Clop
MITRE ATT&CK: S0611 View on attack.mitre.org
Aliases: Cl0p, Clop
- First seen
- 2019-02-01 00:00:00
- Malware type
- ransomware
- Family
- Malware family
- Operating systems
- windows
- Related IoCs
- 154 (62 malicious)
- Last IoC activity
- 2026-09-01 10:30:28
- Profile updated
- 2026-07-07 12:40:28
Targeted industries: education-and-nonprofits energy-and-utilities financial-services healthcare-and-pharmaceutical manufacturing professional-services retail-and-hospitality technology-and-telecommunications transportation-and-logistics
Context
Clop is a ransomware family that was first observed in February 2019 and has been used against retail, transportation and logistics, education, manufacturing, engineering, automotive, energy, financial, aerospace, telecommunications, professional and legal services, healthcare, and high tech industries. Clop is a variant of the CryptoMix ransomware.
Recent IoC activity
62 malicious indicators in Maltiverse are attributed to Clop (S0611). The 20 most recently updated:
Detection coverage
- 2 YARA rules
- 389 Sigma rules
Malware & tools used
- Security Software Discovery (attack-pattern)
- Service Stop (attack-pattern)
- Deobfuscate/Decode Files or Information (attack-pattern)
- Native API (attack-pattern)
- Time Based Checks (attack-pattern)
- Software Packing (attack-pattern)
- System Language Discovery (attack-pattern)
- File and Directory Discovery (attack-pattern)
- Process Discovery (attack-pattern)
- Windows Command Shell (attack-pattern)
- Code Signing (attack-pattern)
- Modify Registry (attack-pattern)
- Network Share Discovery (attack-pattern)
- Inhibit System Recovery (attack-pattern)
- Data Encrypted for Impact (attack-pattern)
- Disable or Modify Tools (attack-pattern)
- Msiexec (attack-pattern)
Used by threat actors
- TA505 (threat-actor)
- Cleo File Transfer Software Zero-Day Exploits (CVE-2024-50623 & CVE-2024-55956) (campaign)
- Clop MOVEit Transfer Vulnerability Exploitation (campaign)
Detection rules
- DITEKSHEN_MALWARE_Win_Clop (yara-rule)
- MALPEDIA_Win_Clop_Auto (yara-rule)
Reports & references
- CrowdStrike — Report2020Crowdstrikeglobalthreatreport (report)
- telekom.com — Cybersecurity Ta505 S Box Of Chocolate 597672 (report)
- telekom.com — Cybersecurity Ta505 Returns With A New Bag Of Tricks 602104 (report)
- secureworks.com — Gold Tahoe (report)
- telekom.com — Eager Beaver A Short Overview Of The Restless Threat Actor Ta505 609546 (report)
- blog.fox-it.com — Ta505 A Brief History Of Their Time (report)
- CrowdStrike — Report2021Gtr (report)
- CrowdStrike — How Big Game Hunting Ttps Shifted After Darkside Pipeline Attack (report)
- Trend Micro — Global Operations Lead To Arrests Of Alleged Members Of Gandcrab (report)
- blog.sensecy.com — Global Ransomware Attacks In 2020 The Top 4 Vulnerabilities (report)
- cisoclub.ru — Otchet Kompanii Group Ib Ransomware Uncovered 2020 2021 (report)
- docs.google.com — 1Mi8Z2Tbhmqq5X8Wf Ozv3Dvjz5Sjos 3 (report)
- ke-la.com — How Ransomware Gangs Find New Monetization Schemes And Evolve In Marketing (report)
- public.intel471.com — Ransomware As A Service 2020 Ryuk Maze Revil Egregor Doppelpaymer (report)
- Broadcom/Symantec — The Ransomware Threat September 2021 (report)
- vulnerability.ch — Ransomware And Date Leak Site Publication Time Analysis (report)
- web.archive.org — Otchet Kompanii Group Ib Ransomware Uncovered 2020 2021 (report)
- advanced-intel.com — Adversarial Perspective Advintel Breach Avoidance Through Monitoring Initial Vulnerabilities (report)
- bleepingcomputer.com — Three More Ransomware Families Create Sites To Leak Stolen Data (report)
- bsi.bund.de — Lagebericht2020 (report)
- cert.ssi.gouv.fr — Certfr 2020 Cti 001 (report)
- coveware.com — Ransomware Attack Vectors Shift As New Software Vulnerability Exploits Abound (report)
- cronup.com — De Ataque Con Malware A Incidente De Ransomware (report)
- flashpoint-intel.com — Cl0P And Revil Escalate Their Ransomware Tactics (report)
- hornetsecurity.com — Leakware Ransomware Hybrid Attacks (report)