Skip to content

Clop

Cl0p, also written as Clop, is a ransomware family and the name of an associated Russian-speaking, financially motivated ransomware and data-extortion operation.

Clop

Family profile

Cl0p, also written as Clop, is a ransomware family and the name of an associated Russian-speaking, financially motivated ransomware and data-extortion operation. It has been linked to activity tracked as TA505. Cl0p attacks have combined file encryption with data theft and threats to publish stolen information, while more recent campaigns have emphasized data-theft extortion without deploying an encryptor.

The operation is particularly associated with mass exploitation of vulnerabilities in enterprise managed-file-transfer software. Its campaigns have targeted Accellion FTA, Fortra GoAnywhere MFT, Progress MOVEit Transfer, and Cleo products, as well as enterprise business software such as Oracle E-Business Suite. Documented exploitation includes CVE-2023-0669 in GoAnywhere MFT and CVE-2023-34362 in MOVEit Transfer. These compromises enable theft of sensitive information and can expose data belonging to customers and other downstream organizations.

Cl0p uses a Tor-hosted leak site to identify victims and publish stolen data when payment demands are not met. It has also distributed stolen datasets through torrents, increasing their accessibility and complicating containment. Its campaigns affect organizations across multiple countries and industries, including healthcare, financial services, legal services, manufacturing, and distribution.

Capabilities

  • Exfiltration
  • Extortion
  • Initial Access

Samples

Recent samples

1 sandbox sample in the Derp library, newest 1 shown

Reported operators

Threat actors

13 named in public reporting
ShadowSyndicate

ShadowSyndicate "had been associated with the ALPHV/BlackCat, Cl0p, Royal, Play, Cactus, Nokoyawa, and Quantum ransomware operations."

CL0P

The vulnerability was first reported on February 1, 2023 as being exploited by the Clop ransomware group, which said it had compromised over 100 organizations that use Fortra’s file-transfer technology.

ShinyHunters

Les hackers de ShinyHunters ont récemment compromis l'infrastructure du gang de ransomwares Cl0p.

FIN11

Cl0p is a Russia-speaking ransomware and data-extortion group best known for exploiting zero-day vulnerabilities in enterprise file-transfer and business software.

INDRIK SPIDER

Payments to ransomware gangs such as Bitpaymer, DopplePaymer, WastedLocker, and Clop carried a sanction violations risk in 2020... Clop: Disputed but speculated to be associated with Evil Corp.

SectorJ04

Until November 21 when they gained admin rights on an unpatched machine, the attackers moved through UM's network compromising servers left and right until it finally deployed the Clop ransomware payload on 267 Windows systems.

Cl0p ransomware affiliates

Cl0p ransomware affiliates are actively exploiting this vulnerability against manufacturing, automotive, aerospace, and retail organizations.

Chubby Scorpius

Cl0p ransomware affiliates are exploiting exposed PTC Windchill and FlexPLM servers to steal engineering and product-design data.

UNC5936

the Oracle EBS platform has been under sustained, documented attack by the Cl0p ransomware group and suspected FIN11 operators throughout 2025 and into 2026

UNC2546

Cl0p Ransomware, aka Cl0p, is a ransomware group that emerged in February 2019 and targeted most industries worldwide, including retail, transportation, education, manufacturing, automotive, energy, financial, telecommunications and even healthcare.

Snakefly

Prior to its patching, attackers linked to the Clop ransomware operation were already exploiting CVE-2023-34362 as a zero-day vulnerability.

FIN7

...observed the group using OpenSSH and Impacket to move laterally and deploy Clop ransomware.

Scattered Spider

The following analytic identifies the execution of CLOP ransomware variants using specific arguments ("runrun" or "temp.dat") to trigger their malicious activities.

