Cl0p
Russian-speaking cybercrime group · Financial — ransomware and extortion
Tactics, Techniques & Procedures (TTPs)
- Mass exploitation of file transfer vulnerabilities (MOVEit, GoAnywhere, Accellion)
- Data exfiltration and double-extortion
- Supply chain targeting via MFT software
- Minimal dwell time — fast exfil before encryption
- Public shaming via leak site
Known Targets
Analyst Notes
Specialises in zero-day exploitation of managed file transfer (MFT) software, compromising hundreds of organisations simultaneously. Believed to be affiliated with or emerged from TA505.
Also Known As
Intelligence Reports
Cl0p: The Group That Turned File Transfer Vulnerabilities Into a Mass Exploitation Business
Cl0p is a financially motivated cybercriminal group that has systematically identified and mass-exploited zero-day vulnerabilities in enterprise file transfer software, compromising thousands of organisations globally. Their MOVEit campaign in 2023 was the largest data theft operation in the history of ransomware. This deep dive covers their operational model, technical approach, and what comes next.
Cl0p Exploiting File Transfer Vulnerabilities Across Transport and Logistics Sector
The Cl0p ransomware group is mass-exploiting a newly disclosed vulnerability in a widely used managed file transfer platform. Several European freight and logistics operators have been impacted, with customs and supply chain data exfiltrated.