Skip to content

Clop

Clop, also styled Cl0p, is a ransomware operation associated with ransomware-as-a-service activity and double-extortion campaigns.

Profile source: Mallory opens in a new tab

Clop

Family profile

Clop, also styled Cl0p, is a ransomware operation associated with ransomware-as-a-service activity and double-extortion campaigns. It has conducted large-scale exploitation of internet-facing enterprise file-transfer and business applications, using access obtained through vulnerabilities to steal sensitive data and pressure victims through threatened publication. Lace Tempest has been identified as an affiliate of the Clop ecosystem.

Clop-linked activity has exploited vulnerabilities in PaperCut print-management products for initial access and has been associated with ransomware deployment. The operation has also targeted managed file-transfer products and enterprise product-lifecycle-management platforms. In a 2026 campaign targeting vulnerable PTC Windchill and FlexPLM deployments, Clop-linked operators used tailored Java web shells to access application functionality, decrypt stored credentials, enumerate file repositories and engineering-data vaults, retrieve and delete files, execute additional Java code, and steal sensitive corporate data. The affected platforms are widely used in manufacturing, aerospace, defense, automotive, medical technology, retail, and supply-chain environments.

Clop is notable for data-extortion campaigns that may emphasize theft and threatened disclosure even where encryption is not confirmed. Its operations have been linked to theft of technical documentation, engineering data, project records, backups, and other enterprise information, followed by victim naming and leak-site publication threats.

Capabilities

  • Credential Theft
  • Exfiltration
  • Extortion
  • Initial Access
  • Post Exploitation

Operational record

1
YARA rules
5
Ransom notes
3
Leak sites
1 available

Offsec

  • Cobalt Strike
  • PowerShell Empire
  • TinyMet

Recent claims

Reported operators

Threat actors

12 named in public reporting
TA505

Lace Tempest "is known to be an affiliate of the Clop ransomware RaaS affiliate."

FIN11

今回は前回のブログでもご紹介した CL0P ( CLOP )ランサムウェアによるゼロデイ攻撃についてです。

INDRIK SPIDER

Payments to ransomware gangs such as Bitpaymer, DopplePaymer, WastedLocker, and Clop carried a sanction violations risk in 2020... Clop: Disputed but speculated to be associated with Evil Corp.

SectorJ04

Until November 21 when they gained admin rights on an unpatched machine, the attackers moved through UM's network compromising servers left and right until it finally deployed the Clop ransomware payload on 267 Windows systems.

ShadowSyndicate

We found connections between ShadowSyndicate infrastructure and Cl0p/Truebot substantiating previous findings of GroupIB

Cl0p ransomware affiliates

Cl0p ransomware affiliates are actively exploiting this vulnerability against manufacturing, automotive, aerospace, and retail organizations.

Chubby Scorpius

Cl0p ransomware affiliates are exploiting exposed PTC Windchill and FlexPLM servers to steal engineering and product-design data.

UNC5936

the Oracle EBS platform has been under sustained, documented attack by the Cl0p ransomware group and suspected FIN11 operators throughout 2025 and into 2026

UNC2546

Cl0p Ransomware, aka Cl0p, is a ransomware group that emerged in February 2019 and targeted most industries worldwide, including retail, transportation, education, manufacturing, automotive, energy, financial, telecommunications and even healthcare.

Snakefly

Prior to its patching, attackers linked to the Clop ransomware operation were already exploiting CVE-2023-34362 as a zero-day vulnerability.

FIN7

...observed the group using OpenSSH and Impacket to move laterally and deploy Clop ransomware.

Scattered Spider

The following analytic identifies the execution of CLOP ransomware variants using specific arguments ("runrun" or "temp.dat") to trigger their malicious activities.

