ThreatBox · Threat Actor Attribution
Clop
a.k.a. CL0P, TA505 (affiliate), FIN11 (related)
Financial (Extortion — data theft > encryption) Russia (attributed) First seen 2019-02
Clop is a data-extortion group that pivoted from traditional ransomware to mass zero-day exploitation of managed file-transfer (MFT) products. They pioneered the 'pure extortion' model — steal data, skip encryption, threaten leak. Landmark campaigns: Accellion FTA (Dec 2020), GoAnywhere MFT (Jan 2023), and the MOVEit Transfer zero-day (May 2023) that hit 2,700+ organisations including US federal agencies, Shell, BBC, British Airways, and Zellis payroll customers.
Targeted sectors
Software supply chain victimsHealthcareFinancial servicesHigher education
Targeted regions
Global
Known TTPs (4)
T1190Exploit Public-Facing Application (MOVEit, GoAnywhere)
T1567.002Exfiltration to Cloud Storage
T1657Financial Theft (leak-site extortion)
T1486Data Encrypted for Impact
Click any technique to open the MITRE ATT&CK reference.
Attack Timeline
- 2020-12Accellion FTA zero-day (CVE-2021-27101)
- 2023-01GoAnywhere MFT zero-day (CVE-2023-0669) — 130+ victims
- 2023-05MOVEit Transfer zero-day (CVE-2023-34362) — 2,700+ victims
- 2024-11Cleo LexiCom / Harmony / VLTrader zero-day (CVE-2024-50623) mass-exploitation
References
End of dossier · Clop
Back to ThreatBox