Clop (Cl0p) Ransomware: Complete Threat Profile, IOCs, And Latest Attacks



Clop ransomware, also written as Cl0p ransomware, has operated as one of the most persistent and strategically sophisticated cyber-extortion threats since its emergence in 2019. What began as a conventional enterprise ransomware family has evolved into a mass-exploitation operation responsible for more than 1,254 claimed victims across 54 countries as of mid-July 2026.
Live Leak-Site Data
As of July 20, 2026, the Clop ransomware group had publicly claimed 1,254 victims on its leak site, including 0 in the last 30 days. Known victims are concentrated in Technology (17%), Business Services (15%) and Consumer Services (13%), and span 53 countries.
This summary is automatically pulled from live cyber threat feeds. Because threat data changes rapidly, please verify critical details manually before taking action. Figures reflect publicly-claimed leak-site victims, not total infections.
Organizations affected by Clop span healthcare, financial services, legal firms, manufacturing, and global enterprise supply chains. Understanding how Clop operates and how it has changed is essential for any organization managing sensitive data or enterprise file transfer infrastructure. If your organization is currently under attack, Proven Data's ransomware recovery team is available immediately.
What is Clop ransomware?
Clop is a ransomware family derived from the CryptoMix strain, first identified in February 2019. It functions as the final payload in a multi-stage attack chain, designed to encrypt enterprise files, exfiltrate sensitive data, and support extortion operations. The malware appends distinctive file extensions to encrypted files and delivers ransom notes containing Bitcoin payment instructions.

The ransomware itself is distinct from the threat group that operates it. Different government agencies and cybersecurity vendors track the operators under varying designations, including TA505, FIN11, and Lace Tempest, among others.
These designations are not always treated as identical across sources, and attribution terminology is not uniform. What remains consistent across independent reporting is that the group is financially motivated, operationally sophisticated, and has operated continuously since at least 2019.
One behavioral characteristic embedded in the malware reflects the group's geographic context. Before execution, Clop queries the system's keyboard layout using the Windows GetKeyboardLayout API. If it detects layouts associated with Russia, Georgia, or Azerbaijan, the ransomware terminates without executing. This behavior is consistent with threat actors operating under informal protections within Commonwealth of Independent States jurisdictions.
For a broader foundation on how ransomware families operate, see our comprehensive guide on what is ransomware.
Operational evolution: from enterprise ransomware to mass extortion
Clop's defining characteristic is not its malware architecture but its strategic evolution. The group has moved from manual, phishing-driven enterprise intrusions targeting individual organizations to automated zero-day exploitation campaigns capable of compromising thousands of organizations simultaneously.
That shift, from targeted ransomware deployment to mass data-theft extortion, represents one of the most significant operational pivots observed in financially motivated cybercrime.
2019–2020: Enterprise ransomware and double extortion
Early Clop operations relied on large-scale phishing campaigns using macro-enabled Excel and Word documents to deliver the Get2 loader.
Attackers established persistence, moved laterally through corporate networks, and deployed Clop as the final payload after gaining control of Active Directory environments.
In March 2020, the group launched a Tor-based leak site used to publish stolen data and pressure victims who refused to pay. This positioned Clop among the earliest ransomware operations to operationalize double extortion at scale.
2021: Accellion FTA and the DEWMODE web shell
In late 2020 and into 2021, the group exploited four zero-day vulnerabilities in the Accellion File Transfer Appliance, tracked as CVE-2021-27101 through CVE-2021-27104. Attackers deployed a custom web shell named DEWMODE to silently exfiltrate data from high-profile targets.
Encryption was frequently skipped in these campaigns. The group demonstrated that stolen data alone was sufficient leverage for extortion, a model they refined in every subsequent major campaign.
2023: GoAnywhere MFT and MOVEit Transfer
In February 2023, the group exploited a remote code injection vulnerability (CVE-2023-0669) in Fortra's GoAnywhere MFT platform, claiming more than 130 victims. That campaign was eclipsed in May 2023 when Clop exploited a SQL injection zero-day (CVE-2023-34362) in Progress MOVEit Transfer.