Exploited software

Vulnerabilities linked to Clop

40 CVEs
CVE-2023-27350 PaperCut MF/NG SetupCompleted Authentication Bypass RCE CVE-2023-0669 Unauthenticated remote code execution in Fortra GoAnywhere MFT CVE-2025-61884 Unauthenticated Information Disclosure in Oracle Configurator Runtime UI CVE-2025-61882 Unauthenticated Remote Code Execution in Oracle E-Business Suite BI Publisher Integration CVE-2023-34362 MOVEit Transfer Unauthenticated SQL Injection CVE-2023-27351 Authentication Bypass in PaperCut NG/MF SecurityRequestFilter CVE-2023-47246 SysAid On-Prem Path Traversal Remote Code Execution CVE-2026-12569 Unauthenticated remote code execution in PTC Windchill PDMlink and FlexPLM CVE-2021-27101 SQL Injection in Accellion File Transfer Appliance CVE-2024-50623 Unrestricted File Upload RCE in Cleo Harmony, VLTrader, and LexiCom CVE-2021-27103 SSRF in Accellion FTA wmProgressstat.html CVE-2021-27102 OS Command Execution in Accellion FTA Local Web Service Call CVE-2021-27104 OS Command Execution in Accellion FTA Admin Endpoints CVE-2022-31199 Netwrix Auditor UAVR Insecure Deserialization RCE CVE-2019-19781 Unauthenticated RCE in Citrix ADC and Gateway (Shitrix) CVE-2021-35211 Pre-auth RCE in SolarWinds Serv-U SSH CVE-2023-35036 SQL Injection in Progress MOVEit Transfer CVE-2026-4681 RCE in PTC Windchill PDMLink and FlexPLM via Deserialization of Untrusted Data CVE-2024-55956 Unauthenticated Command Injection in Cleo Harmony, VLTrader, and LexiCom Autorun Processing CVE-2026-46817 Oracle Payments File Transmission Unauthenticated Takeover CVE-2026-35273 Unauthenticated remote code execution in Oracle PeopleSoft PeopleTools Environment Management Hub CVE-2023-35708 SQL Injection in Progress MOVEit Transfer CVE-2020-1472 Zerologon CVE-2025-30406 Gladinet CentreStack and Triofox ASP.NET ViewState Deserialization RCE CVE-2025-11371 Unauthenticated Local File Inclusion in Gladinet CentreStack and Triofox CVE-2025-14611 Hardcoded AES Keys Unauthenticated LFI in Gladinet CentreStack and Triofox CVE-2025-30746 CSRF in Oracle iStore Shopping Cart CVE-2025-50107 Oracle Universal Work Queue Request Handling Unauthorized Data Access CVE-2025-30745 Oracle MES for Process Manufacturing Device Integration improper access control vulnerability CVE-2025-50105 Improper Authorization in Oracle Universal Work Queue Work Provider Administration CVE-2023-36933 Denial of Service in Progress MOVEit Transfer CVE-2023-41266 Path Traversal Authentication Bypass in Qlik Sense Enterprise for Windows CVE-2023-36934 Unauthenticated SQL Injection in Progress MOVEit Transfer CVE-2025-50071 Improper access control in Oracle Applications Framework Web Utilities CVE-2025-30743 Improper access control in Oracle Lease and Finance Management Internal Operations CVE-2025-50090 Oracle Applications Framework Personalization Improper Access Control Vulnerability CVE-2023-41265 ZeroQlik HTTP Request Tunneling in Qlik Sense Enterprise for Windows CVE-2023-36932 Authenticated SQL Injection in Progress MOVEit Transfer CVE-2025-30739 Oracle CRM Technical Foundation Preferences Unauthorized Data Access and Modification CVE-2025-30744 Improper access control in Oracle Mobile Field Service Multiplatform Sync Errors

MITRE ATT&CK

Clop in ATT&CK

72 distinct techniques

Techniques

72 techniques
T1106 Native API T1490 Inhibit System Recovery T1112 Modify Registry T1140 Deobfuscate/Decode Files or Information T1057 Process Discovery T1027.002 Software Packing T1135 Network Share Discovery T1059.003 Windows Command Shell T1614.001 System Language Discovery T1518.001 Security Software Discovery T1486 Data Encrypted for Impact T1218.007 Msiexec T1685 Disable or Modify Tools T1553.002 Code Signing T1083 File and Directory Discovery T1489 Service Stop T1497.003 Time Based Checks T1190 Exploit Public-Facing Application T1657 Financial Theft T1041 Exfiltration Over C2 Channel T1598 Phishing for Information T1587.004 Exploits T1074 Data Staged T1195 Supply Chain Compromise T1567.003 Exfiltration to Text Storage Sites T1537 Transfer Data to Cloud Account T1114 Email Collection T1078 Valid Accounts T1566 Phishing T1021 Remote Services T1622 Debugger Evasion T1070 Indicator Removal T1567 Exfiltration Over Web Service T1566.001 Spearphishing Attachment T1053.005 Scheduled Task T1070.004 File Deletion T1570 Lateral Tool Transfer T1105 Ingress Tool Transfer T1497.001 System Checks T1553 Subvert Trust Controls T1027 Obfuscated Files or Information T1059 Command and Scripting Interpreter T1021.001 Remote Desktop Protocol T1087.002 Domain Account T1110 Brute Force T1518 Software Discovery T1133 External Remote Services T1033 System Owner/User Discovery T1048 Exfiltration Over Alternative Protocol T1036 Masquerading T1046 Network Service Discovery T1543 Create or Modify System Process T1087 Account Discovery T1555 Credentials from Password Stores T1548.002 Bypass User Account Control T1129 Shared Modules T1059.001 PowerShell T1055 Process Injection T1546.011 Application Shimming T1068 Exploitation for Privilege Escalation T1505.003 Web Shell T1018 Remote System Discovery T1071 Application Layer Protocol T1497 Virtualization/Sandbox Evasion T1485 Data Destruction T1566.003 Spearphishing via Service T1560 Archive Collected Data T1213 Data from Information Repositories T1529 System Shutdown/Reboot T1210 Exploitation of Remote Services T1021.004 SSH T1567.002 Exfiltration to Cloud Storage

