Cl0p is a ransomware family and criminal extortion operation associated with the FIN11 ecosystem and also tracked under names including Graceful Spider, Chubby Scorpius, and Lace Tempest. It is known for large-scale exploitation of high-value enterprise software vulnerabilities, especially in internet-exposed file-transfer, application, and business platforms, followed by theft of sensitive data and extortion. In multiple campaigns, Cl0p operators or affiliates have favored data-theft extortion over widespread file encryption, using stolen information as leverage and pressuring victims with direct outreach and threatened public disclosure.
Cl0p has been linked to mass exploitation campaigns against enterprise products including MOVEit Transfer, Cleo software, Oracle E-Business Suite, and PTC Windchill and FlexPLM. In the Windchill and FlexPLM activity observed in 2026, affiliates exploited a critical unauthenticated remote code execution flaw, in some cases chaining it with a pre-authentication information-disclosure weakness, then deployed JSP web shells for persistent remote access and command execution. Post-compromise activity included filesystem enumeration, staging of engineering and product-design data, extraction of credentials from application stores, exfiltration, and subsequent extortion emails sent at scale to employees within affected organizations. Reported targeting in that campaign included aerospace, automotive, manufacturing, and retail or apparel organizations, reflecting Cl0p’s focus on repositories containing valuable intellectual property and business-sensitive records.
The malware and its operators exhibit typical ransomware and post-exploitation tradecraft, including persistence through web shells, reconnaissance of victim environments, data theft, and defense-evasion checks. Cl0p has been observed modifying Windows Registry settings, checking keyboard layout and language to avoid execution on Russian-language and other CIS-language systems, and searching for antivirus or antimalware-related processes before proceeding. A Linux ELF variant has also been documented, showing that the family is not limited to Windows environments. That Linux variant used RC4-based file encryption logic similar in overall structure to the Windows branch, although it was assessed as less mature and contained implementation flaws that enabled decryption without paying.
Cl0p is best understood as both a ransomware family and a mature extortion brand within the ransomware-as-a-service ecosystem. Its campaigns consistently emphasize exploitation of public-facing enterprise applications, rapid monetization of stolen data, and pressure tactics aligned with double extortion rather than reliance on encryption alone.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
18 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
A critical remote code execution vulnerability in PTC Windchill and FlexPLM, tracked as CVE-2026-12569, is being actively exploited by Clop ransomware affiliates to steal sensitive product data.
A critical remote code execution vulnerability in PTC Windchill and FlexPLM, tracked as CVE-2026-12569 (CVSS 9.8), is being actively exploited by Clop ransomware affiliates to steal sensitive product data. | A critical remote code execution vulnerability in PTC Windchill and FlexPLM, tracked as CVE-2026-12569, is being actively exploited by Clop ransomware affiliates to steal sensitive product data.
Spoločnosť Oracle vydala bezpečnostnú aktualizáciu na svoj produkt E-Business Suite, ktorá opravuje vysoko závažnú zraniteľnosť. CVE-2025-61884 by vzdialený neautentifikovaný útočník zaslaním špeciálne vytvorených HTTP požiadaviek mohol zneužiť na kompromitáciu Oracle Configurator a získanie neoprávneného prístupu k citlivým údajom. [aktualizácia 21.10.2025] zraniteľnosť CVE-2025-61884 bola pridaná do zoznamu aktívne zneužívaných
Zraniteľnosť CVE-2024-55956 možno zneužiť na získanie neoprávneného prístupu k citlivým údajom, vykonanie neoprávnených zmien v systéme a vzdialené vykonanie kódu... V súčasnosti je dostupný Proof of Concept (PoC)... Zraniteľnosť aktívne zneužívajú útočníci minimálne od 3. decembra 2024. Ransomvérová skupina CLOP ju v rámci útokov zneužíva na krádež citlivých údajov.
The timing of the intrusion coincides with a broader hacking campaign that targeted Oracle E-Business Suite systems through a vulnerability tracked as CVE-2025-61882. Google and Mandiant researchers reported in October 2025 that the Cl0p extortion group had exploited that flaw, along with other Oracle E-Business Suite vulnerabilities, to steal data from multiple organizations in August 2025. The vulnerability allowed attackers without valid credentials to execute code remotely over HTTP on systems running Oracle E-Business Suite versions 12.2.3 through 12.2.14. Oracle issued a patch addressing CVE-2025-61882 on October 4, 2025.
A critical vulnerability in Oracle E-Business Suite (EBS), tracked as CVE-2026-46817 (CVSS 9.8), is being actively exploited in the wild. The flaw resides in the File Transmission component of Oracle Payments and allows an unauthenticated attacker with HTTP network access to take over vulnerable systems.