According to CISA Advisory AA23-158a, the MOVEit campaign affected more than 2,000 organizations and compromised data belonging to more than 62 million individuals.
To counter takedowns of its clear-web leak infrastructure, the group began distributing stolen data via peer-to-peer torrents in August 2023, making removal practically impossible.
2024–2025: Cleo and Oracle EBS Expansion
In December 2024, Clop claimed responsibility for exploiting vulnerabilities in Cleo Harmony, VLTrader, and LexiCom (CVE-2024-55956), continuing its focus on managed file transfer platforms.
In 2025, reporting indicates the group expanded targeting to Oracle E-Business Suite (CVE-2025-61882) and Gladinet CentreStack (CVE-2025-14611).
2026: Automated Reconnaissance and Active Campaigns
In January 2026, the group posted 43 victims to its leak site within a single 24-hour period, including major hospitality and media organizations, a pattern security researchers interpret as evidence of automated internet-wide scanning.
The group remained operationally active as of mid-July 2026.
How Clop attacks organizations
A Clop intrusion follows a structured, multi-phase operation that frequently prioritizes data exfiltration over encryption, meaning an organization may be fully compromised and data removed before any visible ransomware indicators appear.
The lifecycle below reflects current behavior based on verified threat intelligence.
Phase 1: Initial access
Historically, Clop gained initial access through spear-phishing campaigns using macro-enabled documents to deliver the Get2 loader, which verified the environment and downloaded secondary payloads.
In major campaigns since 2021, the group has shifted to exploiting zero-day vulnerabilities in externally facing enterprise software, particularly managed file transfer platforms and business application suites.
Phase 2: Persistence and evasion
Following initial access, Clop operators systematically disable security controls before deploying any payload. The malware includes a component that actively terminates and uninstalls endpoint security products, including ESET, Malwarebytes, Webroot, Panda, and Windows Defender.
Executables are signed with valid digital certificates, historically associated with the signer "Insta Software Solution Inc.", to appear legitimate to operating-system security checks. The malware also terminates database and server processes, including SQL, ElasticSearch, and Apache, to ensure data files are fully accessible.
Phase 3: Lateral movement
With defenses suppressed, operators move through the network using tools including SDBot, FlawedAmmy, and Cobalt Strike Beacons. Mimikatz is used to harvest credentials from memory, enabling access to additional accounts and systems without triggering authentication failures.
Phase 4: Active Directory compromise
Access to the Domain Controller is the primary objective of the lateral movement phase. Once achieved, attackers can use the organization's administrative infrastructure to stage and deploy payloads across all connected systems simultaneously via task schedules or remote commands.
Phase 5: Data discovery and exfiltration
Before deploying any ransomware, operators use automated scripts to locate and compress high-value data directories. Tools such as Rclone or TrueBot are used to transfer data to cloud storage services, a technique that can bypass data loss prevention controls by routing traffic through legitimate cloud destinations over standard ports.
Phase 6: Extortion
In campaigns involving encryption, files are appended with Clop-specific extensions and ransom notes are delivered to affected systems.
In data-only campaigns, victims are named on the group's Tor-based leak site and given a deadline to pay.
High-value or uncooperative victims face additional pressure: C-suite workstations are explicitly targeted, employee information may be published, and the group has been observed contacting journalists to amplify reputational impact. Stolen data may also be distributed via torrent, extending the group's leverage well beyond what a standard takedown can address.
For a detailed overview of how double extortion mechanics work, see double extortion ransomware.
Indicators of compromise (IOCs)
The following artifacts provide high-fidelity indicators of Clop activity and should be monitored across endpoint, network, and identity layers. Security teams can use these to build detection rules, configure threat hunting queries, and support forensic triage during an active incident.
