01
Clop is tracked as an affiliate-enabled ransomware service.1,3
The brand supplies shared capabilities, but affiliates can change access methods and tooling; incident scoping should follow observed behavior rather than assume one fixed playbook.
CARDS
Clop is a financially motivated cybercriminal group that emerged in February 2019 as a variant of the CryptoMix ransomware, rapidly evolving into a Ransomware-as-a-Service (RaaS) operation. Initially, the group combined data encryption with exfiltration to execute double extortion campaigns, threatening to publish stolen information on their dedicated leak site if ransoms were not paid. Over time, Clop transitioned to a primarily "encryption-less" extortion model, focusing solely on large-scale data theft via exploiting zero-day vulnerabilities in Managed File Transfer solutions to maximize profits and bypass traditional endpoint defenses. The group is assessed with high confidence to be of Russian-speaking origin, with its malware designed to avoid execution on systems within Commonwealth of Independent States (CIS) countries. Clop is closely associated with the threat groups TA505 and FIN11, and has gained notoriety for its distinct strategy of conducting widespread supply chain attacks by targeting widely used enterprise software.
Directory Briefing
01
The brand supplies shared capabilities, but affiliates can change access methods and tooling; incident scoping should follow observed behavior rather than assume one fixed playbook.
02
The retained behavior points to credentials, remote access, phishing, or exposed services; preserve authentication, VPN, edge-device, email, and remote-administration evidence together.
03
Check for earlier credential use, remote sessions, administrative changes, and data access because public actor records often understate the full pre-impact timeline.
04
Evidence includes credential or account abuse; response should cover privileged, service, remote-access, SaaS, and recovery identities—not just interactive user passwords.
05
Lateral movement, administrative access, and shared server infrastructure can turn a limited foothold into broad business interruption.
06
Reported tooling or behavior includes PowerShell, remote execution, or other dual-use administration behavior; detection must distinguish authorized administration from anomalous context and sequence.
07
Defense impairment or evidence removal is retained in the source record. Protect immutable backups and investigate access to recovery systems before trusting them.
08
Collection or exfiltration behavior includes data staging and exfiltration; counsel and forensics need a shared record of what was accessed, staged, and transferred.
09
Retained targeting includes Construction of Buildings, Food Manufacturing, Other Information Services, Rail Transportation, and Software Publishers across United Arab Emirates, Argentina, Austria, and Australia; translate those sectors into the organization's exposed systems and high-value data.
10
Align counsel, forensics, identity, recovery, insurance, communications, and regulatory analysis around one compromise timeline and one evidence-preservation plan.
Bottom Line Up Front
The brand supplies shared capabilities, but affiliates can change access methods and tooling; incident scoping should follow observed behavior rather than assume one fixed playbook.
The retained behavior points to credentials, remote access, phishing, or exposed services; preserve authentication, VPN, edge-device, email, and remote-administration evidence together.
Check for earlier credential use, remote sessions, administrative changes, and data access because public actor records often understate the full pre-impact timeline.
Evidence includes credential or account abuse; response should cover privileged, service, remote-access, SaaS, and recovery identities—not just interactive user passwords.
Lateral movement, administrative access, and shared server infrastructure can turn a limited foothold into broad business interruption.
Reported tooling or behavior includes PowerShell, remote execution, or other dual-use administration behavior; detection must distinguish authorized administration from anomalous context and sequence.
Defense impairment or evidence removal is retained in the source record. Protect immutable backups and investigate access to recovery systems before trusting them.
Collection or exfiltration behavior includes data staging and exfiltration; counsel and forensics need a shared record of what was accessed, staged, and transferred.
Retained targeting includes Construction of Buildings, Food Manufacturing, Other Information Services, Rail Transportation, and Software Publishers across United Arab Emirates, Argentina, Austria, and Australia; translate those sectors into the organization's exposed systems and high-value data.
Align counsel, forensics, identity, recovery, insurance, communications, and regulatory analysis around one compromise timeline and one evidence-preservation plan.
