← All ransomware groups

Ransomware group profile · #389 by claimed victims

Cl0p ransomwarealso Clop, TA505, FIN11

Distinct from every other crew here in that it often does not deploy ransomware at all. Cl0p specialises in mass exploitation of managed file transfer products, stealing data from hundreds of organisations in a single campaign and extorting on the theft alone.

Active Russia First seen Feb 2019 ATT&CK G0092 AES with RSA wrapped key; frequently skipped entirely in favour of theft alone Russian
0Victims claimed on leak sites
0Victims in the last 30 days
0Victims in the last 90 days
0Countries hit
0Leak-site URLs tracked
Latest claim recorded

Tactics, techniques and procedures

4 MITRE ATT&CK techniques mapped to Cl0p from public advisories and VULONE's own analysis.

TacticTechniqueProcedureConfidence
Initial Access T1190 Exploit Public-Facing Application Zero-day exploitation of managed file transfer products, executed against hundreds of organisations within days: MOVEit Transfer (CVE-2023-34362), GoAnywhere MF… Confirmed
Persistence T1505.003 Web Shell Web shells planted on the compromised appliance, giving durable access and a route to run queries against the application database. Confirmed
Collection T1213 Data from Information Repositories Data pulled straight out of the appliance database, which in a file transfer product is the most sensitive material the organisation has. Confirmed
Exfiltration T1567 Exfiltration Over Web Service Bulk theft over the same channel used for exploitation, often completed within hours. Confirmed

Tooling observed

Indicators, detections and the full playbook

Hashes, C2 addresses, onion services, Sigma and YARA detections per technique, and the negotiation transcripts are available to signed-in analysts.

See full IOCs

Attack playbook

How a typical Cl0p intrusion unfolds, section by section.

Initial access

One vulnerability, hundreds of victims — Cl0p treats initial access as a campaign rather than an intrusion: acquire or develop a zero day in a widely deployed file transfer product, exploit everything reachable in a short window, then extort at leisure. Detecti…

Negotiation and extortion

Extortion without encryption — Where no encryption is deployed there is no recovery question, only a disclosure one. That changes the incident response calculus entirely and should be planned for separately.

Frequently asked

Is Cl0p ransomware still active?
Cl0p is tracked as active.
How many victims has Cl0p claimed?
VULONE has recorded 0 leak-site victim claims attributed to Cl0p, across 0 countries and 0 sectors.
Which industries does Cl0p target?
Sector data for Cl0p victims is not yet available.
Which countries are most affected by Cl0p?
Country data for Cl0p victims is not yet available.
Where does VULONE get Cl0p victim data?
Claims are collected continuously from the group's own leak sites and cross-checked with ransomware.live and RansomLook. A claim is the group's assertion, not a confirmed breach.

Public sources

Other ransomware groups

Victim claims are collected from leak sites and enrichment partners (ransomware.live, RansomLook) and represent the group's own assertions, not confirmed breaches. Profile last updated 28 August 2026. Questions or corrections: [email protected].