Skip to main content
Mallory
Financially Motivated43 malware familiesExploits CVEs in the wild

TA505

Also known asCHIMBORAZOcl0pcl0p_(kta080)cl0p_branded_extortion_operationscl0p_cybercrime_groupcl0p_extortion_gangcl0p_gangcl0p_ransomware_crewcl0p_ransomware_gangcl0p_ransomware_groupcl0p_ransomware_operationcl0p_syndicatecl0p_teamcl0p^_leaksclopclop_crewclop_cybercrime_groupclop_cybercriminal_gangclop_extortion_gangclop_extortion_groupclop_gangclop_ransomwareclop_ransomware_and_data_extortion_groupclop_ransomware_gangclop_ransomware_operationclop_ransomware_teamgold_tahoeGRACEFUL SPIDERHive0065MONTY SPIDERSpandex TempestTA505

TA505 is a financially motivated cybercrime threat actor active since at least 2014. The content links TA505 with aliases and related tracking names including Cl0p/Clop, FIN11, Hive0065, Lace Tempest, DEV-0950, Graceful Spider, Gold Tahoe, Monty Spider, Spandex Tempest, and Chimborazo. The reporting also states that FIN11 is part of the larger TA505 group. The actor has historically conducted malicious spam and spear-phishing campaigns and has delivered malware including Dridex, TrickBot, Locky, Clop/Cryptomix, MINEBRIDGE, FlawedGrace, and SDBbot. IBM X-Force linked Hive0065/TA505 to enterprise intrusions using phishing emails impersonating Onehub and HR representatives, malicious Word documents with VBA macros, spoofed cloud-storage infrastructure, custom DLL droppers with Cobalt Strike-like code, Meterpreter components, and SDBbot as a second-stage RAT. SDBbot is described as supporting remote command execution, video recording, data exfiltration, and delivery of additional payloads. The content states TA505 has carried out targeted attacks across North America, Asia, Africa, and South America. Reported targets over time include industries such as finance, retail, and restaurants, and some COVID-19-themed campaigns targeted healthcare organizations. More recent reporting ties the actor’s Clop-branded operations to mass data-theft and extortion campaigns against organizations using managed file transfer products. Tradecraft directly mentioned in the content includes use of cmd.exe and JavaScript for execution; PowerShell to download and execute malware and reconnaissance scripts; password-protected malicious Word documents; credential theft from Internet Explorer, FTP clients, and Outlook; malware to disable Windows Defender; and use of tools including AdFind, BloodHound, Mimikatz, PowerSploit, and PingCastle. In observed intrusions, operators escalated privileges, compromised domain admin accounts, moved laterally, established persistence via registry Run keys and scheduled task abuse, and used spoofed domains and cloud-hosted malware delivery. The content repeatedly associates TA505/Clop with ransomware and extortion operations. Clop is described as a ransomware operation whose favored malware emerged in 2019 and which began operations in March 2019 using a CryptoMix variant. Reporting states that since 2020 Clop has specialized in exploiting previously unknown vulnerabilities in secure file transfer platforms for large-scale data theft and delayed extortion, often emphasizing pure extortion over encryption. The content specifically links Clop/TA505 to exploitation of Accellion FTA in 2020, SolarWinds Serv-U CVE-2021-35211 in 2021, GoAnywhere MFT in 2023, MOVEit Transfer CVE-2023-34362 in 2023, Oracle EBS-related activity in 2025, and Cleo Harmony/VLTrader/LexiCom vulnerabilities CVE-2024-50623 and CVE-2024-55956. In these campaigns, the actor used webshells or backdoors to enumerate and steal files, extract credentials or Azure Blob storage secrets, and extort victims via the Clop leak site. The content also notes Clop’s use of double-extortion and extortion-only models, with Cisco Talos stating Clop primarily focused on extortion through data theft rather than encryption and was one of the few ransomware actors exploiting zero-day vulnerabilities. Additional reporting in the content describes use of Cobalt Strike via PowerShell, abuse of the RegIdleBackup scheduled task to load FlawedGrace RAT, and broad opportunistic exploitation of exposed MOVEit systems affecting hundreds of organizations.

Share:
Are they targeting you?

Know when an actor pivots toward your sector

Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.

MITRE ATT&CK

Tradecraft

57 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.

