• News/
  • https://www.bleepingcomputer.com/news/security/clop-ransomware-targets-gladinet-centrestack-servers-for-extortion/

Clop ransomware targets Gladinet CentreStack in data theft attacks

BleepingComputer
·
Sergiu Gatlan
·
Published Dec 18, 2025
·
Updated

The Clop ransomware gang (also known as Cl0p) is targeting Internet-exposed Gladinet CentreStack file servers in a new data theft extortion campaign. Gladinet CentreStack enables businesses to securely share files hosted on on-premises file servers through web browsers, mobile apps, and mapped drives without requiring a VPN. According to Gladinet, CentreStack "is used by thousands of businesses from over 49 countries." Since April, Gladinet has released security updates to address several other security flaws that were exploited in attacks, some of them as zero-days. The Clop cybercrime gang is now scanning for and breaching CentreStack servers exposed online, with Curated Intel telling BleepingComputer that ransom notes are left on compromised servers. However, there is currently no information on the vulnerability Clop is exploiting to hack into CentreStack servers. It is unclear whether this is a zero-day flaw or a previously addressed bug that the owners of the hacked systems have yet to patch. "Incident Responders from the Curated Intelligence community have encountered a new CLOP extortion campaign targeting Internet-facing CentreStack file servers," warned threat intel group Curated Intelligence on Thursday. "From recent port scan data, there appears to be at least 200+ unique IPs running the "CentreStack - Login" HTTP Title, making them potential targets of CLOP who is exploiting an unknown CVE (n-day or zero-day) in these systems." Clop has a long history of targeti...

Read full article

Affected Software

1 affected component
Gladinet CentreStack
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is Clop ransomware targeting in this article?

Clop ransomware is targeting Gladinet CentreStack file servers in a data theft extortion campaign.

2

What type of attack is being conducted by the Clop ransomware gang?

The attack involves data theft and extortion from Internet-exposed Gladinet CentreStack servers.

3

Who is affected by the Clop ransomware attacks mentioned?

Businesses using Gladinet CentreStack for secure file sharing are affected by the attacks.

4

What does Gladinet CentreStack provide for its users?

Gladinet CentreStack allows businesses to securely share files hosted on on-premises servers via web browsers, mobile apps, and mapped drives.

5

When was this information about Clop ransomware published?

The article regarding Clop ransomware targeting Gladinet CentreStack was published on December 18, 2025.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203