Back to ThreatBox
ThreatBox · Threat Actor Attribution

Clop

a.k.a. CL0P, TA505 (affiliate), FIN11 (related)
Financial (Extortion — data theft > encryption) Russia (attributed) First seen 2019-02

Clop is a data-extortion group that pivoted from traditional ransomware to mass zero-day exploitation of managed file-transfer (MFT) products. They pioneered the 'pure extortion' model — steal data, skip encryption, threaten leak. Landmark campaigns: Accellion FTA (Dec 2020), GoAnywhere MFT (Jan 2023), and the MOVEit Transfer zero-day (May 2023) that hit 2,700+ organisations including US federal agencies, Shell, BBC, British Airways, and Zellis payroll customers.

Targeted sectors
Software supply chain victimsHealthcareFinancial servicesHigher education
Targeted regions
Global

Known TTPs (4)

Click any technique to open the MITRE ATT&CK reference.

Attack Timeline

  1. 2020-12
    Accellion FTA zero-day (CVE-2021-27101)
  2. 2023-01
    GoAnywhere MFT zero-day (CVE-2023-0669) — 130+ victims
  3. 2023-05
    MOVEit Transfer zero-day (CVE-2023-34362) — 2,700+ victims
  4. 2024-11
    Cleo LexiCom / Harmony / VLTrader zero-day (CVE-2024-50623) mass-exploitation

References

End of dossier · Clop
Back to ThreatBox