Skip to content
The Nexus
Group profile177 claimed in last 30d177 total tracked

Cl0p

Forward this

The ransomware group known as Cl0p is a variant of a previously known strain dubbed CryptoMix. It is worth noting that this variant was delivered as the final payload in a phishing campaign in 2019 and was exclusively financially motivated, with attacks carried out by the threat actors TA505. At that time, malicious actors sent phishing emails that led to a macro-enabled document that would drop a loader called 'Get2.' After gaining an initial foothold in the system or infrastructure, the actors began using reconnaissance, lateral movement, and exfiltration techniques to prepare for the deployment of the ransomware. After the execution of the ransomware, Cl0p appends the extension '.clop' to the end of files, or other types of extensions such as '.CIIp, .Cllp, and .C_L_O_P,' as well as different versions of the ransom note that were also observed after encryption. Depending on the variant, any of the ransom text files were created with names like 'ClopReadMe.txt, README_README.txt, Cl0pReadMe.txt, and READ_ME_!!!.TXT.' The Clop operation has shifted from delivering its final payload via phishing and has begun initiating attacks using vulnerabilities that resulted in the exploitation and infection of victims' infrastructures. Source: https://github.com/crocodyli/ThreatActors-TTPs

First seen: Jul 31 · 00:00 UTCLast seen: Aug 14 · 09:15 UTCTracked since: 2020-03-13
Sectors hit
  • Unspecified39
  • Technology15
  • Retail & E-Commerce8
  • Manufacturing5
  • Financial Services5
  • Other4
  • Healthcare3
  • Transportation2
Countries hit
  • United States22
  • India4
  • Italy3
  • United Kingdom3
  • Mexico2
  • China2
  • Taiwan1
  • Slovakia1
  • Peru1
  • Netherlands1
MITRE ATT&CK · observed TTPs11 tactics

Tactics and techniques attributed to CL0P by ransomware.live's curated TTP catalog. Identifiers link to the canonical MITRE ATT&CK reference for each tactic or sub-technique.

  • TA0001Initial Access
    • T1078Valid accounts

      Have been reported to make use of compromised accounts to access victims via RDP.

    • T1190Exploit public-facing application

      Arrives via any the following exploits: CVE-2021-27101, CVE-2021-27102, CVE-2021-27103, CVE-2021-27104, CVE-2021-35211.

    • T1566.001Phishing: Spear-phishing attachment

      Arrives via phishing emails that have Get2 Loader, which will download the SDBot and FlawedAmmy RAT.

  • TA0002Execution
    • T1059Command and scripting interpreter

      Uses various scripting interpreters like PowerShell, Windows command shell and Visual Basic (macro in documents).

    • T1106Native API

      Uses native API to execute various commands/routines.

    • T1204User execution

      User execution is needed to carry out the payload from the spear-phishing link/attachments.

  • TA0003Persistence
    • T1543.003Create or modify system process: Windows service

      Creates a service to execute the ransomware.

    • T1547Boot or logon autostart execution

      Creates registry run entries to execute the ransomware as a service.

  • TA0004Privilege Escalation
    • T1068Exploitation for privilege escalation

      Makes use of CVE-2021-27102 to escalate privilege.

    • T1484.001Domain Policy modification: Group Policy modification

      Uses stolen credentials to access the AD servers to gain administrator privilege and attack other machines within the network.

    • T1574Hijack execution flow

      UAC bypass.

  • TA0005Defense Evasion
    • T1036.001Masquerading: invalid code signature

      Makes use of the following digital signatures: DVERI, FADO, TOV.

    • T1055.001Process injection: DLL injection

      To deliver other tools and payload, a tool has the capability to inject its downloaded payload.

    • T1070.001Indicator removal on host: clear Windows event logs

      Clears the Event Viewer log files.

    • T1070.004Indicator removal on host: file deletion

      Deletes traces of itself in the infected machine.

    • T1140Deobfuscate/Decode files or information

      The tool used for exfiltration has a part of its malware trace removal, and it drops a base-64 encoded file.

    • T1202Indirect command execution

      A startup script runs just before the system gets to the login screen via startup registry.

    • T1562.001Impair defenses: disable or modify tools

      Disables security-related software by terminating them.

  • TA0007Discovery
    • T1012Query registry

      Queries certain registries as part of its routine.

    • T1018Remote system discovery

      Makes use of tools for network scans.

    • T1057Process discovery

      Discovers certain processes for process termination.

    • T1063Security software discovery

      Discovers security software for reconnaissance and termination.

    • T1082System information discovery

      Identifies keyboard layout and other system information.

    • T1083File and directory discovery

      Searches for specific files and the directory related to its encryption.

  • TA0008Lateral Movement
    • T1021.002Remote services: SMB/Windows admin shares

      Drops a copy of the payload to the compromised AD and then creates a service on the target machine to execute the copy of the payload.

    • T1570Lateral tool transfer

      Can make use of RDP to transfer the ransomware or tools within the network.

  • TA0009Collection
    • T1005Data from local system

      Might make use of RDP to manually search for valuable files or information.

  • TA0010Exfiltration
    • T1567Exfiltration over web service

      DEWMODE web shell extracts list of available files from a MySQL database on the FTA and lists these files and corresponding their metadata. These will then be downloaded using the DEWMODE web shell.

  • TA0011Command and Control
    • T1071Application Layer Protocol

      Uses http/s to communicate to its C&C server.

  • TA0040Impact
    • T1486Data encrypted for impact

      Uses a combination of Salsa20, AES, and ECDH to encrypt the files and key.

    • T1490Inhibit system recovery

      Deletes shadow copies.

