TA505 is a prolific, financially motivated cybercrime threat actor widely associated with large-scale phishing, malware delivery, credential theft, data exfiltration, and ransomware or extortion operations. The group is commonly tracked under numerous aliases including TA505, Graceful Spider, Gold Tahoe, Hive0065, Spandex Tempest, Monty Spider, Chimborazo, and Cl0p or Clop when referring to the ransomware and extortion brand linked to its later operations. Reporting has also associated parts of the actor’s activity with FIN11-related operations, though the exact relationship between TA505, FIN11, and Cl0p branding is not always consistently delineated across vendors. TA505 has historically targeted a broad cross-section of organizations worldwide and is known for opportunistic, high-volume campaigns as well as more selective intrusions against enterprises with valuable data. In more recent activity, the actor has been linked to mass exploitation of enterprise software vulnerabilities for data theft and extortion, including major campaigns against managed file transfer and Oracle enterprise application environments. The group was prominently associated with exploitation of the MOVEit Transfer zero-day CVE-2023-34362, which enabled theft from thousands of organizations and fueled one of the largest data-theft and extortion campaigns on record. It has also been linked to exploitation of Oracle E-Business Suite vulnerabilities, including CVE-2025-61882, in campaigns that reportedly affected more than 100 organizations. The actor’s tradecraft includes rapid weaponization of newly disclosed or zero-day vulnerabilities, large-scale victim enumeration, unauthorized access to internet-facing enterprise applications, account compromise, bulk data exfiltration, and follow-on extortion. TA505 and its associated Cl0p-branded operations are notable for emphasizing data theft and extortion pressure, sometimes without relying on traditional encryption-based ransomware deployment. The group has also been associated with credential access, phishing-based initial access, and use of legitimate administrative functionality and other living-off-the-land techniques to advance intrusions and evade detection. TA505 is best understood as a mature cybercriminal intrusion and extortion ecosystem rather than a nation-state actor. Its operations demonstrate strong operational tempo, adaptability, and the ability to pivot from spam and malware distribution to vulnerability-driven enterprise compromise at scale. Security professionals most commonly recognize and search for this actor as TA505, while Cl0p is the most prominent associated extortion and ransomware brand tied to its later high-profile campaigns.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
55 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
44 malware families attributed to this actor across reporting.
39 additional families tracked in Mallory.
13 CVEs this actor has used in observed campaigns. 13 of them exploited in the wild.
Vulnerable Oracle products have been heavily targeted in the past, with a critical Oracle EBS flaw patched in October 2025, tracked as CVE-2025-61882, subjected to attacks by the Clop ransomware gang.
The most significant incident was the 2023 MOVEit Transfer zero day (CVE-2023-34362), a SQL injection vulnerability exploited by the CL0P/TA505 ransomware group beginning May 27, 2023, before Progress disclosed it on May 31, 2023.
In late January 2023, the CL0P ransomware group launched a campaign using a zero-day vulnerability, now catalogued as CVE-2023-0669, to target the GoAnywhere MFT platform.
TA505 (Clop) is one of the oldest groups, active since 2019... It has been exploiting the Cleo zero-day vulnerability (CVE-2024–55956) since late 2024, which makes it the most active of all groups in the first half of 2025.
In the months prior, Oracle issued emergency patches for E-Business Suite vulnerabilities (CVE-2025-61882, CVE-2025-61884) after active exploitation by groups such as Cl0p.
8 more CVEs tied to this actor tracked in Mallory.
427 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as a ransomware group that previously exploited a different Oracle EBS vulnerability (CVE-2025-61882) in a campaign affecting more than 100 organizations.
Referenced only as a comparison point for the sophistication of GoldenEyeDog.
Mentioned only as background comparison for a prior Oracle-focused campaign.
Referenced as an extortion-motivated group that previously exploited a separate Oracle E-Business Suite vulnerability for mass data theft and extortion.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.