Historical intelligence backfill. This assessment covers reporting originally published on 2025-10-09 and was added to the RWP archive on 2026-09-07.
CL0P's Oracle EBS emails were the bill — the 0-day had been in the suite since August
GTIG/Mandiant 9 October 2025 — CL0P-brand extortion mail from 29 September. Exploitation of what may be CVE-2025-61882 as early as 9 August, suspicious activity to 10 July. Oracle's 11 October patch is the close, not the start.
Bottom line up front
CONFIRMED 9 October 2025 Mandiant/GTIG — from 29 September a high volume of executive emails claimed CL0P affiliation and theft from Oracle E-Business Suite environments. GTIG: the mail followed months of intrusion. Actor(s) exploited what may be CVE-2025-61882 as a zero-day against EBS customers as early as 9 August 2025, weeks before a patch, with additional suspicious activity dated to 10 July. 11 October Oracle released another patch addressing CVE-2025-61884. GTIG (updated): EBS servers through the 11 October patch are likely no longer vulnerable to known chains. It is currently unclear which exact chains map 1:1 to CVE-2025-61882.
This is ERP data-theft extortion, not ransomware on the shop floor. EBS holds suppliers, payroll, orders. Treat internet-facing EBS like an identity system.
What happened
Quiet access through summer. Loud extortion at month-end. Same CL0P cadence as prior file-transfer mass-extortion waves, new product.
Why it matters
ERP on the internet is still a 2025 problem. The email is late.
What is confirmed vs not
CONFIRMED GTIG campaign timing and 0-day window as they stated.
ASSESSED 61882 as the 0-day — GTIG said “may be.”
UNKNOWN full victim set.
What defenders should do
- Patch through 11 October 2025 EBS alerts; pull EBS off WAN.
- Hunt July–September webshells and unusual concurrent manager jobs.
- Extortion mail is IR, not the first evidence.
RWP assessment
Confidence: High on GTIG's sequence. Do not wait for a CVE number to match the implant before you isolate EBS.
Historical intelligence backfill. This assessment covers reporting originally published on 2025-10-09 and was added to the RWP archive on 2026-09-07.
Sources
- GTIG/Mandiant — Oracle E-Business Suite zero-day extortion
- Oracle — CVE-2025-61884 follow-on patch 11 October 2025 (as updated in GTIG post)
- Oracle — EBS security alerts October 2025 (vendor)