Exploited software

Vulnerabilities linked to Clop

40 CVEs
CVE-2023-27351 PaperCut NG/MF Authentication Bypass CVE-2023-27350 PaperCut MF/NG SetupCompleted Authentication Bypass RCE CVE-2023-47246 SysAid On-Prem Path Traversal Remote Code Execution CVE-2023-0669 Pre-authentication RCE in Fortra GoAnywhere MFT License Response Servlet CVE-2023-34362 SQL Injection in Progress MOVEit Transfer CVE-2026-12569 Unauthenticated RCE in PTC Windchill PDMlink and FlexPLM CVE-2021-27101 SQL Injection in Accellion FTA Host Header Handling CVE-2024-50623 Pre-auth RCE via unrestricted file upload/download in Cleo Harmony, VLTrader, and LexiCom CVE-2021-27103 SSRF in Accellion FTA wmProgressstat.html CVE-2021-27102 OS Command Execution in Accellion FTA Local Web Service Call CVE-2021-27104 OS Command Execution in Accellion FTA Admin Endpoints CVE-2022-31199 Netwrix Auditor User Activity Video Recording Insecure Deserialization RCE CVE-2019-19781 Shitrix: Citrix ADC and Gateway Directory Traversal CVE-2021-35211 Pre-auth RCE in SolarWinds Serv-U SSH CVE-2023-35036 SQL Injection in Progress MOVEit Transfer CVE-2026-4681 RCE in PTC Windchill PDMLink and FlexPLM via Deserialization of Untrusted Data CVE-2025-61884 Unauthenticated Information Disclosure in Oracle E-Business Suite Oracle Configurator Runtime UI CVE-2024-55956 Unauthenticated Command Injection in Cleo Harmony, VLTrader, and LexiCom Autorun Processing CVE-2025-61882 Unauthenticated Remote Code Execution in Oracle E-Business Suite BI Publisher Integration CVE-2026-46817 Unauthenticated Oracle Payments File Transmission Takeover CVE-2026-35273 Unauthenticated Remote Code Execution in Oracle PeopleSoft PeopleTools Updates Environment Management CVE-2023-35708 SQL Injection in Progress MOVEit Transfer CVE-2020-1472 Zerologon CVE-2025-30406 Gladinet CentreStack and Triofox ASP.NET ViewState Deserialization RCE CVE-2025-11371 Unauthenticated Local File Inclusion in Gladinet CentreStack and Triofox CVE-2025-14611 Unauthenticated LFI in Gladinet CentreStack and Triofox via Hardcoded AES Keys CVE-2025-30746 CSRF in Oracle iStore Shopping Cart CVE-2025-50107 Oracle Universal Work Queue Request Handling Unauthorized Data Access CVE-2025-30745 Oracle MES for Process Manufacturing Device Integration improper access control vulnerability CVE-2025-50105 Improper access control in Oracle Universal Work Queue Work Provider Administration CVE-2023-36933 Denial of Service in Progress MOVEit Transfer CVE-2023-41266 Path Traversal Authentication Bypass in Qlik Sense Enterprise for Windows CVE-2023-36934 Unauthenticated SQL Injection in Progress MOVEit Transfer CVE-2025-50071 Improper access control in Oracle Applications Framework Web Utilities CVE-2025-30743 Improper access control in Oracle Lease and Finance Management Internal Operations CVE-2025-50090 Oracle Applications Framework Personalization Improper Access Control Vulnerability CVE-2023-41265 ZeroQlik HTTP Request Tunneling in Qlik Sense Enterprise for Windows CVE-2023-36932 Authenticated SQL Injection in Progress MOVEit Transfer CVE-2025-30739 Oracle CRM Technical Foundation Preferences Unauthorized Data Access and Modification CVE-2025-30744 Improper access control in Oracle Mobile Field Service Multiplatform Sync Errors

MITRE ATT&CK

Clop in ATT&CK

87 distinct techniques

Techniques

87 techniques
T1041 Exfiltration Over C2 Channel T1190 Exploit Public-Facing Application T1486 Data Encrypted for Impact T1598 Phishing for Information T1657 Financial Theft T1587.004 Exploits T1074 Data Staged T1195 Supply Chain Compromise T1567.003 Exfiltration to Text Storage Sites T1057 Process Discovery T1112 Modify Registry T1518.001 Security Software Discovery T1140 Deobfuscate/Decode Files or Information T1135 Network Share Discovery T1537 Transfer Data to Cloud Account T1059.003 Windows Command Shell T1114 Email Collection T1106 Native API T1083 File and Directory Discovery T1078 Valid Accounts T1553.002 Code Signing T1566 Phishing T1021 Remote Services T1622 Debugger Evasion T1070 Indicator Removal T1567 Exfiltration Over Web Service T1566.001 Spearphishing Attachment T1053.005 Scheduled Task T1070.004 File Deletion T1570 Lateral Tool Transfer T1105 Ingress Tool Transfer T1497.001 System Checks T1027.002 Software Packing T1562 Impair Defenses T1553 Subvert Trust Controls T1027 Obfuscated Files or Information T1059 Command and Scripting Interpreter T1021.001 Remote Desktop Protocol T1087.002 Domain Account T1110 Brute Force T1490 Inhibit System Recovery T1518 Software Discovery T1133 External Remote Services T1489 Service Stop T1033 System Owner/User Discovery T1048 Exfiltration Over Alternative Protocol T1036 Masquerading T1046 Network Service Discovery T1543 Create or Modify System Process T1087 Account Discovery T1555 Credentials from Password Stores T1548.002 Bypass User Account Control T1129 Shared Modules T1059.001 PowerShell T1055 Process Injection T1546.011 Application Shimming T1068 Exploitation for Privilege Escalation T1505.003 Web Shell T1018 Remote System Discovery T1071 Application Layer Protocol T1614.001 System Language Discovery T1497 Virtualization/Sandbox Evasion T1485 Data Destruction T1566.003 Spearphishing via Service T1560 Archive Collected Data T1213 Data from Information Repositories T1562.001 Disable or Modify Tools T1529 System Shutdown/Reboot T1210 Exploitation of Remote Services T1021.004 SSH T1218.007 Msiexec T1497.003 Time Based Checks T1567.002 Exfiltration to Cloud Storage T1204 User execution T1543.003 Create or modify system process: Windows service T1547 Boot or logon autostart execution T1484.001 Domain Policy modification: Group Policy modification T1574 Hijack execution flow T1036.001 Masquerading: invalid code signature T1055.001 Process injection: DLL injection T1070.001 Indicator removal on host: clear Windows event logs T1202 Indirect command execution T1012 Query registry T1063 Security software discovery T1082 System information discovery T1021.002 Remote services: SMB/Windows admin shares T1005 Data from local system