Reporting

Research mentioning Clop

Sep 11
Cyber Security News

Harley Davidson Alleged Breach - CL0P Ransomware Adds Motorcycle Maker to the List

The CL0P ransomware operation has added motorcycle manufacturer Harley-Davidson to its public extortion leak site, claiming it compromised the company. The listing was highlighted by the ransomNews threat-monitoring account, but Harley-Davidson and its parent organization have not publicly confirmed an intrusion or data theft. CL0P provided no sample files, screenshots, ransom note, stolen-data archive, or technical indicators to substantiate the claim. The purported initial-access vector, affected business unit, scope and type of data allegedly stolen, and whether ransomware encryption occurred remain unknown; the incident should be treated as unconfirmed pending independent validation or an official disclosure.

Sep 11
Cryptika

Harley-Davidson Alleged Breach - CL0P Ransomware Adds Motorcycle Maker to the List | Cryptika Cybersecurity

Aug 15
Github Web

GitHub - tjnel/certgraveyard_yara: Automated YARA rule generation from the Cert Central compromised certificate database. · GitHub

A public project called CertGraveyard has expanded efforts to document abused code-signing certificates used to sign malware, building a shared record of certificate abuse and helping defenders trigger revocations with certificate authorities. The project’s creator said the initiative grew out of years of reporting malicious certificates tied to malware such as SolarMarker, and has helped report more than 2,000 certificates, later growing to roughly 2,400 entries in the database. Supporting tooling includes certReport, which automates abuse reports from malware hashes using sources such as VirusTotal and MalwareBazaar, plus an API, downloadable datasets, feeds, hunting queries, and integrations with platforms including MalwareBazaar, UnpacMe, Malcat, MagicSword.io, and WDAC enforcement workflows. The database reflects a broader pattern in which threat actors repeatedly obtain or abuse valid Authenticode certificates to make malware appear trustworthy, reduce Windows warnings, and sustain delivery campaigns. Prior reporting cited SolarMarker cycling through impostor-issued certificates, FakeBat distributing signed MSI and MSIX installers, Netbounce using valid certificates and fake software branding, Dark Caracal signing Bandook variants with legitimate certificates, and Operation Red Signature abusing a stolen vendor certificate in a supply-chain intrusion. CertGraveyard’s operator said certificate authorities often act on external reports within hours, making revocation a practical disruption measure, though the project has also faced operational pressure including a major DDoS attack while handling heavy daily lookup and download volumes from defenders and malware-analysis integrations.

Aug 12
Hookphish

Ransomware Group clop Hits: HONGHE-TECH.COM

The Clop ransomware operation has repeatedly targeted enterprise networks with intrusions that begin with phishing or exploitation of exposed systems, followed by manual lateral movement, credential theft, and domain-wide deployment. Reporting from ANSSI and AhnLab linked earlier campaigns to TA505, describing attacks in which operators used tools such as Cobalt Strike and Mimikatz, encrypted files with .Clop or .CIop extensions, and disrupted business operations at victims including E-Land Group, Software AG, and reportedly Indiabulls Group. Analysts also observed Clop using signed malware components, targeting Active Directory environments, stopping business-critical services before encryption, and in some cases preserving shadow copies depending on the variant. The group increasingly shifted from encryption-only attacks to double extortion and broader data-leak pressure tactics. Clop operators published stolen files on leak sites, demanded multimillion-dollar payments, contacted victims' customers directly to intensify pressure, and were tied to mass data-theft campaigns exploiting managed file transfer flaws such as CVE-2023-0669 in Fortra GoAnywhere MFT, which was linked to theft from about 130 companies. More recent victim listings attributed to Clop include organizations in the U.S., Canada, Peru, China, Taiwan, and Europe across technology, manufacturing, retail, and other sectors, underscoring the group's continued global focus on enterprise-scale ransomware and data-breach operations.

Aug 12
Hookphish

Ransomware Group clop Hits: 9ALTITUDES.COM

Aug 12
Hookphish

Ransomware Group clop Hits: WATERLANDPE.COM

Aug 12
Hookphish

Ransomware Group clop Hits: NETPOWER.COM

Aug 12
Hookphish

Ransomware Group clop Hits: ALDOGROUP.COM (ALDOSHOES.COM)