Decision Context
Clop is a financially motivated cybercriminal group that emerged in February 2019 as a variant of the CryptoMix ransomware, rapidly evolving into a Ransomware-as-a-Service (RaaS) operation. Initially, the group combined data encryption with exfiltration to execute double extortion campaigns, threatening to publish stolen information on their dedicated leak site if ransoms were not paid. Over time, Clop transitioned to a primarily "encryption-less" extortion model, focusing solely on large-scale data theft via exploiting zero-day vulnerabilities in Managed File Transfer solutions to maximize profits and bypass traditional endpoint defenses. The group is assessed with high confidence to be of Russian-speaking origin, with its malware designed to avoid execution on systems within Commonwealth of Independent States (CIS) countries. Clop is closely associated with the threat groups TA505 and FIN11, and has gained notoriety for its distinct strategy of conducting widespread supply chain attacks by targeting widely used enterprise software.1,3,2
Actor Card Detail
Victimology
No named victim organizations are retained in the cited source artifacts for this profile. Countries and sectors are targeting context, not victim identities.
Identity
Targeting
Target Countries / Exposure1,2
Campaign Context
| Campaign / Operation | Source-Backed Context |
|---|---|
| Cl0p MOVEit Transfer Mass Exploitation4,10,11,3 | Cl0p MOVEit Transfer Mass Exploitation is retained in the campaign database for Cl0p. CISA and the FBI assess that the CL0P ransomware gang began exploiting the then-zero-day SQL injection vulnerability CVE-2023-34362 in Progress MOVEit Transfer on or about May 27, 2023. Public reporting describes exploitation of internet-facing managed-file-transfer applications, deployment of the LEMURLOOT web shell, data theft, and extortion pressure. The operational response is to scope the actual server, account, file-transfer, and data-access evidence; public victim and leak-site claims are not proof of compromise on their own. |
Indicators
SOCRadar reports 10502 IOCs for this profile. IntelliOS currently retains 56 cited public observable/context rows; this is not the full possible public-source IOC corpus.
Source coverage: 10 source groups tracked; 8 currently contribute retained observable or context rows.
Retained Observables
Showing 58 of 58
| Type | Value | Source |
|---|---|---|
| SHA-256 Hash | 0b3220b11698b1436d1d866ac07cc90018e59884e91a8cb71ef8924309f1e0e94 | CISA AA23-158A |
| SHA-256 Hash | 0e3a14638456f4451fe8d76fdc04e591fba942c2f16da31857ca66293a58a4c34 | CISA AA23-158A |
| SHA-256 Hash | 0ea05169d111415903a1098110c34cdbbd390c23016cd4e179dd9ef5071044954 | CISA AA23-158A |
| SHA-256 Hash | 110e301d3b5019177728010202c8096824829c0b11bb0dc0bff55547ead182864 | CISA AA23-158A |
| SHA-256 Hash | 1826268249e1ea58275328102a5a8d158d36b4fd312009e4a2526f0bfbc30de24 | CISA AA23-158A |
| SHA-256 Hash | 3a977446ed70b02864ef8cfa3135d8b134c93ef868a4cc0aa5d3c2a74545725b4 | CISA AA23-158A |
| SHA-256 Hash | 48367d94ccb4411f15d7ef9c455c92125f3ad812f2363c4d2e949ce1b615429a4 | CISA AA23-158A |
| SHA-256 Hash | 98a30c7251cf622bd4abce92ab527c3f233b817a57519c2dd2bf8e3d3ccb7db84 | CISA AA23-158A |
| SHA-256 Hash | d5bbcaa0c3eeea17f12a5cc3dbcaffff423d00562acb694561841bcfe984a3b74 | CISA AA23-158A |
| SHA-256 Hash | eb9f5cbe71f9658d38fb4a7aa101ad40534c4c93ee73ef5f6886d89159b0e2c24 | CISA AA23-158A |
| SHA-256 Hash | fe5f8388ccea7c548d587d1e2843921c038a9f4ddad3cb03f3aa8a45c29c6a2f4 | CISA AA23-158A |
| Filename | human2.aspx4 | CISA AA23-158A |
| Filename | larabqFa.exe4 | CISA AA23-158A |
| Filename | Qboxdv.dll4 | CISA AA23-158A |
| Filename | update.jsp4 | CISA AA23-158A |
| Filename | Zoom.exe4 | CISA AA23-158A |
| Filename | ZoomInstaller.exe4 | CISA AA23-158A |
| Tool / Process | Cleo Harmony / VLTrader / LexiCom8 | ZeroFox |
| Tool / Process | Fortra GoAnywhere MFT7 | NVD |
| Tool / Process | MOVEit Transfer4 | CISA AA23-158A |
| CVE | CVE-2023-06697 | NVD |
| CVE | CVE-2023-343624 | CISA AA23-158A |
| CVE | CVE-2023-3436210 | NVD |
| CVE | CVE-2024-506239 | SecurityWeek |
| CVE | CVE-2024-559569 | SecurityWeek |
| Alias / Related Name | DEV-09506 | Canadian Centre |
| Alias / Related Name | FIN116 | Canadian Centre |
| Alias / Related Name | Lace Tempest6 | Canadian Centre |