Reporting

Research mentioning Clop

Aug 15
Github Web

GitHub - tjnel/certgraveyard_yara: Automated YARA rule generation from the Cert Central compromised certificate database. · GitHub

A public project called CertGraveyard has expanded efforts to document abused code-signing certificates used to sign malware, building a shared record of certificate abuse and helping defenders trigger revocations with certificate authorities. The project’s creator said the initiative grew out of years of reporting malicious certificates tied to malware such as SolarMarker, and has helped report more than 2,000 certificates, later growing to roughly 2,400 entries in the database. Supporting tooling includes certReport, which automates abuse reports from malware hashes using sources such as VirusTotal and MalwareBazaar, plus an API, downloadable datasets, feeds, hunting queries, and integrations with platforms including MalwareBazaar, UnpacMe, Malcat, MagicSword.io, and WDAC enforcement workflows. The database reflects a broader pattern in which threat actors repeatedly obtain or abuse valid Authenticode certificates to make malware appear trustworthy, reduce Windows warnings, and sustain delivery campaigns. Prior reporting cited SolarMarker cycling through impostor-issued certificates, FakeBat distributing signed MSI and MSIX installers, Netbounce using valid certificates and fake software branding, Dark Caracal signing Bandook variants with legitimate certificates, and Operation Red Signature abusing a stolen vendor certificate in a supply-chain intrusion. CertGraveyard’s operator said certificate authorities often act on external reports within hours, making revocation a practical disruption measure, though the project has also faced operational pressure including a major DDoS attack while handling heavy daily lookup and download volumes from defenders and malware-analysis integrations.

Aug 12
Hookphish

Ransomware Group clop Hits: HONGHE-TECH.COM

The Clop ransomware operation has repeatedly targeted enterprise networks with intrusions that begin with phishing or exploitation of exposed systems, followed by manual lateral movement, credential theft, and domain-wide deployment. Reporting from ANSSI and AhnLab linked earlier campaigns to TA505, describing attacks in which operators used tools such as Cobalt Strike and Mimikatz, encrypted files with .Clop or .CIop extensions, and disrupted business operations at victims including E-Land Group, Software AG, and reportedly Indiabulls Group. Analysts also observed Clop using signed malware components, targeting Active Directory environments, stopping business-critical services before encryption, and in some cases preserving shadow copies depending on the variant. The group increasingly shifted from encryption-only attacks to double extortion and broader data-leak pressure tactics. Clop operators published stolen files on leak sites, demanded multimillion-dollar payments, contacted victims' customers directly to intensify pressure, and were tied to mass data-theft campaigns exploiting managed file transfer flaws such as CVE-2023-0669 in Fortra GoAnywhere MFT, which was linked to theft from about 130 companies. More recent victim listings attributed to Clop include organizations in the U.S., Canada, Peru, China, Taiwan, and Europe across technology, manufacturing, retail, and other sectors, underscoring the group's continued global focus on enterprise-scale ransomware and data-breach operations.

Aug 12
Hookphish

Ransomware Group clop Hits: 9ALTITUDES.COM

Aug 12
Hookphish

Ransomware Group clop Hits: WATERLANDPE.COM

Aug 12
Hookphish

Ransomware Group clop Hits: NETPOWER.COM

Aug 12
Hookphish

Ransomware Group clop Hits: ALDOGROUP.COM (ALDOSHOES.COM)

Aug 12
Hookphish

Ransomware Group clop Hits: IRCO.COM

Aug 12
Hookphish

Ransomware Group clop Hits: LARGAN.COM.TW

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.