Clop, also tracked as Snakefly and associated with the aliases TA505 and FIN11, is a financially motivated cybercrime threat actor best known for large-scale extortion operations centered on mass data theft from enterprise file-transfer and business software. The group operates the Clop ransomware brand and has been a prominent driver of the shift from traditional file-encrypting ransomware toward encryption-less extortion, in which stolen data is used as leverage through leak threats rather than widespread deployment of an encryptor. The actor is notable for exploiting zero-day vulnerabilities in widely deployed enterprise software to compromise many organizations through a single flaw. High-confidence reporting links Clop/Snakefly to exploitation of Accellion FTA vulnerabilities in 2021, the GoAnywhere MFT zero-day CVE-2023-0669, the MOVEit Transfer zero-day CVE-2023-34362 in 2023, and Oracle E-Business Suite zero-day exploitation in 2025. In the MOVEit campaign, the group exploited the vulnerable web application, deployed the Lemurloot web shell, accessed underlying databases, and exfiltrated victim data at scale. Because these products are commonly used for inter-organizational file exchange and enterprise workflows, Clop operations have repeatedly created downstream supply-chain impact affecting numerous victim organizations and their customers. Clop historically used a ransomware payload to encrypt victim files, but more recent operations have emphasized data-theft extortion and leak-site pressure. The group has publicly claimed responsibility for major campaigns, asserted that it stole data from multiple software users and their customers, and threatened publication unless victims paid. This tradecraft places Clop among the most influential extortion actors in the evolution of modern ransomware-adjacent operations. Observed capabilities include initial access through exploitation of internet-facing enterprise applications, post-exploitation activity via web shells and database interaction, large-scale data exfiltration, and defense evasion through reduced reliance on noisy encryption stages. The actor’s campaigns demonstrate strong operational focus on opportunistic mass victimization, software supply-chain leverage, and monetization through extortion.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
12 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 malware families attributed to this actor across reporting.
3 CVEs this actor has used in observed campaigns. 3 of them exploited in the wild.
Earlier this year it was responsible for exploiting a zero-day vulnerability (CVE-2023-0669) in the GoAnywhere MFT platform.
The original vulnerability (CVE-2023-34362) was patched on May 31... Prior to its patching, attackers linked to the Clop ransomware operation were already exploiting CVE-2023-34362 as a zero-day vulnerability. Proof-of-concept code for the exploit is now publicly available...
"Its most recent campaign came to light in October 2025, when it was linked to extortion attacks that targeted users of Oracle E-Business Suites (EBS). Snakefly exploited a critical zero-day vulnerability (CVE-2025-61882) in EBS that allowed unauthenticated attackers to remotely execute code on vulnerable systems."
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Operator behind Cl0p-associated activity highlighted for scaling encryptionless extortion by exploiting vulnerabilities in widely used enterprise software to steal data at scale and threaten publication.
Cybercrime group operating the Clop extortion/ransomware operation, with a track record of exploiting zero-day vulnerabilities in managed file-transfer products for large-scale data theft and extortion.
Pioneering “encryptionless extortion” by using zero-day exploit campaigns against enterprise software to exfiltrate data at scale and extort victims via threatened leaks; linked to attacks on Oracle E-Business Suite via a critical zero-day.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.