TA505 is a financially motivated cybercrime threat actor associated with large-scale phishing, malware delivery, banking fraud, and later ransomware and data-extortion operations. The cluster is widely linked to the Cl0p ransomware and extortion ecosystem and is also tracked under aliases including Graceful Spider, Gold Tahoe, Hive0065, Monty Spider, Spandex Tempest, Chimborazo, and Clop/Cl0p. Some reporting also overlaps Cl0p-related activity with FIN11 and other vendor-specific designations, though alias mapping can vary by source. The actor is known for opportunistic, high-volume operations as well as targeted intrusions against enterprises. Historically, TA505 has used malspam and social-engineering campaigns to deliver malware families such as Dridex, FlawedAmmyy, Trick, and other loaders and backdoors, then monetized access through credential theft, fraud, lateral movement, and deployment of ransomware. In more recent years, activity associated with the Cl0p branch has emphasized data theft and double extortion, often prioritizing exfiltration from high-value enterprise systems over disruptive encryption alone. A defining characteristic of the Cl0p-linked activity is repeated exploitation of zero-day and n-day vulnerabilities in widely deployed enterprise file transfer, managed file transfer, and business application platforms. Public reporting has tied the group or its affiliates to mass exploitation campaigns involving Accellion FTA, GoAnywhere MFT, MOVEit Transfer, Cleo software, Oracle E-Business Suite, and PTC Windchill and FlexPLM. These campaigns typically focus on stealing sensitive business data at scale and then pressuring victims through extortion emails and leak-site exposure. Observed tradecraft includes exploitation of public-facing applications, deployment of web shells, use of valid accounts, filesystem enumeration, staging and exfiltration of sensitive data, and broad internal pressure tactics such as emailing large numbers of employees from compromised accounts. In PTC Windchill and FlexPLM intrusions reported in 2026, Cl0p-linked affiliates were observed chaining application flaws to achieve unauthenticated remote code execution, deploying server-side web shells, harvesting sensitive engineering and product-development data, and conducting extortion against organizations in manufacturing, automotive, aerospace, and retail. Similar tactics were reported in Oracle E-Business Suite campaigns focused on theft of customer and HR-related data. Victimology is broad but consistently favors organizations holding valuable operational, financial, customer, or intellectual-property data. Manufacturing, retail, professional services, transportation, healthcare, technology, and large multinational enterprises have all been affected. The actor is not considered a nation-state threat actor; it is best characterized as a mature eCrime operation or ecosystem with affiliate-driven elements, strong operational tempo, and a demonstrated ability to rapidly weaponize newly disclosed vulnerabilities for mass victimization. TA505 and its Cl0p-associated operations remain notable for combining scalable intrusion methods with enterprise-focused extortion, making the group one of the most consequential financially motivated threat clusters in the ransomware and data-theft landscape.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
28 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
43 malware families attributed to this actor across reporting.
38 additional families tracked in Mallory.
15 CVEs this actor has used in observed campaigns. 15 of them exploited in the wild.
The timing of the intrusion coincides with a broader hacking campaign that targeted Oracle E-Business Suite systems through a vulnerability tracked as CVE-2025-61882. Google and Mandiant researchers reported in October 2025 that the Cl0p extortion group had exploited that flaw, along with other Oracle E-Business Suite vulnerabilities, to steal data from multiple organizations in August 2025. The vulnerability allowed attackers without valid credentials to execute code remotely over HTTP on systems running Oracle E-Business Suite versions 12.2.3 through 12.2.14. Oracle issued a patch addressing CVE-2025-61882 on October 4, 2025.
The most significant incident was the 2023 MOVEit Transfer zero day (CVE-2023-34362), a SQL injection vulnerability exploited by the CL0P/TA505 ransomware group beginning May 27, 2023, before Progress disclosed it on May 31, 2023.
Zraniteľnosť CVE-2024-55956 možno zneužiť na získanie neoprávneného prístupu k citlivým údajom, vykonanie neoprávnených zmien v systéme a vzdialené vykonanie kódu... V súčasnosti je dostupný Proof of Concept (PoC)... Zraniteľnosť aktívne zneužívajú útočníci minimálne od 3. decembra 2024. Ransomvérová skupina CLOP ju v rámci útokov zneužíva na krádež citlivých údajov.
Spoločnosť Oracle vydala bezpečnostnú aktualizáciu na svoj produkt E-Business Suite, ktorá opravuje vysoko závažnú zraniteľnosť. CVE-2025-61884 by vzdialený neautentifikovaný útočník zaslaním špeciálne vytvorených HTTP požiadaviek mohol zneužiť na kompromitáciu Oracle Configurator a získanie neoprávneného prístupu k citlivým údajom. [aktualizácia 21.10.2025] zraniteľnosť CVE-2025-61884 bola pridaná do zoznamu aktívne zneužívaných
In late January 2023, the CL0P ransomware group launched a campaign using a zero-day vulnerability, now catalogued as CVE-2023-0669, to target the GoAnywhere MFT platform.
10 more CVEs tied to this actor tracked in Mallory.
445 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Cl0p affiliate is reportedly exploiting CVE-2026-12569 in PTC Windchill/FlexPLM to gain remote code execution, deploy JSP webshells, enumerate filesystems, stage and exfiltrate data, and send extortion emails to impacted organizations.
A ransomware/extortion group whose Italian victim claims were linked to a mass-exploitation campaign against Oracle E-Business Suite.
Ransomware group that ran a concentrated campaign in January-February using large-scale zero-day exploitation.
Actively exploiting CVE-2026-12569 in PTC Windchill and FlexPLM to gain unauthenticated remote code execution, deploy persistent JSP web shells, steal sensitive product data, harvest LDAP credentials, exfiltrate data, and conduct extortion campaigns.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.