ShellCodeX
Tools โ€ข Events โ€ข News โ€ข Insights
SEO Checker
Threat Group Profile

clop

โ— Active โ€” last 30 days
Victim claims 91
First seen May 2026
Last activity 14 Aug 2026
Tracked since Mar 2020

Group overview

The ransomware group known as Cl0p is a variant of a previously known strain dubbed CryptoMix. It is worth noting that this variant was delivered as the final payload in a phishing campaign in 2019 and was exclusively financially motivated, with attacks carried out by the threat actors TA505. At that time, malicious actors sent phishing emails that led to a macro-enabled document that would drop a loader called 'Get2.' After gaining an initial foothold in the system or infrastructure, the actors began using reconnaissance, lateral movement, and exfiltration techniques to prepare for the deployment of the ransomware. After the execution of the ransomware, Cl0p appends the extension '.clop' to the end of files, or other types of extensions such as '.CIIp, .Cllp, and .C_L_O_P,' as well as different versions of the ransom note that were also observed after encryption. Depending on the variant, any of the ransom text files were created with names like 'ClopReadMe.txt, README_README.txt, Cl0pReadMe.txt, and READ_ME_!!!.TXT.' The Clop operation has shifted from delivering its final payload via phishing and has begun initiating attacks using vulnerabilities that resulted in the exploitation and infection of victims' infrastructures.Source: https://github.com/crocodyli/ThreatActors-TTPs

Preferred targets

Technology ยท 15 Retail & E-Commerce ยท 8 Manufacturing ยท 5 Financial Services ยท 5 Healthcare ยท 4 Other ยท 4

Most targeted countries

US ยท 24 IN ยท 4 GB ยท 3 IT ยท 3 CN ยท 2 MX ยท 2

Tactics & techniques (MITRE ATT&CK)

Initial Access

Valid accounts Exploit public-facing application Phishing: Spear-phishing attachment

Execution

Command and scripting interpreter Native API User execution

Persistence

Create or modify system process: Windows service Boot or logon autostart execution

Privilege Escalation

Exploitation for privilege escalation Domain Policy modification: Group Policy modification Hijack execution flow

Defense Evasion

Masquerading: invalid code signature Process injection: DLL injection Indicator removal on host: clear Windows event logs Indicator removal on host: file deletion Deobfuscate/Decode files or information Indirect command execution Impair defenses: disable or modify tools

Discovery

Query registry Remote system discovery Process discovery Security software discovery System information discovery File and directory discovery

Lateral Movement

Remote services: SMB/Windows admin shares Lateral tool transfer

Collection

Data from local system

Victim Claims Timeline

Back to radar
๐Ÿ‡บ๐Ÿ‡ธ United States

SMAPCENTER.UAH.EDU

SMAPCENTER.UAH.EDU

Data exfiltrated included the following: Database, Project - files Total size: 6,08Gb Revenue: $113,000,000

Education
๐Ÿ‡บ๐Ÿ‡ธ United States

TRISTAR.COM

TRISTAR.COM

Data exfiltrated included the following: Database, Project - files Total size: 1579,9Gb Revenue: $1,000,000,000

๐Ÿ‡ฌ๐Ÿ‡ง United Kingdom

MAMASANDPAPAS.COM

MAMASANDPAPAS.COM

Data exfiltrated included the following: Database, Project - files Total size: 1,18Gb Revenue: $131,000,000

Retail & E-Commerce
๐Ÿ‡บ๐Ÿ‡ธ United States

CORNELIUS.COM

CORNELIUS.COM

Data exfiltrated included the following: Database, Project, PDF, TXT, DOC - files Total size: 3684Gb Revenue: $269,800,000

๐Ÿ‡จ๐Ÿ‡ญ Switzerland

MAMMUT.COM

MAMMUT.COM

Data exfiltrated included the following: .png files, files Windchil Total size: 136Gb Revenue: $281,000,000

Retail & E-Commerce
๐Ÿ‡บ๐Ÿ‡ธ United States

PARTECH.COM

PARTECH.COM

Data exfiltrated included the following: Database, Project, Cad-files, Backups Total size: 24Gb Revenue: $475,700,000

Technology
๐Ÿ‡บ๐Ÿ‡ธ United States

STARKEY.COM

STARKEY.COM

Data exfiltrated included the following: Database, Project Total size: 3030Gb Revenue: $939,200,000