ICYMI: Catch-up on events relating to the MOVEit data breach so far: ... MOVEit Data Breach [CVE-2023-34362]
Oracle published a security advisory about a vulnerability (CVE-2026-35273) in PeopleSoft, specifically in the Enterprise PeopleTools, versions 8.61 and 8.62. There is credible intelligence that this vulnerability is being actively exploited in the wild, however there is no publicly available proof-of-concept (PoC).
A remote code execution vulnerability (CVE-2021-35211) affecting SolarWinds Serv-U software has previously been exploited as a zero-day by suspected Chinese attackers for cyber espionage purposes, and later by the Cl0p ransomware outfit.
PaperCut servers have been previously breached by ransomware gangs in 2023 by exploiting a critical, unauthenticated remote code execution (RCE) vulnerability (CVE–2023–27350)... One month later, CISA and the FBI issued a joint advisory warning that the Bl00dy Ransomware gang had also begun exploiting the CVE-2023–27350 RCE vulnerability to gain initial access to the networks of educational organizations.
PaperCut servers have been previously breached by ransomware gangs in 2023 by exploiting a critical, unauthenticated remote code execution (RCE) vulnerability (CVE–2023–27350) and a high-severity information disclosure flaw (CVE–2023–27351).
Cl0p Ransomware, aka Cl0p, is a ransomware group that emerged in February 2019 and targeted most industries worldwide, including retail, transportation, education, manufacturing, automotive, energy, financial, telecommunications and even healthcare. | Cl0p exploited a zero-day vulnerability in Cleo LexiCom, Cleo VLTrader, and Cleo Harmony products to steal data. The vulnerability, tracked as CVE-2024-50623, enables remote file uploads and downloads, leading to remote code execution. A fix has been released for affected Cleo products (version 5.8.0.21), but researchers have warned that the patch may be bypassed. Huntress disclosed the active exploitation of the vulnerability and provided a proof-of-concept to demonstrate its potential impact.
CL0P have utilized this tactic in the targeting of organizations using a vulnerable version of ‘Accellion FTA’, a file transfer appliance. As such, following vulnerabilities have reportedly been exploited to gain access to victim data as well as potentially pivoting into victim networks: CVE-2021-27101 – Critical SQL Injection via a crafted Host header in versions ≤9_12_370. | Cl0p Ransomware, aka Cl0p, is a ransomware group that emerged in February 2019 and targeted most industries worldwide, including retail, transportation, education, manufacturing, automotive, energy, financial, telecommunications and even healthcare.
CL0P have utilized this tactic in the targeting of organizations using a vulnerable version of ‘Accellion FTA’, a file transfer appliance. As such, following vulnerabilities have reportedly been exploited to gain access to victim data as well as potentially pivoting into victim networks: CVE-2021-27104 – Critical command execution via a crafted POST in versions ≤9_12_370. | Cl0p Ransomware, aka Cl0p, is a ransomware group that emerged in February 2019 and targeted most industries worldwide, including retail, transportation, education, manufacturing, automotive, energy, financial, telecommunications and even healthcare.
CL0P have utilized this tactic in the targeting of organizations using a vulnerable version of ‘Accellion FTA’, a file transfer appliance. As such, following vulnerabilities have reportedly been exploited to gain access to victim data as well as potentially pivoting into victim networks: CVE-2021-27102 – Command execution via a local web service call in versions ≤9_12_411. | Cl0p Ransomware, aka Cl0p, is a ransomware group that emerged in February 2019 and targeted most industries worldwide, including retail, transportation, education, manufacturing, automotive, energy, financial, telecommunications and even healthcare.
CL0P have utilized this tactic in the targeting of organizations using a vulnerable version of ‘Accellion FTA’, a file transfer appliance. As such, following vulnerabilities have reportedly been exploited to gain access to victim data as well as potentially pivoting into victim networks: CVE-2021-27103 – Critical server-side request forgery (SSRF) in versions ≤9_12_411. | Cl0p Ransomware, aka Cl0p, is a ransomware group that emerged in February 2019 and targeted most industries worldwide, including retail, transportation, education, manufacturing, automotive, energy, financial, telecommunications and even healthcare.
Cl0p is a type of ransomware that has been used in cyberattacks since 2019.
Cl0p is a type of ransomware that has been used in cyberattacks since 2019.
10 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Cl0p ransomware affiliates are exploiting exposed PTC Windchill and FlexPLM servers to steal engineering and product-design data.
Cl0p ransomware affiliates are exploiting exposed PTC Windchill and FlexPLM servers to steal engineering and product-design data.
Cl0p ransomware affiliates are exploiting exposed PTC Windchill and FlexPLM servers to steal engineering and product-design data.
