Ransomware group profile · #389 by claimed victims
Cl0p ransomwarealso Clop, TA505, FIN11
Distinct from every other crew here in that it often does not deploy ransomware at all. Cl0p specialises in mass exploitation of managed file transfer products, stealing data from hundreds of organisations in a single campaign and extorting on the theft alone.
Tactics, techniques and procedures
4 MITRE ATT&CK techniques mapped to Cl0p from public advisories and VULONE's own analysis.
| Tactic | Technique | Procedure | Confidence |
|---|---|---|---|
| Initial Access | T1190 Exploit Public-Facing Application | Zero-day exploitation of managed file transfer products, executed against hundreds of organisations within days: MOVEit Transfer (CVE-2023-34362), GoAnywhere MF… | Confirmed |
| Persistence | T1505.003 Web Shell | Web shells planted on the compromised appliance, giving durable access and a route to run queries against the application database. | Confirmed |
| Collection | T1213 Data from Information Repositories | Data pulled straight out of the appliance database, which in a file transfer product is the most sensitive material the organisation has. | Confirmed |
| Exfiltration | T1567 Exfiltration Over Web Service | Bulk theft over the same channel used for exploitation, often completed within hours. | Confirmed |
Tooling observed
Indicators, detections and the full playbook
Hashes, C2 addresses, onion services, Sigma and YARA detections per technique, and the negotiation transcripts are available to signed-in analysts.
Attack playbook
How a typical Cl0p intrusion unfolds, section by section.
Initial access
One vulnerability, hundreds of victims — Cl0p treats initial access as a campaign rather than an intrusion: acquire or develop a zero day in a widely deployed file transfer product, exploit everything reachable in a short window, then extort at leisure. Detecti…
Negotiation and extortion
Extortion without encryption — Where no encryption is deployed there is no recovery question, only a disclosure one. That changes the incident response calculus entirely and should be planned for separately.
Frequently asked
Is Cl0p ransomware still active?
How many victims has Cl0p claimed?
Which industries does Cl0p target?
Which countries are most affected by Cl0p?
Where does VULONE get Cl0p victim data?
Public sources
| Title | Publisher | Date |
|---|---|---|
| #StopRansomware: CL0P Ransomware Gang Exploits CVE-2023-34362 MOVEit Vulnerability (AA23-158A) | CISA / FBI | 7 Jun 2023 |
Other ransomware groups
Victim claims are collected from leak sites and enrichment partners (ransomware.live, RansomLook) and represent the group's own assertions, not confirmed breaches. Profile last updated 28 August 2026. Questions or corrections: [email protected].