Healthcare
๐Ÿ‡น๐Ÿ‡ผ Taiwan

LARGAN.COM.TW

LARGAN.COM.TW

Data exfiltrated included the following: Project, Soft Total size: 56Gb Revenue: $1,700,000,000

Manufacturing
๐Ÿ‡บ๐Ÿ‡ธ United States

TOASTTAB.COM

TOASTTAB.COM

Data exfiltrated included the following: project, backup database, logs Total size: 215Gb Revenue: $6,400,000,000

Hospitality
๐Ÿ‡ฎ๐Ÿ‡ท Iran

IRCO.COM

IRCO.COM

Data exfiltrated included the following: Cad-files, PDF drawings, diagrams, product presentations, specifications, manuals and instructions Total size: 5564Gb Revenue: $7...

๐Ÿ‡จ๐Ÿ‡ฆ Canada

ALDOGROUP.COM (ALDOSHOES.COM)

ALDOSHOES.COM

Data exfiltrated included the following: TSV files, soft, Projects, Cad-files Total size: 424Gb Revenue: $14,800,000,000

Retail & E-Commerce
๐Ÿ‡ณ๐Ÿ‡ฑ Netherlands

PHILIPS.COM

PHILIPS.COM

Data exfiltrated included the following: PDF drawings, diagrams, blueprints Total size: 13.5Gb Revenue: $20,700,000,000

Healthcare
๐Ÿ‡บ๐Ÿ‡ธ United States

FISERV.COM

FISERV.COM

Data exfiltrated included the following: Projects, Cad-files, files Windchil, Soft Total size: 874Gb Revenue: $21,200,000,000

Financial Services
๐Ÿ‡บ๐Ÿ‡ธ United States

GE.COM

GE.COM

Data exfiltrated included the following: Software backups, system files, projects Total size: 391Gb Revenue: $113,000,000,000

Technology
Unknown

NETPOWER.COM

NETPOWER.COM

Data exfiltrated included the following: Projects, Cad-files, Backup files Windchil Total size: 230Gb Revenue: $370,900,000

Technology
๐Ÿ‡ฌ๐Ÿ‡ง United Kingdom

SHELL.COM (August 2026)

SHELL.COM

Data exfiltrated included the following: Engineering drawings, photos of the facilities, scans of facility testing reports, project plans Total size: 89Gb Revenue: $2,673...

Energy & Utilities
๐Ÿ‡บ๐Ÿ‡ธ United States

CONTINENTAL.AERO

CONTINENTAL.AERO

[AI generated] N/A

Transportation
๐Ÿ‡จ๐Ÿ‡ณ China

MINDRAY.COM

MINDRAY.COM

[AI generated] Mindray is a Chinese medical device company headquartered in Shenzhen, China. It develops, manufactures, and markets medical equipment including patient mo...

Healthcare
Unknown

nuv*******

[CVEโ€‘2026โ€‘12569] Data exfiltrated included the following: Project, Soft

Unknown

ipm*******

[CVEโ€‘2026โ€‘12569] Data exfiltrated included the following: PDF files, Cad-files, Soft

Unknown

ecc*******

[CVEโ€‘2026โ€‘12569] Data exfiltrated included the following: DBF files, Cad-files, Project, Soft, Backups

Unknown

st*******

[CVEโ€‘2026โ€‘12569] Data exfiltrated included the following: Database, Project

Unknown

qc*******

[CVEโ€‘2026โ€‘12569] Data exfiltrated included the following: Database, Project

Unknown

flu*******

[CVEโ€‘2026โ€‘12569] Data exfiltrated included the following: Database, Project,Cad-files

Unknown

mid*******

[CVEโ€‘2026โ€‘12569] Data exfiltrated included the following: Database, Project

Unknown

itk*******

[CVEโ€‘2026โ€‘12569] Data exfiltrated included the following: Database, Projects

Unknown

G3A*******

[CVEโ€‘2026โ€‘12569] Data exfiltrated included the following: Database, Projects

Unknown

arc*******

[CVEโ€‘2026โ€‘12569] Data exfiltrated included the following: Database, Projects

Technology
Unknown

omn*******

[CVEโ€‘2026โ€‘12569] Data exfiltrated included the following: Database, Projects, SQL Backups, Soft installers, Jpeg, Png, PDF - files

Unknown

lif*******

[CVEโ€‘2026โ€‘12569] Data exfiltrated included the following: Database, Projects, Backups, Logs, Soft installers, PDF, TXT, XML - files