Skip to content

Clop

Cl0p is a ransomware and data-extortion operation active since 2019 and commonly associated with the TA505/FIN11 ecosystem, also tracked under names including Graceful Spider, Chubby Scorpius, and Lace Tempest.

Profile source: Mallory opens in a new tab

Clop

Family profile

Cl0p is a ransomware and data-extortion operation active since 2019 and commonly associated with the TA505/FIN11 ecosystem, also tracked under names including Graceful Spider, Chubby Scorpius, and Lace Tempest. It has operated in a ransomware-as-a-service model and is notable for repeatedly exploiting high-value public-facing enterprise applications rather than relying solely on conventional malware delivery. Cl0p has targeted organizations across multiple sectors, including banking, healthcare, finance, manufacturing, automotive, aerospace, retail, and other enterprises that store sensitive operational or intellectual-property data.

Cl0p is known for both encryption-based ransomware activity and theft-led extortion. In multiple major campaigns it favored large-scale data theft and double extortion, threatening public release of stolen information even when encryption was absent or secondary. The group has been linked to exploitation of managed file transfer and enterprise application vulnerabilities, including Accellion FTA, GoAnywhere MFT, MOVEit Transfer, Oracle E-Business Suite, and in 2026 PTC Windchill and FlexPLM. In the MOVEit campaign, operators exploited CVE-2023-34362, deployed the LEMURLOOT web shell, and exfiltrated data from underlying databases. In the 2026 Windchill/FlexPLM campaign, affiliates reportedly chained a pre-authentication information-disclosure issue with CVE-2026-12569 to achieve unauthenticated remote code execution, deploy JSP web shells, enumerate filesystems, steal engineering and product-design data, and conduct extortion against affected organizations.

Observed intrusion methods attributed to Cl0p include spearphishing, exploitation of public-facing applications, and use of compromised remote access credentials such as RDP. Reported post-compromise behavior includes PowerShell and command-shell execution, web-shell persistence, privilege escalation, process injection, use of Cobalt Strike for command and control, security-tool discovery, and anti-recovery actions such as deleting shadow copies. Cl0p malware has also been reported to avoid installation on systems configured for Russian or other CIS languages and to search for antivirus and antimalware processes. The operation is widely recognized for mass exploitation campaigns against exposed enterprise software and for monetizing access through extortion centered on stolen corporate data.

Capabilities

  • Defense Evasion
  • Exfiltration
  • Extortion
  • Initial Access
  • Persistence
  • Post Exploitation
  • Privilege Escalation
  • Process Injection
  • Reconnaissance

Operational record

1
YARA rules
4
Ransom notes
3
Leak sites
1 available

Offsec

  • Cobalt Strike
  • PowerShell Empire
  • TinyMet

Recent claims

Reported operators

Threat actors

10 named in public reporting
FIN11

The infamous Clop ransomware, mainly known as Cl0p, targets various industries and organizations, extorting data for a considerable ransom.

TA505

The infamous Clop ransomware, mainly known as Cl0p, targets various industries and organizations, extorting data for a considerable ransom.

Cl0p ransomware affiliates

Cl0p ransomware affiliates are actively exploiting this vulnerability against manufacturing, automotive, aerospace, and retail organizations.

Chubby Scorpius

Cl0p ransomware affiliates are exploiting exposed PTC Windchill and FlexPLM servers to steal engineering and product-design data.

ShadowSyndicate

...Watermark ... ShadowSyndicate, CL0P (кампания эксплуатации Cleo)...

UNC5936

the Oracle EBS platform has been under sustained, documented attack by the Cl0p ransomware group and suspected FIN11 operators throughout 2025 and into 2026

UNC2546

Cl0p Ransomware, aka Cl0p, is a ransomware group that emerged in February 2019 and targeted most industries worldwide, including retail, transportation, education, manufacturing, automotive, energy, financial, telecommunications and even healthcare.

Snakefly

Prior to its patching, attackers linked to the Clop ransomware operation were already exploiting CVE-2023-34362 as a zero-day vulnerability.

FIN7

...observed the group using OpenSSH and Impacket to move laterally and deploy Clop ransomware.

