Genea, Cleo and Aon: Aon Ransomware Attack Analysis: Termite Group Exploits CVE-2024-50623 in Cleo Software

Genea, Cleo and Aon: Aon Ransomware Attack Analysis: Termite Group Exploits CVE-2024-50623 in Cleo Software

Aon Hit by Termite Ransomware Attack Exploiting Cleo Software Vulnerability

On October 7, 2026, global professional services firm Aon was publicly identified as the victim of a ransomware attack attributed to the Termite group. The breach, discovered the same day, originated on October 6, 2026, with initial access gained through a critical vulnerability in Cleo file transfer products (LexiCom, VLTransfer, and Harmony).

The attack exploited CVE-2024-50623, an unauthenticated remote code execution (RCE) flaw in Cleo software. Notably, even systems patched to version 5.8.0.21 remained vulnerable, suggesting the group employed sophisticated bypass techniques. Once inside Aon’s network, Termite ransomware conducted lateral movement via Windows APIs (e.g., WNetOpenEnum, WNetEnumResourcesW), encrypting both local and remote drives while deleting shadow copies (vssadmin.exe) and disabling security services to hinder recovery.

The malware, identified by its SHA256 hash (30a8cf3e6863030c762b468bf48d679f3dd053a80793770443938fa18de89617), deployed ransom notes in multiple formats (.txt, .html, .hta) across affected directories. Termite’s tactics align with MITRE ATT&CK techniques, including Exploit Public-Facing Application (T1190), Inhibit System Recovery (T1490), and Data Encrypted for Impact (T1486).

Termite has a history of targeting high-value sectors, including supply chain, healthcare, and professional services, with prior victims such as Blue Yonder (supply chain) and Genea (healthcare, Australia). As a firm handling sensitive client data, insurance policies, and financial records, Aon’s breach raises concerns over data exposure, regulatory repercussions, and operational disruption.

At the time of reporting, no official statement from Aon or law enforcement had been released, and the specific data compromised remains undisclosed. The incident underscores the persistent threat posed by ransomware groups exploiting third-party software vulnerabilities in critical infrastructure. Organizations using Cleo products are advised to review patch status and implement compensating controls, such as network segmentation and EDR monitoring, to mitigate similar risks.

Source: https://www.rescana.com/post/aon-ransomware-attack-analysis-termite-group-exploits-cve-2024-50623-in-cleo-software

Genea TPRM report: https://www.rankiteo.com/company/getgenea

Cleo TPRM report: https://www.rankiteo.com/company/cleo-communications

Aon TPRM report: https://www.rankiteo.com/company/aon

"id": "clegetaon1791376186",
"linkid": "cleo-communications, getgenea, aon",
"type": "Ransomware",
"date": "10/2026",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'industry': 'professional services',
                        'location': 'global',
                        'name': 'Aon',
                        'type': 'professional services firm'}],
 'attack_vector': 'Exploit Public-Facing Application (T1190)',
 'data_breach': {'data_encryption': 'Yes',
                 'sensitivity_of_data': 'sensitive client data, insurance '
                                        'policies, and financial records'},
 'date_detected': '2026-10-07',
 'date_publicly_disclosed': '2026-10-07',
 'description': 'On October 7, 2026, global professional services firm Aon was '
                'publicly identified as the victim of a ransomware attack '
                'attributed to the Termite group. The breach, discovered the '
                'same day, originated on October 6, 2026, with initial access '
                'gained through a critical vulnerability in Cleo file transfer '
                'products (LexiCom, VLTransfer, and Harmony). The attack '
                'exploited CVE-2024-50623, an unauthenticated remote code '
                'execution (RCE) flaw in Cleo software. Termite ransomware '
                'conducted lateral movement via Windows APIs, encrypting both '
                'local and remote drives while deleting shadow copies and '
                'disabling security services to hinder recovery.',
 'impact': {'brand_reputation_impact': 'brand reputation impact',
            'legal_liabilities': 'regulatory repercussions',
            'operational_impact': 'operational disruption'},
 'initial_access_broker': {'entry_point': 'Cleo file transfer products '
                                          '(LexiCom, VLTransfer, and Harmony)'},
 'post_incident_analysis': {'root_causes': 'Exploitation of CVE-2024-50623 in '
                                           'Cleo software, even in patched '
                                           'systems (version 5.8.0.21)'},
 'ransomware': {'data_encryption': 'Yes', 'ransomware_strain': 'Termite'},
 'recommendations': 'Organizations using Cleo products are advised to review '
                    'patch status and implement compensating controls, such as '
                    'network segmentation and EDR monitoring, to mitigate '
                    'similar risks.',
 'threat_actor': 'Termite',
 'title': 'Aon Hit by Termite Ransomware Attack Exploiting Cleo Software '
          'Vulnerability',
 'type': 'ransomware',
 'vulnerability_exploited': 'CVE-2024-50623'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.