Ransomware group profile · #4 by claimed victims
Clop ransomwarealso Cl0p
The ransomware group known as Cl0p is a variant of a previously known strain dubbed CryptoMix. It is worth noting that this variant was delivered as the final payload in a phishing campaign in 2019 and was exclusively financially motivated, with attacks carried out by the threat actors TA505.<br> <br> At that time, malicious actors sent phishing emails that led to a macro-enabled document that would drop a loader called 'Get2.' After gaining an initial foothold in the system or infrastructure, the actors began using reconnaissance, lateral movement, and exfiltration techniques to prepare for the deployment of the ransomware.<br> <br> After the execution of the ransomware, Cl0p appends the extension '.clop' to the end of files, or other types of extensions such as '.CIIp, .Cllp, and .C_L_O_P,' as well as different versions of the ransom note that were also observed after encryption. Depending on the variant, any of the ransom text files were created with names like 'ClopReadMe.txt, README_README.txt, Cl0pReadMe.txt, and READ_ME_!!!.TXT.'<br> <br> The Clop operation has shifted from delivering its final payload via phishing and has begun initiating attacks using vulnerabilities that resulted in the exploitation and infection of victims' infrastructures.<BR>Source: https://github.com/crocodyli/ThreatActors-TTPs
Victimology
Who Clop claims to have breached, from 1,344 leak-site posts recorded by VULONE.
Claims per month last 12 months
Top sectors
Top countries
Latest claimed victims 12 most recent
| Victim | Sector | Country | Claimed |
|---|---|---|---|
| HENRYPRATT.COM henrypratt.com | Manufacturing | US | 10 Sep 2026 |
| HARLEY-DAVIDSON.COM harley-davidson.com | Manufacturing | US | 10 Sep 2026 |
| HENRYPRATT.COM | — | — | 10 Sep 2026 |
| HARLEY-DAVIDSON.COM | — | — | 10 Sep 2026 |
| ZEBRA.COM zebra.com | Manufacturing | US | 14 Aug 2026 |
| NUVITIA.COM nuvitia.com | Technology | ES | 12 Aug 2026 |
| IPMSOLUTIONS.SK ipmsolutions.sk | Professional Services | SK | 12 Aug 2026 |
| ECCELLENT.COM eccellent.com | Other | IT | 12 Aug 2026 |
| STNET.IT stnet.it | Technology | IT | 12 Aug 2026 |
| QCPL.IN qcpl.in | Manufacturing | IN | 12 Aug 2026 |
| FLUIDLOGIC.COM fluidlogic.com | Technology | US | 12 Aug 2026 |
| MIDLANDIND.COM.AU midlandind.com.au | Manufacturing | AU | 12 Aug 2026 |
All 1,344 Clop victims, searchable
Full victim list with claim posts, domains, timing and exports, plus the negotiation chats and leak-site screenshots VULONE archives for this crew.
Tactics, techniques and procedures
ATT&CK technique mapping for Clop is in progress. Victimology, infrastructure status and leak-site tracking are live above.
Indicators, detections and the full playbook
Hashes, C2 addresses, onion services, Sigma and YARA detections per technique, and the negotiation transcripts are available to signed-in analysts.
Frequently asked
Is Clop ransomware still active?
How many victims has Clop claimed?
Which industries does Clop target?
Which countries are most affected by Clop?
Where does VULONE get Clop victim data?
Other ransomware groups
Victim claims are collected from leak sites and enrichment partners (ransomware.live, RansomLook) and represent the group's own assertions, not confirmed breaches. Profile last updated 16 September 2026. Questions or corrections: [email protected].