| Alias / Related Name | TA5056 | Canadian Centre |
| Alias / Related Name | TA5053 | MITRE |
| Malware Family | LEMURLOOT4 | CISA AA23-158A |
| Network Indicator | http://connectzoomdownload.com/download/ZoomInstaller.exe4 | CISA AA23-158A |
| Network Indicator | http://guerdofest.com/gate.php4 | CISA AA23-158A |
| Network Indicator | http://hiperfdhaus.com4 | CISA AA23-158A |
| Network Indicator | http://jirostrogud.com4 | CISA AA23-158A |
| Network Indicator | http://qweastradoc.com4 | CISA AA23-158A |
| Network Indicator | http://qweastradoc.com/gate.php4 | CISA AA23-158A |
| Network Indicator | http://zoom.voyage/download/Zoom.exe4 | CISA AA23-158A |
| Network Indicator | https://connectzoomdownload.com/download/ZoomInstaller.exe4 | CISA AA23-158A |
| Network Indicator | 104.194.222.1074 | CISA AA23-158A |
| Network Indicator | 146.0.77.1414 | CISA AA23-158A |
| Network Indicator | 162.244.34.264 | CISA AA23-158A |
| Network Indicator | 185.104.194.1564 | CISA AA23-158A |
| Network Indicator | 185.117.88.174 | CISA AA23-158A |
| Network Indicator | 45.227.253.1334 | CISA AA23-158A |
| Network Indicator | 5.149.248.684 | CISA AA23-158A |
| Network Indicator | 91.222.174.954 | CISA AA23-158A |
| Email Address | gagnondani225@gmail.com4 | CISA AA23-158A |
| Email Address | rey14000707@gmail.com4 | CISA AA23-158A |
| Email Address | unlock@rsv-box.com4 | CISA AA23-158A |
| Email Address | unlock@support-mult.com4 | CISA AA23-158A |
| Campaign Context | CISA/FBI AA23-158A attributes MOVEit Transfer CVE-2023-34362 exploitation to the CL0P ransomware gang and retains TA505 as a related known alias.4 | CISA AA23-158A |
| Campaign Context | NVD records CVE-2023-0669 as a Fortra GoAnywhere MFT pre-authentication command-injection vulnerability; retain as historical GoAnywhere campaign context connected to public CL0P reporting.7 | NVD |
| Campaign Context | NVD records CVE-2023-34362 as a MOVEit Transfer SQL injection vulnerability that can allow unauthenticated database access; CISA KEV status establishes active-exploitation prioritization, not organization-specific compromise.10 | NVD |
| Campaign Context | Progress Software's May 31, 2023 MOVEit Transfer advisory is the vendor remediation reference for the original critical vulnerability and related response guidance.11 | Progress |
| Campaign Context | SecurityWeek reported CVE-2024-55956 assignment and CL0P's claim of Cleo exploitation; IntelliOS retains this as claim/campaign context rather than proof that every Cleo exploitation incident is CL0P.9 | SecurityWeek |
| Campaign Context | The Canadian Centre profiles CL0P as ransomware operated by TA505 and lists related names including FIN11, Lace Tempest, DEV-0950, GRACEFUL SPIDER, and other vendor aliases; IntelliOS treats these as source-retained related names, not automatic one-to-one identity proof for every campaign.6 | Canadian Centre |
| Campaign Context | ZeroFox reported CL0P claimed responsibility for Cleo MFT exploitation in December 2024 and caveated the extent of compromise and extortion activity at the time of reporting.8 | ZeroFox |
| Source | Reported | Retained | Coverage Status |
|---|---|---|---|
| SOCRadar2 | 10502 | 0 | Reported IOC count retained; underlying SOCRadar feed values are not republished unless stored as cited public observables. |
| CISA/FBI4 | N/A | 41 | Public observables or source-context rows retained and displayed. |
| Google/Mandiant5 | N/A | 0 | Context source retained; no direct observable rows retained from this source yet. |
| Canadian Centre for Cyber Security6 | N/A | 5 | Public observables or source-context rows retained and displayed. |
| NVD7 | N/A | 3 | Public observables or source-context rows retained and displayed. |
| ZeroFox Intelligence8 | N/A | 2 | Public observables or source-context rows retained and displayed. |
| SecurityWeek9 | N/A | 3 | Public observables or source-context rows retained and displayed. |
| NIST NVD10 | N/A | 2 | Public observables or source-context rows retained and displayed. |
| Progress Software11 | N/A | 1 | Public observables or source-context rows retained and displayed. |
| MITRE ATT&CK3 | N/A | 1 | Public observables or source-context rows retained and displayed. |
Actor Chronology
No source-backed actor-activity dates are currently retained. Publication and record-maintenance dates are not promoted into activity dates.