Recent claimed victims
ManufacturingUnited StatesAug 14 · 09:15 UTC

ZEBRA.COM

ZEBRA.COM
Aug 13 · 20:21 UTC

ZEBRA.COM

Aug 12 · 16:24 UTC

NETPOWER.COM

Aug 12 · 16:24 UTC

SHELL.COM (August 2026)

Aug 12 · 16:24 UTC

GE.COM

Aug 12 · 16:23 UTC

FISERV.COM

Aug 12 · 16:23 UTC

PHILIPS.COM

Aug 12 · 16:23 UTC

ALDOGROUP.COM (ALDOSHOES.COM)

Aug 12 · 16:23 UTC

IRCO.COM

Aug 12 · 16:22 UTC

TOASTTAB.COM

Aug 12 · 16:22 UTC

LARGAN.COM.TW

Aug 12 · 16:22 UTC

STARKEY.COM

Aug 12 · 16:21 UTC

PARTECH.COM

Aug 12 · 16:21 UTC

MAMMUT.COM

Aug 12 · 16:21 UTC

CORNELIUS.COM

Aug 12 · 16:20 UTC

MAMASANDPAPAS.COM

Aug 12 · 16:20 UTC

TRISTAR.COM

Aug 12 · 16:20 UTC

SMAPCENTER.UAH.EDU

Aug 12 · 16:20 UTC

SUUNTO.CN (SUUNTO.COM)

Aug 12 · 16:20 UTC

BRILLONCONSUMER.COM (BRILLONCONSUMER.COM)

Aug 12 · 16:19 UTC

JPMGROUP.CO.IN

Aug 12 · 16:19 UTC

CLOVER.COM

Aug 12 · 16:19 UTC

ATOMBERG.COM

Aug 12 · 16:19 UTC

HONGHE-TECH.COM

Aug 12 · 16:18 UTC

INTELLIGENTGROWTHSOLUTIONS.COM

Aug 12 · 16:18 UTC

INTELLIHOT.COM

Aug 12 · 16:18 UTC

9ALTITUDES.COM

Aug 12 · 16:18 UTC

WATERLANDPE.COM

Aug 12 · 16:18 UTC

THERMOS.COM

Aug 12 · 16:17 UTC

NUOVACMM.COM

Aug 12 · 16:17 UTC

IVALUESYS.COM

Aug 12 · 16:17 UTC

SPKAA.COM

Aug 12 · 16:17 UTC

LIFESTRAW.COM

Aug 12 · 16:16 UTC

OMNITANKER.COM

Aug 12 · 16:16 UTC

ARCHERGREY.COM

Aug 12 · 16:16 UTC

G3AEROSPACE.COM

Aug 12 · 16:16 UTC

ITKHOLDING.HU

Aug 12 · 16:16 UTC

MIDLANDIND.COM.AU

Aug 12 · 16:15 UTC

FLUIDLOGIC.COM

Aug 12 · 16:15 UTC

QCPL.IN

Aug 12 · 16:15 UTC

STNET.IT

Aug 12 · 16:15 UTC

ECCELLENT.COM

Aug 12 · 16:15 UTC

IPMSOLUTIONS.SK

Aug 12 · 16:14 UTC

NUVITIA.COM

TechnologyUnited StatesAug 12 · 15:52 UTC

AOL.COM

AOL.COM

AOL.com is an American web services and media company headquartered in New York, USA. Originally known as America Online, it was one of the pioneering internet service providers in the 1990s. Today, AOL operates as a digital media and advertising technology platform under Verizon Communications, offering email services, news, entertainment content, and online advertising solutions to consumers and businesses across the United States and globally.

United KingdomAug 12 · 15:51 UTC

GATE7LLC.COMGBBEV.COM

GATE7LLC.COMGBBEV.COM
Agriculture and Food ProductionMexicoAug 12 · 15:50 UTC

ENTERATEK.MXESBERBEVERAGE.COM

ENTERATEK.MXESBERBEVERAGE.COM
TechnologyFranceAug 12 · 15:49 UTC

NUVITIA.COM

NUVITIA.COM
Professional ServicesSlovakiaAug 12 · 15:49 UTC

IPMSOLUTIONS.SK

IPMSOLUTIONS.SK
OtherItalyAug 12 · 15:48 UTC

ECCELLENT.COM

ECCELLENT.COM
TechnologyItalyAug 12 · 15:48 UTC

STNET.IT

STNET.IT
ManufacturingIndiaAug 12 · 15:47 UTC

QCPL.IN

QCPL.IN
TechnologyUnited StatesAug 12 · 15:46 UTC

FLUIDLOGIC.COM

FLUIDLOGIC.COM
ManufacturingAustraliaAug 12 · 15:46 UTC

MIDLANDIND.COM.AU

MIDLANDIND.COM.AU
TechnologyHungaryAug 12 · 15:45 UTC

ITKHOLDING.HU

ITKHOLDING.HU
Government & DefenseUnited StatesAug 12 · 15:45 UTC

G3AEROSPACE.COM

G3AEROSPACE.COM
OtherUnited StatesAug 12 · 15:44 UTC

ARCHERGREY.COM

ARCHERGREY.COM
TransportationUnited StatesAug 12 · 15:44 UTC

OMNITANKER.COM

OMNITANKER.COM
Retail & E-CommerceUnited StatesAug 12 · 15:43 UTC

LIFESTRAW.COM

LIFESTRAW.COM
KazakhstanAug 12 · 15:43 UTC

SPKAA.COM

SPKAA.COM
CL0P · Underground group profile · The Nexus