15 of 15 tactics80 techniques×N= number of intelligence reports citing this technique
MITRE ATT&CK
TA0043
Reconnaissance
2 techniques
T1592
Gather Victim Host Information
T1598
Phishing for Information
TA0042
Resource Development
2 techniques
T1583
Acquire Infrastructure
T1588
Obtain Capabilities
T1588.002
Tool
TA0001
Initial Access
3 techniques
T1078×3
Valid Accounts
T1190×10
Exploit Public-Facing Application
T1566
Phishing
T1566.001×4
Spearphishing Attachment
T1566.003
Spearphishing via Service
TA0002
Execution
4 techniques
T1047
Windows Management Instrumentation
T1059
Command and Scripting Interpreter
T1059.001×5
PowerShell
T1059.003×4
Windows Command Shell
T1059.005×2
Visual Basic
T1059.007×2
JavaScript
T1203×2
Exploitation for Client Execution
T1204
User Execution
T1204.002×2
Malicious File
TA0003
Persistence
5 techniques
T1078×3
Valid Accounts
T1112×3
Modify Registry
T1505
Server Software Component
T1505.003
Web Shell
T1543
Create or Modify System Process
T1543.003
Windows Service
T1547
Boot or Logon Autostart Execution
T1547.001×2
Registry Run Keys / Startup Folder
T1547.009
Shortcut Modification
TA0004
Privilege Escalation
4 techniques
T1055
Process Injection
T1055.001
Dynamic-link Library Injection
T1078×3
Valid Accounts
T1543
Create or Modify System Process
T1543.003
Windows Service
T1547
Boot or Logon Autostart Execution
T1547.001×2
Registry Run Keys / Startup Folder
T1547.009
Shortcut Modification
TA0005
Stealth
8 techniques
T1027
Obfuscated Files or Information
T1027.002
Software Packing
T1036
Masquerading
T1055
Process Injection
T1055.001
Dynamic-link Library Injection
T1070
Indicator Removal
T1070.004
File Deletion
T1078×3
Valid Accounts
T1140
Deobfuscate/Decode Files or Information
T1218
System Binary Proxy Execution
T1218.007
Msiexec
T1218.011
Rundll32
T1497
Virtualization/Sandbox Evasion
T1497.003
Time Based Checks
TA0112
Defense Impairment
2 techniques
T1112×3
Modify Registry
T1553
Subvert Trust Controls
T1553.002
Code Signing
TA0006
Credential Access
2 techniques
T1003
OS Credential Dumping
T1555
Credentials from Password Stores
T1555.003
Credentials from Web Browsers
TA0007
Discovery
7 techniques
T1018
Remote System Discovery
T1033
System Owner/User Discovery
T1046
Network Service Discovery
T1069
Permission Groups Discovery
T1082×2
System Information Discovery
T1087
Account Discovery
T1497
Virtualization/Sandbox Evasion
T1497.003
Time Based Checks
TA0008
Lateral Movement
1 technique
T1021
Remote Services
T1021.002
SMB/Windows Admin Shares
TA0009
Collection
3 techniques
T1074
Data Staged
T1213
Data from Information Repositories
T1560
Archive Collected Data
TA0011
Command and Control
3 techniques
T1071
Application Layer Protocol
T1071.001×3
Web Protocols
T1105×3
Ingress Tool Transfer
T1219
Remote Access Tools
TA0010
Exfiltration
2 techniques
T1041×3
Exfiltration Over C2 Channel
T1537×2
Transfer Data to Cloud Account
TA0040
Impact
5 techniques
T1485
Data Destruction
T1486×7
Data Encrypted for Impact
T1489
Service Stop
T1490
Inhibit System Recovery
T1657
Financial Theft
ARSENAL

Associated malware families

43 malware families attributed to this actor across reporting.

