-8ba2-9ccb653e64da",
      "confidence": 90,
      "external_references": [],
      "x_ally_claim_object": {
        "kind": "iri",
        "value": "https://attack.mitre.org/techniques/T1190/"
      }
    }
  ]
}
