Offsec
- Cobalt Strike
- PowerShell Empire
- TinyMet
Cl0p is a ransomware and data-extortion operation active since 2019 and commonly associated with the TA505/FIN11 ecosystem, also tracked under names including Graceful Spider, Chubby Scorpius, and Lace Tempest.
Profile source: Mallory opens in a new tabClop
Cl0p is a ransomware and data-extortion operation active since 2019 and commonly associated with the TA505/FIN11 ecosystem, also tracked under names including Graceful Spider, Chubby Scorpius, and Lace Tempest. It has operated in a ransomware-as-a-service model and is notable for repeatedly exploiting high-value public-facing enterprise applications rather than relying solely on conventional malware delivery. Cl0p has targeted organizations across multiple sectors, including banking, healthcare, finance, manufacturing, automotive, aerospace, retail, and other enterprises that store sensitive operational or intellectual-property data.
Cl0p is known for both encryption-based ransomware activity and theft-led extortion. In multiple major campaigns it favored large-scale data theft and double extortion, threatening public release of stolen information even when encryption was absent or secondary. The group has been linked to exploitation of managed file transfer and enterprise application vulnerabilities, including Accellion FTA, GoAnywhere MFT, MOVEit Transfer, Oracle E-Business Suite, and in 2026 PTC Windchill and FlexPLM. In the MOVEit campaign, operators exploited CVE-2023-34362, deployed the LEMURLOOT web shell, and exfiltrated data from underlying databases. In the 2026 Windchill/FlexPLM campaign, affiliates reportedly chained a pre-authentication information-disclosure issue with CVE-2026-12569 to achieve unauthenticated remote code execution, deploy JSP web shells, enumerate filesystems, steal engineering and product-design data, and conduct extortion against affected organizations.
Observed intrusion methods attributed to Cl0p include spearphishing, exploitation of public-facing applications, and use of compromised remote access credentials such as RDP. Reported post-compromise behavior includes PowerShell and command-shell execution, web-shell persistence, privilege escalation, process injection, use of Cobalt Strike for command and control, security-tool discovery, and anti-recovery actions such as deleting shadow copies. Cl0p malware has also been reported to avoid installation on systems configured for Russian or other CIS languages and to search for antivirus and antimalware processes. The operation is widely recognized for mass exploitation campaigns against exposed enterprise software and for monetizing access through extortion centered on stolen corporate data.
Reported operators
The infamous Clop ransomware, mainly known as Cl0p, targets various industries and organizations, extorting data for a considerable ransom.
The infamous Clop ransomware, mainly known as Cl0p, targets various industries and organizations, extorting data for a considerable ransom.
Cl0p ransomware affiliates are actively exploiting this vulnerability against manufacturing, automotive, aerospace, and retail organizations.
Cl0p ransomware affiliates are exploiting exposed PTC Windchill and FlexPLM servers to steal engineering and product-design data.
...Watermark ... ShadowSyndicate, CL0P (кампания эксплуатации Cleo)...
the Oracle EBS platform has been under sustained, documented attack by the Cl0p ransomware group and suspected FIN11 operators throughout 2025 and into 2026
Cl0p Ransomware, aka Cl0p, is a ransomware group that emerged in February 2019 and targeted most industries worldwide, including retail, transportation, education, manufacturing, automotive, energy, financial, telecommunications and even healthcare.
Prior to its patching, attackers linked to the Clop ransomware operation were already exploiting CVE-2023-34362 as a zero-day vulnerability.
...observed the group using OpenSSH and Impacket to move laterally and deploy Clop ransomware.
The following analytic identifies the execution of CLOP ransomware variants using specific arguments ("runrun" or "temp.dat") to trigger their malicious activities.
Exploited software
MITRE ATT&CK
Reporting
Cl0p ransomware affiliates are actively exploiting internet-exposed PTC Windchill PDMLink and FlexPLM servers to steal engineering, product-design, and other intellectual-property data from victim organizations. The intrusion chain combines a pre-authentication information disclosure in the FlexPLM WSDL endpoint with CVE-2026-12569, a critical deserialization-based remote code execution flaw affecting vulnerable Windchill and FlexPLM releases before 11.0 M030, allowing unauthenticated compromise. Reporting from Ransom-ISAC, eCrime.ch, and DEFUSED indicates the activity likely began as a zero-day campaign in early June and primarily threatens manufacturers, automotive firms, aerospace organizations, and retail/apparel companies that store sensitive product-development records on these platforms. After gaining access, the attackers reportedly deploy hex-named JSP webshells under the Windchill login path, enumerate files including use of flst.txt, and stage data for theft before launching double-extortion pressure campaigns. Extortion emails observed from July 20 carried the subject line "Windchill PDMLink module serious data leak" and were sent from randomly compromised accounts to large numbers of internal users at affected organizations, increasing pressure before public naming. CISA added CVE-2026-12569 to its Known Exploited Vulnerabilities catalog, while security groups warned that unpatched, internet-facing Windchill and FlexPLM deployments remain the main exposure point.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.