HackerFeeds
All ransomware groups

clop

1,254 tracked victims
·first seen 2020-03-13·last activity 2026-05-01

Group profile

The ransomware group known as Cl0p is a variant of a previously known strain dubbed CryptoMix. It is worth noting that this variant was delivered as the final payload in a phishing campaign in 2019 and was exclusively financially motivated, with attacks carried out by the threat actors TA505.<br> <br> At that time, malicious actors sent phishing emails that led to a macro-enabled document that would drop a loader called 'Get2.' After gaining an initial foothold in the system or infrastructure, the actors began using reconnaissance, lateral movement, and exfiltration techniques to prepare for the deployment of the ransomware.<br> <br> After the execution of the ransomware, Cl0p appends the extension '.clop' to the end of files, or other types of extensions such as '.CIIp, .Cllp, and .C_L_O_P,' as well as different versions of the ransom note that were also observed after encryption. Depending on the variant, any of the ransom text files were created with names like 'ClopReadMe.txt, README_README.txt, Cl0pReadMe.txt, and READ_ME_!!!.TXT.'<br> <br> The Clop operation has shifted from delivering its final payload via phishing and has begun initiating attacks using vulnerabilities that resulted in the exploitation and infection of victims' infrastructures.<BR>Source: https://github.com/crocodyli/ThreatActors-TTPs

MITRE ATT&CK TTPs

TA0001

Initial Access

  • T1078Valid accounts

    Have been reported to make use of compromised accounts to access victims via RDP.

  • T1190Exploit public-facing application

    Arrives via any the following exploits: CVE-2021-27101, CVE-2021-27102, CVE-2021-27103, CVE-2021-27104, CVE-2021-35211.

  • T1566.001Phishing: Spear-phishing attachment

    Arrives via phishing emails that have Get2 Loader, which will download the SDBot and FlawedAmmy RAT.

TA0002

Execution

  • T1059Command and scripting interpreter

    Uses various scripting interpreters like PowerShell, Windows command shell and Visual Basic (macro in documents).

  • T1106Native API

    Uses native API to execute various commands/routines.

  • T1204User execution

    User execution is needed to carry out the payload from the spear-phishing link/attachments.

TA0003

Persistence

  • T1543.003Create or modify system process: Windows service

    Creates a service to execute the ransomware.

  • T1547Boot or logon autostart execution

    Creates registry run entries to execute the ransomware as a service.

TA0004

Privilege Escalation

  • T1068Exploitation for privilege escalation

    Makes use of CVE-2021-27102 to escalate privilege.

  • T1484.001Domain Policy modification: Group Policy modification

    Uses stolen credentials to access the AD servers to gain administrator privilege and attack other machines within the network.

  • T1574Hijack execution flow

    UAC bypass.

TA0005

Defense Evasion

  • T1036.001Masquerading: invalid code signature

    Makes use of the following digital signatures: DVERI, FADO, TOV.

  • T1055.001Process injection: DLL injection

    To deliver other tools and payload, a tool has the capability to inject its downloaded payload.

  • T1070.001Indicator removal on host: clear Windows event logs

    Clears the Event Viewer log files.

  • T1070.004Indicator removal on host: file deletion

    Deletes traces of itself in the infected machine.

  • T1140Deobfuscate/Decode files or information

    The tool used for exfiltration has a part of its malware trace removal, and it drops a base-64 encoded file.

  • T1202Indirect command execution

    A startup script runs just before the system gets to the login screen via startup registry.

  • T1562.001Impair defenses: disable or modify tools

    Disables security-related software by terminating them.

TA0007

Discovery

  • T1012Query registry

    Queries certain registries as part of its routine.

  • T1018Remote system discovery

    Makes use of tools for network scans.

  • T1057Process discovery

    Discovers certain processes for process termination.

  • T1063Security software discovery

    Discovers security software for reconnaissance and termination.

  • T1082System information discovery

    Identifies keyboard layout and other system information.

  • T1083File and directory discovery

    Searches for specific files and the directory related to its encryption.

TA0008

Lateral Movement

  • T1021.002Remote services: SMB/Windows admin shares

    Drops a copy of the payload to the compromised AD and then creates a service on the target machine to execute the copy of the payload.

  • T1570Lateral tool transfer

    Can make use of RDP to transfer the ransomware or tools within the network.

TA0009

Collection

  • T1005Data from local system

    Might make use of RDP to manually search for valuable files or information.

TA0010

Exfiltration

  • T1567Exfiltration over web service

    DEWMODE web shell extracts list of available files from a MySQL database on the FTA and lists these files and corresponding their metadata. These will then be downloaded using the DEWMODE web shell.

TA0011

Command and Control

  • T1071Application Layer Protocol

    Uses http/s to communicate to its C&C server.

TA0040

Impact

  • T1486Data encrypted for impact

    Uses a combination of Salsa20, AES, and ECDH to encrypt the files and key.

  • T1490Inhibit system recovery

    Deletes shadow copies.

