Clop

MITRE ATT&CK: S0611 View on attack.mitre.org

Aliases: Cl0p, Clop

First seen
2019-02-01 00:00:00
Malware type
ransomware
Family
Malware family
Operating systems
windows
Related IoCs
154 (62 malicious)
Last IoC activity
2026-09-01 10:30:28
Profile updated
2026-07-07 12:40:28

Targeted industries: education-and-nonprofits energy-and-utilities financial-services healthcare-and-pharmaceutical manufacturing professional-services retail-and-hospitality technology-and-telecommunications transportation-and-logistics

Context

Clop is a ransomware family that was first observed in February 2019 and has been used against retail, transportation and logistics, education, manufacturing, engineering, automotive, energy, financial, aerospace, telecommunications, professional and legal services, healthcare, and high tech industries. Clop is a variant of the CryptoMix ransomware.

Recent IoC activity

62 malicious indicators in Maltiverse are attributed to Clop (S0611). The 20 most recently updated:

TypeIndicatorUpdatedSources
IP address 5.188.87.40 2026-09-01 7
file sample 2026-08-23_c04be778a104c2367e1bd984d3a8c1a2_amadey_clop_elex_hellokitty_smoke-loader 2026-08-23 1
file sample 2026-08-19_c1e378e42e67a9433627eb5d2c6053a6_cobalt-strike_elex_wannacry 2026-08-20 1
file sample 2026-08-17_2d8bababba3df963e029b0c7d75b480e_destroyer_elex_glassworm_ngrbot_wannacry 2026-08-18 1
file sample cheezu.io_chrome.exe 2026-08-17 1
file sample cheezu.io_chrome.exe 2026-08-17 1
file sample cheezu.io_chrome.exe 2026-08-17 1
file sample cheezu.io_chrome.exe 2026-08-17 1
file sample add91718a8b5baae8c805eb4820159d8cad6519b207f2a544a7181350bcf7e8a 2026-08-12 1
file sample 2026-03-11_31c03cc1ccf855a45c2aeda2cf4ca766_clop_cobalt-strike_elex_remcos 2026-08-06 1
file sample 2026-07-13_9e467d6ab20a63577216f231d07c3d57_clop_elex_remcos 2026-07-13 1
file sample e7cdde7f52821eaa2b843fb712dfe1320a44ea0c331c43b81bd06ca5c39e4731.exe 2026-05-10 2
file sample SHIPPING DOCUMENTS.js 2026-04-24 2
file sample 2026-03-15_7a0a5fd54554887c35e97bcb7f58318e_elex_remcos_rhadamanthys_stop 2026-03-15 1
file sample 2026-03-15_5cec8c9680722abfc12d3a6b2d00bc99_clop_elex_remcos 2026-03-15 1
file sample 2026-03-14_88d262a7804ea887d71f82edb607200f_clop_elex_remcos 2026-03-14 1
file sample 2026-03-14_797f5a3a01754aec5a78c93b7b83674f_clop_elex_remcos 2026-03-14 1
file sample 2026-03-14_3931c82daf50cb031fa9ab3a02fbba90_elex_remcos_rhadamanthys_stop 2026-03-14 1
file sample 2026-03-13_27aa9e03d7a9a9ea3e5d2fe77aa3df3c_elex_remcos_rhadamanthys_stop 2026-03-13 1
file sample 2026-03-13_ee03b9c339fb7ed8682afb552e58ae8d_clop_elex_remcos 2026-03-13 1

Detection coverage

  • 2 YARA rules
  • 389 Sigma rules

Malware & tools used

  • Security Software Discovery (attack-pattern)
  • Service Stop (attack-pattern)
  • Deobfuscate/Decode Files or Information (attack-pattern)
  • Native API (attack-pattern)
  • Time Based Checks (attack-pattern)
  • Software Packing (attack-pattern)
  • System Language Discovery (attack-pattern)
  • File and Directory Discovery (attack-pattern)
  • Process Discovery (attack-pattern)
  • Windows Command Shell (attack-pattern)
  • Code Signing (attack-pattern)
  • Modify Registry (attack-pattern)
  • Network Share Discovery (attack-pattern)
  • Inhibit System Recovery (attack-pattern)
  • Data Encrypted for Impact (attack-pattern)
  • Disable or Modify Tools (attack-pattern)
  • Msiexec (attack-pattern)

Used by threat actors

  • TA505 (threat-actor)
  • Cleo File Transfer Software Zero-Day Exploits (CVE-2024-50623 & CVE-2024-55956) (campaign)
  • Clop MOVEit Transfer Vulnerability Exploitation (campaign)

Detection rules

  • DITEKSHEN_MALWARE_Win_Clop (yara-rule)
  • MALPEDIA_Win_Clop_Auto (yara-rule)

Reports & references

  • CrowdStrike — Report2020Crowdstrikeglobalthreatreport (report)
  • telekom.com — Cybersecurity Ta505 S Box Of Chocolate 597672 (report)
  • telekom.com — Cybersecurity Ta505 Returns With A New Bag Of Tricks 602104 (report)
  • secureworks.com — Gold Tahoe (report)
  • telekom.com — Eager Beaver A Short Overview Of The Restless Threat Actor Ta505 609546 (report)
  • blog.fox-it.com — Ta505 A Brief History Of Their Time (report)
  • CrowdStrike — Report2021Gtr (report)
  • CrowdStrike — How Big Game Hunting Ttps Shifted After Darkside Pipeline Attack (report)
  • Trend Micro — Global Operations Lead To Arrests Of Alleged Members Of Gandcrab (report)
  • blog.sensecy.com — Global Ransomware Attacks In 2020 The Top 4 Vulnerabilities (report)
  • cisoclub.ru — Otchet Kompanii Group Ib Ransomware Uncovered 2020 2021 (report)
  • docs.google.com — 1Mi8Z2Tbhmqq5X8Wf Ozv3Dvjz5Sjos 3 (report)
  • ke-la.com — How Ransomware Gangs Find New Monetization Schemes And Evolve In Marketing (report)
  • public.intel471.com — Ransomware As A Service 2020 Ryuk Maze Revil Egregor Doppelpaymer (report)
  • Broadcom/Symantec — The Ransomware Threat September 2021 (report)
  • vulnerability.ch — Ransomware And Date Leak Site Publication Time Analysis (report)
  • web.archive.org — Otchet Kompanii Group Ib Ransomware Uncovered 2020 2021 (report)
  • advanced-intel.com — Adversarial Perspective Advintel Breach Avoidance Through Monitoring Initial Vulnerabilities (report)
  • bleepingcomputer.com — Three More Ransomware Families Create Sites To Leak Stolen Data (report)
  • bsi.bund.de — Lagebericht2020 (report)
  • cert.ssi.gouv.fr — Certfr 2020 Cti 001 (report)
  • coveware.com — Ransomware Attack Vectors Shift As New Software Vulnerability Exploits Abound (report)
  • cronup.com — De Ataque Con Malware A Incidente De Ransomware (report)
  • flashpoint-intel.com — Cl0P And Revil Escalate Their Ransomware Tactics (report)
  • hornetsecurity.com — Leakware Ransomware Hybrid Attacks (report)

External references