IntelliOS Intel Products
PANDA Flash Threat Intel Brief
Source-backed brief for CVE-2023-34362, CISA/FBI's MOVEit exploitation record, LEMURLOOT hunting, and managed-file-transfer response.
CARDS Campaign
Canonical CARDS campaign record with citations, ATT&CK mappings, source-bound attribution, and response takeaways.
Source Reconciliation
| Source | Primary Name | Treatment | Boundary |
|---|---|---|---|
| SOCRadar | Clop | Baseline actor-card record retained for the current profile view. | Fields reflect the retained database record. Additional source consensus, collisions, and canonical identity mappings can be layered into this profile without automatically merging actors. |
| IntelliOS | Clop | Normalizes this record for directory search, card display, profile lookup, and future product linking. | Normalization is a presentation and workflow aid; it is not an independent attribution claim. |
Source Collision Notes
IntelliOS starts this detail page from the retained source record for Clop.
No possible same-actor, alias reuse, sub-cluster, duplicate-boundary, or external-source collision is currently retained for this actor.
| Collision Source | Candidate Records | Shared Evidence | Treatment |
|---|---|---|---|
| None retained | No candidate records | No shared evidence recorded | No collision action needed. |
| External sources | Mandiant, CrowdStrike, other non-SOCRadar sources | None retained | External collisions are shown separately when retained. |
Citations
| # | Source | Use In Card |
|---|---|---|
| 1 | SOCRadar Threat Actor Database https://socradar.io/free-tools/threat-actor/ransomware | Threat actor directory source for profile fields and reported activity. |
| 2 | SOCRadar Actor Profile https://socradar.io/free-tools/ransomware-intelligence/groups/clop | Actor-specific source for ransomware profile metadata and reported IOC counts when available. |
| 3 | MITRE ATT&CK https://attack.mitre.org/groups/G0092/ | ATT&CK source for group, campaign, software, alias, and technique mappings where matched. |
| 4 | CISA AA23-158A: CL0P exploits MOVEit vulnerability https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-158a | Government Advisory |
| 5 | Mandiant: Zero-day MOVEit Transfer data theft https://cloud.google.com/blog/topics/threat-intelligence/zero-day-moveit-data-theft | Threat Intelligence |
| 6 | Canadian Centre: Profile of TA505 / CL0P ransomware https://www.cyber.gc.ca/en/guidance/profile-ta505-cl0p-ransomware | Threat Actor Profile |
| 7 | NVD: CVE-2023-0669 https://nvd.nist.gov/vuln/detail/cve-2023-0669 | Vulnerability Record |
| 8 | ZeroFox: CL0P Claims Responsibility for Cleo Zero-Day Exploitation https://www.zerofox.com/intelligence/flash-report-cl0p-claims-responsibility-for-zero-day-exploitation/ | Threat Intelligence |
| 9 | SecurityWeek: CVE Assigned to Cleo Vulnerability as Cl0p Takes Credit https://www.securityweek.com/cve-assigned-to-cleo-vulnerability-as-cl0p-ransomware-group-takes-credit-for-exploitation/ | Security News |
| 10 | NVD: CVE-2023-34362 https://nvd.nist.gov/vuln/detail/CVE-2023-34362 | Vulnerability Record |
| 11 | Progress: MOVEit Transfer Critical Vulnerability - 31 May 2023 https://www.progress.com/moveit/security/advisories/moveit-transfer-critical-vulnerability-31-may-2023 | Vendor Advisory |