FamilyContextEvidenceLast seen
ClopThe most notorious among these are campaigns involving banking Trojans such as Dridex and TrickBot, ransomware such as Clop/Cryptomix and MINEBRIDGE...20May 26, 2026
DridexThe most notorious among these are campaigns involving banking Trojans such as Dridex and TrickBot... More recent Hive0065 campaigns reported in March 2020 exploited the current interest in the COVID-19 pandemic, using Coronavirus-themed phishing emails to deliver the Locky ransomware and the Dridex banking Trojan.7May 26, 2026
LockyMore recent Hive0065 campaigns reported in March 2020 exploited the current interest in the COVID-19 pandemic, using Coronavirus-themed phishing emails to deliver the Locky ransomware and the Dridex banking Trojan.7May 26, 2026
Cobalt StrikeDetects the PowerShell pattern used at the end of a Cobalt Strike PowerShell loader to perform the decompression of the executable. This loader is used in attacks such as scripted web delivery. Cobalt Strike is a legitimate, commercial penetration testing tool that has been largely co-opted by ransomware gangs to launch attacks. Cobalt Strike's popularity is mainly due to its beacons or payload being stealthy, and easily customizable. Cobalt Strike Beacon provides encrypted communication with the C&C server to send information and receive commands.6May 6, 2026
LemurlootIn May 2023, a widespread SQL injection attack targeted MOVEit, a widely used file-transfer service. The attacks, attributed to the Russian-speaking cybercrime group Clop, compromised multiple global organizations... Attackers exploited a critical vulnerability, installing a custom webshell called "LemurLoot" to rapidly access and exfiltrate large volumes of data.5May 26, 2026

38 additional families tracked in Mallory.

WEAPONIZED

Associated vulnerabilities

12 CVEs this actor has used in observed campaigns. 12 of them exploited in the wild.

CVE-2025-61882Unauthenticated RCE in Oracle E-Business Suite Concurrent Processing BI Publisher IntegrationIn the wildEvidence26

The patch arrived just one week after Oracle released an emergency fix for CVE-2025-61882, a critical remote code execution flaw that the Cl0p ransomware gang exploited as a zero-day in a mass data theft campaign beginning in August.

CVE-2023-34362SQL Injection in Progress MOVEit TransferIn the wildEvidence20

On May 31st, Progress Software issued an advisory and patch for a vulnerability subsequently identified as CVE-2023-34362 and assigned a severity rating of 9.8 out of 10. The company stated the vulnerability “could lead to escalated privileges and potential unauthorized access to the environment.” In other words, it was a vulnerability which could enable hackers to access MOVEit and steal data – something which it later emerged had been happening since at least May 27th.

CVE-2023-0669Pre-authentication RCE in Fortra GoAnywhere MFT License Response ServletIn the wildEvidence6

In late January 2023, the CL0P ransomware group launched a campaign using a zero-day vulnerability, now catalogued as CVE-2023-0669, to target the GoAnywhere MFT platform.

CVE-2024-50623Unauthenticated unrestricted file upload/download leading to RCE in Cleo Harmony, VLTrader, and LexiComIn the wildEvidence4

In October, Cleo disclosed a vulnerability tracked as CVE-2024-50623 that allowed unrestricted file uploads and downloads, leading to remote code execution... CISA confirmed that the critical CVE-2024-50623 security vulnerability in Cleo Harmony, VLTrader, and LexiCom file transfer software has been exploited in ransomware attacks.

CVE-2024-55956Unauthenticated command injection in Cleo Harmony, VLTrader, and LexiCom Autorun handlingIn the wildEvidence4

The new vulnerability used in the December attacks is now tracked as CVE-2024-55956 and is fixed in Cleo Harmony, VLTrader, and LexiCom 5.8.0.24. While exploiting this vulnerability, the threat actors uploaded a JAVA backdoor dubbed 'Malichus'... Clop confirmed they are behind the recent exploitation of the Cleo CVE-2024-55956 vulnerability.

7 more CVEs tied to this actor tracked in Mallory.

IOCS

Observables

293 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.

IOC values are gated. View more in Mallory for domains, IPs, hashes, and other artifacts, or pipe them straight into your SIEM.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: sector and geo overlap with your footprint, the IOCs they’re burning right now, detection coverage, and what to do next.
Target overlap

Match sector + geo + tech-stack targeting against your real footprint.

Tradecraft mapping57

Every observed MITRE ATT&CK technique, grouped by tactic.

Malware arsenal43

Families this actor is known to deploy, with IOCs and behavior.

Exploited CVEs12

CVEs this actor has used in known campaigns.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Observables293

Domains, IPs, and hashes tied to this actor, refreshed continuously.