The Cl0p ransomware group has launched a significant extortion campaign targeting organizations using Oracle’s E-Business Suite (EBS). This campaign exploits a critical zero-day vulnerability, CVE-2025-61882, in the EBS’s Business Intelligence Publisher (BI Publisher) Integration component. This flaw allows unauthenticated remote code execution, posing a severe risk to enterprises relying on this software.
Beginning in late September 2025, Cl0p initiated a high-volume email campaign directed at executives across various organizations. These emails claimed successful infiltration of EBS environments and the exfiltration of sensitive business data. The attackers demanded payment to prevent the public release of the stolen information, following a pattern observed in previous Cl0p operations.
Oracle responded by issuing emergency patches on October 4, 2025, to address CVE-2025-61882. The vulnerability affects EBS versions 12.2.3 through 12.2.14. Organizations are urged to apply these patches promptly to mitigate the risk of exploitation.
Cl0p’s exploitation of this vulnerability underscores a broader trend of ransomware groups targeting enterprise applications. In recent years, Cl0p has exploited zero-day vulnerabilities in platforms such as Accellion, MOVEit Transfer, GoAnywhere, and Cleo. This pattern highlights the group’s sophisticated capability to identify and weaponize high-impact security flaws in widely used enterprise software.
Security experts emphasize the critical importance of timely patch management and proactive monitoring. Organizations should implement network monitoring for suspicious activity targeting the BI Publisher Integration component and review access logs for unauthorized administrative actions. The rapid exploitation of vulnerabilities like CVE-2025-61882 demonstrates the need for organizations to maintain current patch levels and adopt defense-in-depth strategies to protect against zero-day exploitation campaigns.
As ransomware groups continue to evolve their tactics, the exploitation of enterprise software vulnerabilities is likely to increase. Organizations must prioritize cybersecurity measures, including regular vulnerability assessments, employee training, and incident response planning, to defend against these sophisticated threats.