Cybersecurity experts are sounding the alarm about a dramatic increase in malicious scanning activity targeting Progress MOVEit Transfer systems, indicating potential preparation for large-scale cyberattacks.
## Sharp Increase in Scanning Activity
Threat intelligence firm GreyNoise has detected a significant spike in scanning attempts beginning May 27, 2025. The numbers tell a concerning story:
– **Before May 27**: Fewer than 10 scanning IPs detected daily
– **May 27**: Over 100 unique IP addresses
– **May 28**: 319 IP addresses
– **Current levels**: 200-300 IPs daily
Over the past 90 days, researchers have identified 682 unique IP addresses involved in this activity, with 449 observed in just the last 24 hours. Of these recent addresses, 344 are classified as suspicious and 77 as malicious.
## Global Threat Landscape
The scanning activity originates from multiple countries, with the highest concentration in:
– United States (majority)
– Germany
– Japan
– Singapore
– Brazil
– Netherlands
– South Korea
– Hong Kong
– Indonesia
## Active Exploitation Attempts
On June 12, 2025, GreyNoise detected actual exploitation attempts targeting two known MOVEit vulnerabilities:
– **CVE-2023-34362**: Previously exploited by Cl0p ransomware group in 2023, affecting over 2,770 organizations
– **CVE-2023-36934**: Another critical security flaw
## Why MOVEit is a Prime Target
MOVEit Transfer is a widely-used managed file transfer solution employed by businesses and government agencies to securely share sensitive data. Its popularity and access to high-value information make it an attractive target for cybercriminals.
## Essential Security Measures
Organizations using MOVEit Transfer should immediately:
1. **Block malicious IP addresses** identified in threat intelligence reports
2. **Update software** to the latest security patches
3. **Avoid public internet exposure** of MOVEit instances
4. **Monitor systems** for unusual activity
The surge in scanning activity suggests cybercriminals are actively searching for vulnerable MOVEit installations, making immediate protective action critical for organizations using this platform.