Recent victims

showing 50 of 1,254
DateWebsite / victimSectorCountry
2026-05-01
injurylawyers.com
INJURYLAWYERS.COMINJURYLAWYERS.COM
Business ServicesUS
2026-05-01
integralife.com
INTEGRALIFE.COMINTEGRALIFE.COM
HealthcareUS
2026-03-30
aighealthcare.in
AIGHEALTHCARE.INAIGHEALTHCARE.IN
HealthcareIN
2026-03-30
cloud.clearwaygroup.com
CLOUD.CLEARWAYGROUP.COMCLOUD.CLEARWAYGROUP.COM
Technology
2026-02-14
dad.co.th
DAD.CO.THDAD.CO.TH
TechnologyTH
2026-02-14
themortgagefirm.com
THEMORTGAGEFIRM.COMTHEMORTGAGEFIRM.COM
Financial ServicesUS
2026-02-14
fishwindowcleaning.com
FISHWINDOWCLEANING.COMFISHWINDOWCLEANING.COM
Business ServicesUS
2026-02-14
solutionsinsafety.com
SOLUTIONSINSAFETY.COMSOLUTIONSINSAFETY.COM
Business Services
2026-02-14
boyden.com
BOYDEN.COMBOYDEN.COM
Business ServicesUS
2026-02-14
cfdt.fr
CFDT.FRCFDT.FR
Public SectorFR
2026-02-14
spohnassociates.com
SPOHNASSOCIATES.COMSPOHNASSOCIATES.COM
TechnologyUS
2026-02-14
garnergroup.net
GARNERGROUP.NETGARNERGROUP.NET
Not Found
2026-02-14
theperpetual.com
THEPERPETUAL.COMTHEPERPETUAL.COM
TechnologyUS
2026-02-14
aigbusiness.com
AIGBUSINESS.COMAIGBUSINESS.COM
Financial Services
2026-02-14
hydeparkumc.org
HYDEPARKUMC.ORGHYDEPARKUMC.ORG
EducationUS
2026-02-14
giacare.com
GIACARE.COMGIACARE.COM
HealthcareUS
2026-02-14
giaspace.com
GIASPACE.COMGIASPACE.COM
TechnologyUS
2026-02-14
onesupport.com
ONESUPPORT.COMONESUPPORT.COM
TechnologyUS
2026-02-14
hudsonsustainable.com
HUDSONSUSTAINABLE.COMHUDSONSUSTAINABLE.COM
EnergyUS
2026-02-14
gokallit.com
GOKALLIT.COMGOKALLIT.COM
Technology
2026-02-14
chehardy.com
CHEHARDY.COMCHEHARDY.COM
Not FoundUS
2026-02-14
rbdconstruction.com
RBDCONSTRUCTION.COMRBDCONSTRUCTION.COM
ConstructionUS
2026-02-14
broadreachretail.com
BROADREACHRETAIL.COMBROADREACHRETAIL.COM
Consumer ServicesUS
2026-02-14
be09.fr
BE09.FRBE09.FR
Not FoundFR
2026-02-14
smithipservices.com
SMITHIPSERVICES.COMSMITHIPSERVICES.COM
Business Services
2026-02-14
proactivemedical.com
PROACTIVEMEDICAL.COMPROACTIVEMEDICAL.COM
HealthcareUS
2026-02-14
itarchitechs.com
ITARCHITECHS.COMITARCHITECHS.COM
TechnologyUS
2026-02-14
hudsonexecutive.com
HUDSONEXECUTIVE.COMHUDSONEXECUTIVE.COM
Financial ServicesUS
2026-02-14
anstechinc.com
ANSTECHINC.COMANSTECHINC.COM
TechnologyUS
2026-02-07
mnkassociates.com
MNKASSOCIATES.COMMNKASSOCIATES.COM
Not Found
2026-02-07
vippllc.com
VIPPLLC.COMVIPPLLC.COM
Not Found
2026-02-07
trjltd.co.uk
TRJLTD.CO.UKTRJLTD.CO.UK
Not FoundUK
2026-02-07
strategicobjectives.com
STRATEGICOBJECTIVES.COMSTRATEGICOBJECTIVES.COM
Business ServicesCA
2026-02-07
idealwelders.com
IDEALWELDERS.COMIDEALWELDERS.COM
ManufacturingCA
2026-02-07
crowdedisland.com
CROWDEDISLAND.COMCROWDEDISLAND.COM
Not Found
2026-02-07
dukosi.com
DUKOSI.COMDUKOSI.COM
TechnologyGB
2026-02-07
conwest.com
CONWEST.COMCONWEST.COM
Not FoundCA
2026-02-07
ngattorneys.com
NGATTORNEYS.COMNGATTORNEYS.COM
Not Found
2026-02-07
labinf.it
LABINF.ITLABINF.IT
TechnologyIT
2026-02-07
augustea.com
AUGUSTEA.COMAUGUSTEA.COM
Transportation/LogisticsIT
2026-02-07
mediaworld.com.hk
MEDIAWORLD.COM.HKMEDIAWORLD.COM.HK
TechnologyHK
2026-02-07
wardhavencapital.com
WARDHAVENCAPITAL.COMWARDHAVENCAPITAL.COM
Financial Services
2026-02-07
longhornorganics.com
LONGHORNORGANICS.COMLONGHORNORGANICS.COM
Agriculture and Food ProductionUS
2026-02-07
dcsnorway.com
DCSNORWAY.COMDCSNORWAY.COM
Not FoundNO
2026-02-07
shackelford.law
SHACKELFORD.LAWSHACKELFORD.LAW
Business Services
2026-02-07
serve-cloud.com
SERVE-CLOUD.COMSERVE-CLOUD.COM
Technology
2026-02-07
mark-finn.co.uk
MARK-FINN.CO.UKMARK-FINN.CO.UK
ConstructionUK
2026-02-07
emeg.co.uk
EMEG.CO.UKEMEG.CO.UK
Business ServicesUK
2026-02-07
logicalmicro.com
LOGICALMICRO.COMLOGICALMICRO.COM
TechnologyGB
2026-02-07
H
HODERO HOLDINGS LTD
Not FoundBM