Cl0p — Ransomware Profile
Cl0p ransomware group conducted unprecedented mass exploitation campaigns via MOVEit and GoAnywhere zero-days, affecting thousands of organizations globally.Also tracked as
TA505 ransomware arm, CryptoMix (lineage), Snakefly, Graceful Spider, Clop
IntelFusions coverage (6)
- New crew Storm goes after US clinics, banks and factories 2026-08-25 · Ransomware
- Cl0p names 45 victims in a day, including GE and Shell 2026-08-14 · Ransomware
- Ransomware crews pile onto Italy's industrial firms 2026-08-13 · Cyber Incidents
- Ransomware claims against Indian firms tripled in a month 2026-08-12 · Cyber Incidents
- Cl0p Goes Linux — and Gets It Wrong: SentinelLabs Publishes Free Decryptor for Flawed ELF Ransomware Variant 2026-02-16 · Ransomware
- TA505 Pivots from Phishing to CVE-2021-35211 SolarWinds Serv-U Exploitation: Cobalt Strike Delivery and RegIdleBackup COM Handler Hijacking for FlawedGrace RAT Persistence 2026-02-16 · Ransomware
Tools & malware
- Cl0p (CL0P) ransomware encryptor Ransomware (CryptoMix-derived)
- Cobalt Strike Post-exploitation framework
- DEWMODE Web shell (Accellion FTA)
- FlawedAmmyy / FlawedGrace Remote access trojan (RAT)
- Get2 Loader / dropper
- GOLDVEIN.JAVA Java downloader
- LEMURLOOT Web shell (MOVEit Transfer)
- SAGEGIFT Java reflective class loader (Oracle WebLogic)
- SAGELEAF in-memory dropper
- SAGEWAVE malicious Java servlet filter
- SDBot Backdoor
- TinyMet Meterpreter stager
- Truebot First-stage downloader
Recent claimed victims
- HENRYPRATT.COM 2026-09-10
- HARLEY-DAVIDSON.COM 2026-09-10
- Data exfiltrated included the following: Database, Project 2026-08-14
- INTELLIGENTGROWTHSOLUTIONS.COM 2026-08-12
- 9ALTITUDES.COM 2026-08-12
- AOL.COM 2026-08-12
- GATE7LLC.COMGBBEV.COM 2026-08-12
- ENTERATEK.MXESBERBEVERAGE.COM 2026-08-12
- NUVITIA.COM 2026-08-12
- IPMSOLUTIONS.SK 2026-08-12
- ECCELLENT.COM 2026-08-12
- STNET.IT 2026-08-12
- QCPL.IN 2026-08-12
- FLUIDLOGIC.COM 2026-08-12
- MIDLANDIND.COM.AU 2026-08-12
- ITKHOLDING.HU 2026-08-12
- G3AEROSPACE.COM 2026-08-12
- ARCHERGREY.COM 2026-08-12
- OMNITANKER.COM 2026-08-12
- LIFESTRAW.COM 2026-08-12
- SPKAA.COM 2026-08-12
- IVALUESYS.COM 2026-08-12
- NUOVACMM.COM 2026-08-12
- THERMOS.COM 2026-08-12
- WATERLANDPE.COM 2026-08-12
Vendor research
- Oracle E-Business Suite Zero-Day Exploited in Widespread Extortion Campaign Google Threat Intelligence Group (Mandiant)
- SentinelOne SentinelLABS SentinelOne
- Zero-Day Vulnerability in MOVEit Transfer Exploited for Data Theft Mandiant (Google Cloud)
- Graceful Spider Adversary Profile CrowdStrike
- Clop At The Top - But For How Long? Sophos
- Ransomware Spotlight: Clop Trend Micro
- #StopRansomware: CL0P Ransomware Gang Exploits CVE-2023-34362 MOVEit Vulnerability CISA / FBI
Countries linked to this actor
- United States targets