Description Summary
Clop (Cl0p) ransomware is a long-running family active since 2019, derived from the CryptoMix family. Operated by the FIN11 / TA505 actor cluster, Clop is most notorious for mass-exploitation campaigns against managed file transfer products — Accellion FTA (2020/21), GoAnywhere MFT (2023), MOVEit Transfer (2023), and Cleo (2024) — affecting thousands of organizations downstream.
Threat Actor
The FIN11 / TA505 cluster, a financially motivated Russian-speaking group. Distinguished by industrial-scale zero-day exploitation of file-transfer software.
Technical Indicators
Encryption Extension
.clop / .Cl0p
Encryption Algorithm
AES-256 + RSA-1024
Ransom Note Name
ClopReadMe.txt / README_README.txt
Targeted Industries
Financial, Government, Healthcare, Education, Retail (cross-industry via supply-chain)
First Seen
February 2019
Last Seen
Active — Oracle E-Business Suite zero-day campaign (CVE-2025-61882), Aug–Oct 2025
Geographical Location
Global
MITRE ATT&CK Matrix
| Tactic | TTP | Technique Name |
|---|---|---|
| Initial Access x 4 | T1566 | Phishing |
| T1190 | Exploit Public-Facing Application | |
| T1078 | Valid Accounts | |
| T1190 | Exploit Public-Facing Application (MOVEit, GoAnywhere, Cleo) | |
| Execution x 1 | T1059 | Command and Scripting Interpreter |
| Execution Persistence x 1 | T1053 | Scheduled Task/Job |
| Defense Evasion x 2 | T1562.001 | Disable or Modify Tools |
| T1070.004 | File Deletion | |
| Discovery x 2 | T1083 | File and Directory Discovery |
| T1082 | System Information Discovery | |
| Lateral Movement x 2 | T1021.001 | Remote Services: RDP |
| T1021.002 | SMB/Windows Admin Shares | |
| Exfiltration x 2 | T1041 | Exfiltration Over C2 Channel |
| T1567.002 | Exfiltration to Cloud Storage | |
| Impact x 3 | T1486 | Data Encrypted for Impact |
| T1490 | Inhibit System Recovery | |
| T1489 | Service Stop | |
| Persistence x 1 | T1505.003 | Web Shell (LemurLoot) |