Overview

Platforms: Windows
Variants: —
Extensions: .clop
ATT&CK software: —
Initial access: Exploit Public-Facing Application
Top countries: —
Observed sectors: —
Tracked victims: 1,302

Attribution

TA505 VERIFIED
Documented Clop user
MITRE ATT&CK documents TA505 ransomware campaigns involving Clop.
FIN11 PROBABLE
Primary Cl0p extortion association
Mandiant has attributed numerous Cl0p ransomware and data-extortion operations to FIN11 and related clusters, while noting that the Cl0p brand is not necessarily used exclusively by FIN11.

Affiliates

No affiliate information available.

Activity

Recent Observations

Continued Cl0p victim claims
September 2026
Extortion activity
New Cl0p victim claims continued to be observed in September 2026.
Oracle EBS campaign drives Q1 activity
March 2026
Mass extortion campaign
Cl0p recorded 127 victim postings during Q1 2026, largely associated with exploitation of Oracle E-Business Suite.
Oracle E-Business Suite extortion campaign
September 2025
Zero-day exploitation
Actors using the Cl0p extortion brand launched a large-scale campaign targeting Oracle E-Business Suite environments after months of exploitation activity.
Cleo MFT exploitation
December 2024
Mass exploitation
A suspected FIN11 cluster exploited Cleo managed file-transfer products as part of a data-theft extortion campaign associated with the Cl0p ecosystem.
MOVEit campaign
May 2023
Mass exploitation
Cl0p-linked actors exploited a MOVEit Transfer zero-day at scale and stole data from organizations around the world.

TTPs

ATT&CK coverage: 6 techniques · 5 tactics
T1190 Exploit Public-Facing Application
VERIFIED
Initial Access
Cl0p-linked campaigns repeatedly exploited internet-facing enterprise applications and managed file-transfer products for initial access and data theft.
T1059.003 Windows Command Shell
VERIFIED
Execution
Clop ransomware can use cmd.exe to execute commands on compromised systems.
T1218.007 Msiexec
VERIFIED
Defense Evasion
Clop has used msiexec.exe as part of activity designed to interfere with security tooling.
Show more TTPs (3)
T1614.001 System Language Discovery
VERIFIED
Discovery
Clop checks system language and keyboard configuration and has avoided execution on certain CIS-language systems.
T1490 Inhibit System Recovery
VERIFIED
Impact
Clop has been documented interfering with recovery mechanisms during ransomware operations.
T1486 Data Encrypted for Impact
VERIFIED
Impact
Clop ransomware encrypts victim files using multiple cryptographic mechanisms.

Victims

CVEs

Progress Software — MOVEit Transfer
Cl0p-linked actors exploited this previously unknown SQL injection vulnerability at scale to deploy the LEMURLOOT web shell and steal data.
Associated since: May 2023
Fortra — GoAnywhere MFT
FIN11-attributed Cl0p extortion activity was associated with exploitation of this GoAnywhere MFT vulnerability.
Associated since: January 2023
Cleo — Harmony / VLTrader / LexiCom
Google Threat Intelligence linked exploitation of this zero-day to a suspected FIN11 cluster conducting data-theft extortion associated with the Cl0p ecosystem.
Associated since: December 2024
Show more CVEs (2)
Oracle — E-Business Suite
Actors using the Cl0p extortion brand exploited Oracle E-Business Suite environments in a large-scale zero-day campaign.
Associated since: August 2025
Oracle — E-Business Suite
Google Threat Intelligence reported this vulnerability among the Oracle EBS zero-days associated with Cl0p-branded extortion activity.
Associated since: August 2025

Infrastructure

Cl0p leak site
Cl0p operates Tor-hosted data leak infrastructure used to publish victim claims and stolen information as part of its extortion model.
Extortion infrastructure
Cl0p operations use dedicated contact addresses, negotiation channels and victim-specific extortion communications following data theft.

Timeline

2026-09
Continued Cl0p activity
New Cl0p victim claims continued to be observed in September 2026.
2026-03
Oracle campaign drives Q1 activity
Check Point recorded 127 Cl0p victim postings during Q1 2026, largely associated with the Oracle EBS campaign.
2025-09
Oracle EBS extortion campaign
A large-scale Cl0p-branded extortion campaign followed exploitation of Oracle E-Business Suite zero-day vulnerabilities.
Show more events (6)
2024-12
Cleo MFT exploitation
A suspected FIN11 cluster exploited a Cleo zero-day in another data-theft extortion campaign.
2023-05
MOVEit mass exploitation
Cl0p-linked actors exploited CVE-2023-34362 in MOVEit Transfer and stole data from organizations worldwide.
2023-01
GoAnywhere MFT campaign
Cl0p-linked actors exploited GoAnywhere MFT as part of another mass data-theft extortion campaign.
2021-01
Accellion FTA campaign
Actors exploited Accellion FTA zero-days to steal data and subsequently used the Cl0p leak site for extortion.
2020-01
Cl0p data leak infrastructure emerges
The Cl0p data leak site became part of a combined ransomware and data-extortion model.
2019-02
Clop ransomware first observed
Clop ransomware was first observed in February 2019.

Sources

Clop — S0611
MITRE ATT&CK
Framework
TA505 — G0092
MITRE ATT&CK
Framework
FIN11: Widespread Email Campaigns as Precursor for Ransomware and Data Theft
Mandiant / Google Threat Intelligence
Vendor research
Show more sources (8)