Historical intelligence backfill. This assessment covers reporting originally published on 2025-10-09 and was added to the RWP archive on 2026-09-07.

Daily Top · Vulnerabilities

CL0P's Oracle EBS emails were the bill — the 0-day had been in the suite since August

GTIG/Mandiant 9 October 2025 — CL0P-brand extortion mail from 29 September. Exploitation of what may be CVE-2025-61882 as early as 9 August, suspicious activity to 10 July. Oracle's 11 October patch is the close, not the start.

RWP Ventures · 2026-09-07 · event 2025-08-09 · 1 min read · priority 8.7

Bottom line up front

CONFIRMED 9 October 2025 Mandiant/GTIG — from 29 September a high volume of executive emails claimed CL0P affiliation and theft from Oracle E-Business Suite environments. GTIG: the mail followed months of intrusion. Actor(s) exploited what may be CVE-2025-61882 as a zero-day against EBS customers as early as 9 August 2025, weeks before a patch, with additional suspicious activity dated to 10 July. 11 October Oracle released another patch addressing CVE-2025-61884. GTIG (updated): EBS servers through the 11 October patch are likely no longer vulnerable to known chains. It is currently unclear which exact chains map 1:1 to CVE-2025-61882.

This is ERP data-theft extortion, not ransomware on the shop floor. EBS holds suppliers, payroll, orders. Treat internet-facing EBS like an identity system.

What happened

Quiet access through summer. Loud extortion at month-end. Same CL0P cadence as prior file-transfer mass-extortion waves, new product.

Why it matters

ERP on the internet is still a 2025 problem. The email is late.

What is confirmed vs not

CONFIRMED GTIG campaign timing and 0-day window as they stated.

ASSESSED 61882 as the 0-day — GTIG said “may be.”

UNKNOWN full victim set.

What defenders should do

  1. Patch through 11 October 2025 EBS alerts; pull EBS off WAN.
  2. Hunt July–September webshells and unusual concurrent manager jobs.
  3. Extortion mail is IR, not the first evidence.

RWP assessment

Confidence: High on GTIG's sequence. Do not wait for a CVE number to match the implant before you isolate EBS.

Historical intelligence backfill. This assessment covers reporting originally published on 2025-10-09 and was added to the RWP archive on 2026-09-07.

Sources

  1. GTIG/Mandiant — Oracle E-Business Suite zero-day extortion
  2. Oracle — CVE-2025-61884 follow-on patch 11 October 2025 (as updated in GTIG post)
  3. Oracle — EBS security alerts October 2025 (vendor)