Cl0p, also known as Clop, is a financially motivated cybercriminal ransomware and data-extortion operation targeting large organizations worldwide. Its operations encompass both double extortion, combining file encryption with threats to publish stolen information, and encryption-less extortion based on stolen data. The group maintains a data-leak site to publicize victims and pressure organizations into payment. Its victims include financial institutions, government agencies, universities, technology companies, energy organizations, transportation businesses, and media organizations, including organizations affected indirectly through compromised service providers. Cl0p specializes in exploiting internet-facing applications that store, process, or transfer sensitive files. Its campaigns have targeted Accellion FTA, SolarWinds Serv-U, GoAnywhere MFT, MOVEit Transfer, PaperCut, SysAid, Cleo managed file transfer products, Oracle E-Business Suite, and Gladinet file-sharing products. Its operations frequently employ zero-day exploitation, extended reconnaissance, automated attacks against numerous organizations, and infrastructure distributed across multiple hosting providers. Several major campaigns have begun during holiday periods. The 2023 GoAnywhere and MOVEit campaigns emphasized data theft and extortion without deploying file-encrypting ransomware. During MOVEit exploitation, Cl0p used CVE-2023-34362 and the LEMURLOOT web shell to access and exfiltrate stored files. Attackers injected privileged application sessions or created malicious accounts to transfer files through the application, and also used native application APIs to retrieve encryption keys and decrypt files directly. These techniques bypassed the protection offered by encryption at rest after application compromise. Cl0p has also used Truebot for information collection and exfiltration. Exploitation of Cleo products deployed the Malichus Java backdoor, which supports data theft, command execution, and lateral movement. Cl0p is associated with the overlapping TA505 and FIN11 cybercrime ecosystem. Some tracking schemes equate Cl0p with TA505, while others distinguish overlapping operational clusters; these names do not consistently represent an identical organizational scope.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
53 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
46 malware families attributed to this actor across reporting.
41 additional families tracked in Mallory.
20 CVEs this actor has used in observed campaigns. 20 of them exploited in the wild.
Clop's campaign exploited a zero-day vulnerability in the MOVEit file transfer software to steal data. Progress first released patches for supported versions of MOVEit on May 31 to fix the exploited flaw, designated CVE-2023-34362.
Tracking under CVE-2026-12569 (CVSS 9.3/9.8), the flaw involved an input validation and untrusted object deserialization failure within product lifecycle management endpoints.
The origins of the hostility trace to autumn 2025 during an extortion campaign centered on an Oracle E-Business Suite (EBS) zero-day vulnerability designated as CVE-2025-61882. Threat intelligence tracking revealed that unpatched enterprise Oracle EBS instances were systematically targeted to exfiltrate critical corporate databases from over one hundred corporations.
The attack was made possible by exploiting a zero-day vulnerability in the Fortra GoAnywhere MFT (Managed File Transfer), first disclosed on February 3, 2023, and now tracked as CVE-2023-0669.
Microsoft was able to identify the involvement of two ransomware gangs (CL0P and LockBit) who were exploiting the tracked CVE-2023-27350 and CVE-2023-27351.
15 more CVEs tied to this actor tracked in Mallory.
1,585 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Clop conducted a financially motivated data-theft and extortion campaign against organizations using MOVEit Transfer, with at least 131 organizations reportedly affected by June 28, 2023. Compromised service providers also exposed their customers' data. Although Clop previously used file-encrypting malware, this campaign appears to have involved data exfiltration only, resembling its earlier GoAnywhere campaign. Clop gradually published victim names to pressure organizations into contacting it and paying. Its claims that it deleted stolen government data were not independently established.
Described as a longstanding ransomware group and an alleged extortion target of ShinyHunters operator Rey. Rey also published a blog post identifying two Russian men as alleged core developers and hackers behind Cl0p. The article does not detail Cl0p's own attacks, malware deployments, or exploited vulnerabilities.
An established ransomware group discussed as an alleged extortion target of Rey, rather than as an operator in the PeopleSoft campaign. Rey also published a blog post identifying two Russian men as its purported core developers and hackers. The article does not independently establish those identities or describe specific Cl0p attacks.
A rival cybercrime group identified as a victim of ShinyHunters, which reportedly compromised it and defaced its leak site. The article does not describe Clop’s own attacks or malware use.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.