Clop (Cl0p) Ransomware

Description Summary

Clop (Cl0p) ransomware is a long-running family active since 2019, derived from the CryptoMix family. Operated by the FIN11 / TA505 actor cluster, Clop is most notorious for mass-exploitation campaigns against managed file transfer products — Accellion FTA (2020/21), GoAnywhere MFT (2023), MOVEit Transfer (2023), and Cleo (2024) — affecting thousands of organizations downstream.

Threat Actor

The FIN11 / TA505 cluster, a financially motivated Russian-speaking group. Distinguished by industrial-scale zero-day exploitation of file-transfer software.

Technical Indicators

Encryption Extension
.clop / .Cl0p
Encryption Algorithm
AES-256 + RSA-1024
Ransom Note Name
ClopReadMe.txt / README_README.txt
Targeted Industries
Financial, Government, Healthcare, Education, Retail (cross-industry via supply-chain)
First Seen
February 2019
Last Seen
Active — Oracle E-Business Suite zero-day campaign (CVE-2025-61882), Aug–Oct 2025
Geographical Location
Global

MITRE ATT&CK Matrix

Tactic TTP Technique Name
Initial Access x 4 T1566 Phishing
T1190 Exploit Public-Facing Application
T1078 Valid Accounts
T1190 Exploit Public-Facing Application (MOVEit, GoAnywhere, Cleo)
Execution x 1 T1059 Command and Scripting Interpreter
Execution Persistence x 1 T1053 Scheduled Task/Job
Defense Evasion x 2 T1562.001 Disable or Modify Tools
T1070.004 File Deletion
Discovery x 2 T1083 File and Directory Discovery
T1082 System Information Discovery
Lateral Movement x 2 T1021.001 Remote Services: RDP
T1021.002 SMB/Windows Admin Shares
Exfiltration x 2 T1041 Exfiltration Over C2 Channel
T1567.002 Exfiltration to Cloud Storage
Impact x 3 T1486 Data Encrypted for Impact
T1490 Inhibit System Recovery
T1489 Service Stop
Persistence x 1 T1505.003 Web Shell (LemurLoot)