Scattered Spider

The following analytic identifies the execution of CLOP ransomware variants using specific arguments ("runrun" or "temp.dat") to trigger their malicious activities.

Exploited software

Vulnerabilities linked to Clop

39 CVEs
CVE-2023-0669 Pre-authentication RCE in Fortra GoAnywhere MFT License Response Servlet CVE-2021-35211 Remote Code Execution in SolarWinds Serv-U via SSH CVE-2023-35036 SQL Injection in Progress MOVEit Transfer CVE-2023-34362 SQL Injection in Progress MOVEit Transfer CVE-2021-27101 SQL Injection in Accellion FTA Host Header Handling CVE-2021-27103 SSRF in Accellion FTA wmProgressstat.html CVE-2021-27102 OS Command Execution in Accellion FTA Local Web Service Call CVE-2021-27104 OS Command Injection in Accellion FTA Admin Endpoints CVE-2026-4681 RCE in PTC Windchill PDMLink and FlexPLM via Deserialization of Untrusted Data CVE-2026-12569 Unauthenticated RCE in PTC Windchill PDMLink and FlexPLM CVE-2025-61884 Unauthenticated Information Disclosure in Oracle E-Business Suite Oracle Configurator Runtime UI CVE-2024-55956 Unauthenticated Command Injection in Cleo Harmony, VLTrader, and LexiCom Autorun Processing CVE-2025-61882 Unauthenticated RCE in Oracle E-Business Suite BI Publisher Integration CVE-2026-46817 Oracle E-Business Suite Oracle Payments File Transmission Unauthenticated Takeover CVE-2026-35273 Unauthenticated RCE in Oracle PeopleSoft Enterprise PeopleTools Updates Environment Management CVE-2023-27350 PaperCut MF/NG Authentication Bypass and RCE CVE-2023-27351 Authentication Bypass in PaperCut NG/MF SecurityRequestFilter CVE-2024-50623 Pre-auth RCE via unrestricted file upload/download in Cleo Harmony, VLTrader, and LexiCom CVE-2023-35708 SQL Injection in Progress MOVEit Transfer CVE-2020-1472 ZeroLogon CVE-2025-30406 Gladinet CentreStack/Triofox ASP.NET ViewState Deserialization RCE CVE-2025-11371 Unauthenticated Local File Inclusion in Gladinet CentreStack and Triofox CVE-2025-14611 Unauthenticated LFI in Gladinet CentreStack and Triofox via Hardcoded AES Keys CVE-2025-30746 CSRF in Oracle iStore Shopping Cart CVE-2025-50107 Oracle Universal Work Queue Request Handling Improper Access Control CVE-2025-30745 Oracle MES for Process Manufacturing Device Integration improper access control vulnerability CVE-2022-31199 Netwrix Auditor User Activity Video Recording Remote Code Execution CVE-2023-47246 Path Traversal RCE in SysAid On-Premise CVE-2025-50105 Improper access control in Oracle Universal Work Queue Work Provider Administration CVE-2023-36933 Denial of Service in Progress MOVEit Transfer CVE-2023-41266 Path Traversal Authentication Bypass in Qlik Sense Enterprise for Windows CVE-2023-36934 Unauthenticated SQL Injection in Progress MOVEit Transfer CVE-2025-50071 Improper access control in Oracle Applications Framework Web Utilities CVE-2025-30743 Improper access control in Oracle Lease and Finance Management Internal Operations CVE-2025-50090 Oracle Applications Framework Personalization Improper Access Control Vulnerability CVE-2023-41265 ZeroQlik HTTP Request Tunneling in Qlik Sense Enterprise for Windows CVE-2023-36932 Authenticated SQL Injection in Progress MOVEit Transfer CVE-2025-30739 Oracle CRM Technical Foundation Preferences Unauthorized Data Access and Modification CVE-2025-30744 Improper access control in Oracle Mobile Field Service Multiplatform Sync Errors