Cl0p ransomware affiliates are exploiting exposed PTC Windchill and FlexPLM servers to steal engineering and product-design data.
the Oracle EBS platform has been under sustained, documented attack by the Cl0p ransomware group and suspected FIN11 operators throughout 2025 and into 2026
21 distinct techniques documented for this family, organized by ATT&CK tactic.
victims failing to meet their ransom demands are promptly ‘named and shamed’ on ‘CL0P^_- LEAKS’, the group’s Tor-hosted leak site... CL0P provide multiple contact email addresses as well as, more recently, a link to an online chat feature on their Tor hidden service
The access methods behind all this aren’t exotic. Reused credentials pulled from old breaches and dark web dumps, unpatched public-facing systems... CL0P’s four Italian claims in January and February trace directly back to its mass-exploitation campaign against Oracle E-Business Suite
During the 2016 Ukraine Electric Power Attack, Sandworm Team used the xp_cmdshell command in MS-SQL. During the 2025 Poland Wiper Attacks, the adversaries leveraged PsExec to run cmd.exe commands on multiple victim machines. Numerous malware families and groups are described as using cmd.exe, cmd /c, Windows command shell, or command-line interfaces to execute commands, payloads, reconnaissance, persistence, cleanup, and ransomware actions.
During the 2015 Ukraine Electric Power Attack, Sandworm Team modified in-registry Internet settings to lower internet security before launching rundll32.exe ... AADInternals can modify registry keys ... ADVSTORESHELL is capable of setting and deleting Registry values ... [many additional examples].
victims failing to meet their ransom demands are promptly ‘named and shamed’ on ‘CL0P^_- LEAKS’, the group’s Tor-hosted leak site... CL0P provide multiple contact email addresses as well as, more recently, a link to an online chat feature on their Tor hidden service
Then by using the RC4 “master-key” the ransomware encrypts the generated RC4 key and stores it to $filename.$clop_extension.
During the 2015 Ukraine Electric Power Attack, Sandworm Team modified in-registry Internet settings to lower internet security before launching rundll32.exe ... AADInternals can modify registry keys ... ADVSTORESHELL is capable of setting and deleting Registry values ... [many additional examples].
Initially, the ransomware creates a new process by calling fork and exits the parent-process. The child-process sets its file mode creation mask... It then calls setsid, creates a session and sets the process group ID.
The content repeatedly describes malware and threat actors listing files and directories, enumerating drives, searching for files by extension/name/path, retrieving file metadata, and browsing file systems (for example: "APT28 has used Forfiles to locate PDF, Excel, and Word documents during collection" and "cmd can be used to find files and directories with native functionality such as dir commands").
It tries to access root by changing the working directory to “/” (chdir(“/”)). Once the permissions are set, the ransomware proceeds encrypting other directories.
Adversaries may attempt to get a listing of security software, configurations, defensive tools, and sensors that are installed on a system or in a cloud environment.
Avaddon checks for specific keyboard layouts and OS languages to avoid targeting Commonwealth of Independent States (CIS) entities... Bazar can perform a check to ensure that the operating system's keyboard and language settings are not set to Russian... Clop has checked the keyboard language using the GetKeyboardLayout() function... Ryuk has been observed to query the registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Nls\Language and the value InstallLanguage.
the exfiltration of sensitive and valuable data prior to encryption... In addition to the wholesale theft of data from file servers and network storage devices... CL0P have repeatedly demonstrated their ability to gather large data stores including those used by database and email servers.
encrypt the data using the Windows CryptoAPI and then writing this encrypted data to a new file before the original is deleted.
A new report links 148 ransomware attacks to Italian organizations in H1 2026... Two groups dominate the leaderboard, tied at 21 claims apiece: LockBit5 and Qilin.
The earliest iteration we identified of the shared kill list was a batch script deployed alongside LockerGoga... Other iterations of the list we have observed are also hardcoded directly into the ransomware binaries.
Akira will delete system volume shadow copies via PowerShell commands. Avaddon deletes backups and shadow copies using native system tools. Babuk has the ability to delete shadow volumes using vssadmin.exe delete shadows /all /quiet. BlackCat can delete shadow copies using vssadmin.exe delete shadows /all /quiet and wmic.exe Shadowcopy Delete; it can also modify the boot loader using bcdedit /set {default} recoveryenabled No.
215 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
200 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware associated here with exploitation of a PTC Windchill/FlexPLM vulnerability to gain initial access, deploy JSP webshells, enumerate filesystems, stage and exfiltrate data, and send extortion emails.
A ransomware/extortion family notable in 2025 for large-scale exploitation of zero-day vulnerabilities and emphasis on data theft extortion rather than encryption.
Ransomware family whose affiliates are exploiting the Windchill/FlexPLM vulnerability to gain access, deploy persistent JSP web shells, exfiltrate sensitive product data, and conduct extortion.
Ransomware/extortion operation associated here with exploitation of internet-exposed PTC Windchill/FlexPLM systems to gain unauthenticated remote code execution, deploy JSP web shells, enumerate files, stage engineering and design data, and conduct double-extortion data theft.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.