File extensions
- .clop
- .CIop (capital I, not lowercase L)
- .Cllp
- .C_L_O_P
Ransom notes
- ClopReadMe.txt
- CIopReadMe.txt
- README_README.txt
- READ_ME_!!!.TXT
Mutexes
- FFRRTTOOOTTPPWWZZZLLSS^-
- MakeMoneyFromAirEathWorld#666Go
- BestChangeT0pMoney^-666
API signature
- OpenPrinterW(L"KJFk23983ruafbuyTHFNIO#wu", 0, 0)
MITRE ATT&CK TTPs
The following MITRE ATT&CK techniques map directly to documented Clop behavior and can inform detection engineering, threat hunting, and security control validation.
| ID | Technique | Clop usage |
|---|---|---|
| T1190 | Exploit public-facing application | MOVEit Transfer, GoAnywhere MFT, Accellion FTA, Cleo platforms, Oracle E-Business Suite |
| T1505.003 | Web shell | DEWMODE deployed during the Accellion FTA campaign |
| T1059.001 | PowerShell | Automated file discovery and data staging scripts |
| T1567.002 | Exfiltration over web service | Rclone transfers to cloud storage buckets |
| T1486 | Data encrypted for impact | .clop and variant extensions appended to target files |
Detection and prevention
Effective defense against Clop requires controls distributed across every phase of the attack chain. No single control is sufficient: the group has consistently demonstrated the ability to subvert endpoint security tools, exploit trusted software, and compromise backup infrastructure. Organizations that rely on point-in-time controls alone remain exposed.
As Amr Fathy, Senior DFIR Engineer at Proven Data, notes: "Compliance is a point-in-time checkbox. We have worked cases where organizations passed HIPAA audits but had unpatched VPN appliances with known critical CVEs or had exposed RDP to the internet. Compliance tells you what you should do; security is what you actually do daily."
Security checklist
- Audit and patch all managed file transfer platforms immediately, including GoAnywhere, MOVEit Transfer, Cleo Harmony, VLTrader, and LexiCom.
- Treat edge devices (firewalls, VPN concentrators, file-transfer portals, and remote access gateways) as high-risk nodes requiring rapid patching, deep logging, and continuous monitoring with strong administrative access controls.
- Conduct a daily privileged-access review covering new and stale administrator accounts, service accounts, OAuth consent grants, backup-console access, and RMM agent activity. Most Clop investigations eventually become identity investigations.
- Deploy EDR or XDR solutions with kernel-level visibility, behavioral detection for process injection and driver-based security tool bypass, and alert correlation for encoded PowerShell correlated with surrounding process activity.
- Maintain offline or immutable backups and test recovery under operational conditions regularly. Protect backup control-plane credentials with the same rigor applied to backup data itself; control-plane compromise can render immutable storage ineffective.
- Implement egress filtering on file-transfer systems to detect and block unauthorized outbound connections to cloud storage destinations.
For guidance on identifying ransomware activity earlier in the attack chain, see how to detect ransomware.
Incident response immediate steps
A suspected Clop intrusion requires a different response posture than a conventional ransomware incident. Because the group routinely exfiltrates data weeks before any visible payload is deployed, responders should treat network log history, not encrypted files, as the primary evidence source. Organizations that focus only on restoring systems risk missing the full scope of data exposure.
Immediate actions
- Isolate affected systems from the network. Preserve forensic artifacts before initiating any recovery or shutdown procedures that could overwrite evidence.
- Analyze network logs for exfiltration activity beginning weeks or months prior to the first visible indicator. The encryption event is rarely the starting point of the intrusion.
- Immediately cycle all API keys, cloud storage tokens, service-account credentials, and domain passwords accessible within compromised systems or applications.
- Do not make ransom-related decisions before engaging a qualified DFIR specialist. Payment does not guarantee that stolen data will not be published or transferred to additional actors.
Proven Data's incident response team provides 24/7 emergency response for active ransomware incidents, including forensic investigation, containment, and breach notification support.


Written by
Amr Fathy is a dedicated cybersecurity professional with over 7 years of extensive experience in digital forensics, incident response, reverse engineering, and threat intelligence. He currently serves as Senior DFIR Engineer at Proven Data LLC, conducting triage collection, incident response, and digital forensics activities.