MITRE ATT&CK

Clop in ATT&CK

66 distinct techniques

Techniques

66 techniques
T1548.002 Bypass User Account Control T1129 Shared Modules T1070 Indicator Removal T1059.001 PowerShell T1055 Process Injection T1059.003 Windows Command Shell T1546.011 Application Shimming T1068 Exploitation for Privilege Escalation T1566 Phishing T1105 Ingress Tool Transfer T1190 Exploit Public-Facing Application T1505.003 Web Shell T1018 Remote System Discovery T1486 Data Encrypted for Impact T1071 Application Layer Protocol T1041 Exfiltration Over C2 Channel T1537 Transfer Data to Cloud Account T1518.001 Security Software Discovery T1112 Modify Registry T1614.001 System Language Discovery T1083 File and Directory Discovery T1140 Deobfuscate/Decode Files or Information T1497 Virtualization/Sandbox Evasion T1070.004 File Deletion T1057 Process Discovery T1078 Valid Accounts T1657 Financial Theft T1490 Inhibit System Recovery T1489 Service Stop T1074 Data Staged T1133 External Remote Services T1485 Data Destruction T1566.003 Spearphishing via Service T1560 Archive Collected Data T1553.002 Code Signing T1213 Data from Information Repositories T1562.001 Disable or Modify Tools T1562 Impair Defenses T1567 Exfiltration Over Web Service T1529 System Shutdown/Reboot T1195 Supply Chain Compromise T1210 Exploitation of Remote Services T1135 Network Share Discovery T1021.004 SSH T1027.002 Software Packing T1218.007 Msiexec T1497.003 Time Based Checks T1106 Native API T1567.002 Exfiltration to Cloud Storage T1566.001 Phishing: Spear-phishing attachment T1059 Command and scripting interpreter T1204 User execution T1543.003 Create or modify system process: Windows service T1547 Boot or logon autostart execution T1484.001 Domain Policy modification: Group Policy modification T1574 Hijack execution flow T1036.001 Masquerading: invalid code signature T1055.001 Process injection: DLL injection T1070.001 Indicator removal on host: clear Windows event logs T1202 Indirect command execution T1012 Query registry T1063 Security software discovery T1082 System information discovery T1021.002 Remote services: SMB/Windows admin shares T1570 Lateral tool transfer T1005 Data from local system

Reporting

Research mentioning Clop

Jul 25
The Hacker News

Cl0p Affiliates Target Internet-Exposed PTC Windchill and FlexPLM with Unauthenticated RCE

Cl0p ransomware affiliates are actively exploiting internet-exposed PTC Windchill PDMLink and FlexPLM servers to steal engineering, product-design, and other intellectual-property data from victim organizations. The intrusion chain combines a pre-authentication information disclosure in the FlexPLM WSDL endpoint with CVE-2026-12569, a critical deserialization-based remote code execution flaw affecting vulnerable Windchill and FlexPLM releases before 11.0 M030, allowing unauthenticated compromise. Reporting from Ransom-ISAC, eCrime.ch, and DEFUSED indicates the activity likely began as a zero-day campaign in early June and primarily threatens manufacturers, automotive firms, aerospace organizations, and retail/apparel companies that store sensitive product-development records on these platforms. After gaining access, the attackers reportedly deploy hex-named JSP webshells under the Windchill login path, enumerate files including use of flst.txt, and stage data for theft before launching double-extortion pressure campaigns. Extortion emails observed from July 20 carried the subject line "Windchill PDMLink module serious data leak" and were sent from randomly compromised accounts to large numbers of internal users at affected organizations, increasing pressure before public naming. CISA added CVE-2026-12569 to its Known Exploited Vulnerabilities catalog, while security groups warned that unpatched, internet-facing Windchill and FlexPLM deployments remain the main exposure point.

Jul 24
Cyber Security News

Cl0p Hackers Exploit Windchill Servers to Steal Companies’ Secret Product Designs

Jul 22
Ransom Isac

Cl0p Exploitation of PTC Windchill & FlexPLM (CVE-2026-12569) | Ransom-ISAC Blog - Ransom-ISAC

Jul 22
Wiz Cloud Threats

Cl0p Exploitation of PTC Windchill and FlexPLM Vulnerability

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.