ShellCodeX
Tools • Events • News • Insights
SEO Checker
Threat Group Profile

clop

● Active — last 30 days
Victim claims 91
First seen May 2026
Last activity 14 Aug 2026
Tracked since Mar 2020

Group overview

The ransomware group known as Cl0p is a variant of a previously known strain dubbed CryptoMix. It is worth noting that this variant was delivered as the final payload in a phishing campaign in 2019 and was exclusively financially motivated, with attacks carried out by the threat actors TA505. At that time, malicious actors sent phishing emails that led to a macro-enabled document that would drop a loader called 'Get2.' After gaining an initial foothold in the system or infrastructure, the actors began using reconnaissance, lateral movement, and exfiltration techniques to prepare for the deployment of the ransomware. After the execution of the ransomware, Cl0p appends the extension '.clop' to the end of files, or other types of extensions such as '.CIIp, .Cllp, and .C_L_O_P,' as well as different versions of the ransom note that were also observed after encryption. Depending on the variant, any of the ransom text files were created with names like 'ClopReadMe.txt, README_README.txt, Cl0pReadMe.txt, and READ_ME_!!!.TXT.' The Clop operation has shifted from delivering its final payload via phishing and has begun initiating attacks using vulnerabilities that resulted in the exploitation and infection of victims' infrastructures.Source: https://github.com/crocodyli/ThreatActors-TTPs

Preferred targets

Technology · 15 Retail & E-Commerce · 8 Manufacturing · 5 Financial Services · 5 Healthcare · 4 Other · 4

Most targeted countries

US · 24 IN · 4 GB · 3 IT · 3 CN · 2 MX · 2

Tactics & techniques (MITRE ATT&CK)

Initial Access

Valid accounts Exploit public-facing application Phishing: Spear-phishing attachment

Execution

Command and scripting interpreter Native API User execution

Persistence

Create or modify system process: Windows service Boot or logon autostart execution

Privilege Escalation

Exploitation for privilege escalation Domain Policy modification: Group Policy modification Hijack execution flow

Defense Evasion

Masquerading: invalid code signature Process injection: DLL injection Indicator removal on host: clear Windows event logs Indicator removal on host: file deletion Deobfuscate/Decode files or information Indirect command execution Impair defenses: disable or modify tools

Discovery

Query registry Remote system discovery Process discovery Security software discovery System information discovery File and directory discovery

Lateral Movement

Remote services: SMB/Windows admin shares Lateral tool transfer

Collection

Data from local system

Victim Claims Timeline

Back to radar
Unknown

sp*******

[CVE‑2026‑12569] Data exfiltrated included the following: Database, Projects

Unknown

iva*******

[CVE‑2026‑12569] Data exfiltrated included the following: Database, Projects, Backups

Unknown

nuo*******

[CVE‑2026‑12569] Data exfiltrated included the following: Database, Projects, Soft installers

Unknown

the*******

[CVE‑2026‑12569] Data exfiltrated included the following: Database, Projects, Soft installers

Unknown

wat*******

[CVE‑2026‑12569] Data exfiltrated included the following: Database, Projects, Project Backups, SQL Database Backup

Unknown

9al*******

[CVE‑2026‑12569] Data exfiltrated included the following: Database, Projects, Project Backups, SQL Database Backup

Unknown

int*******

[CVE‑2026‑12569] Data exfiltrated included the following: Database, Project, PDF, XLSX, XLS, DOCX - files

Technology
Unknown

hon*******

[CVE‑2026‑12569] Data exfiltrated included the following: Database, Project - files

Unknown

ato*******

[CVE‑2026‑12569] Data exfiltrated included the following: Database, Project - files

Unknown

clo*******

[CVE‑2026‑12569] Data exfiltrated included the following: Database, Project - files

Unknown

jpm*******

[CVE‑2026‑12569] Data exfiltrated included the following: Database, Project - files

Financial Services
Unknown

bri*******

[CVE‑2026‑12569] Data exfiltrated included the following: Database, Project - files

Financial Services
Unknown

suu*******

[CVE‑2026‑12569] Data exfiltrated included the following: Database, Project - files

Unknown

sma*******

[CVE‑2026‑12569] Data exfiltrated included the following: Database, Project - files

Unknown

tri*******

[CVE‑2026‑12569] Data exfiltrated included the following: Database, Project - files

Unknown

cor*******

[CVE‑2026‑12569] Data exfiltrated included the following: Database, Project, PDF, TXT, DOC - files

Unknown

mam*******

[CVE‑2026‑12569] Data exfiltrated included the following: .png files, files Windchil

Unknown

par*******

[CVE‑2026‑12569] Data exfiltrated included the following: Database, Project, Cad-files, Backups

Technology
Unknown

sta*******

[CVE‑2026‑12569] Data exfiltrated included the following: Database, Project

Unknown

lar*******

[CVE‑2026‑12569] Data exfiltrated included the following: Project, Soft

Unknown

toa*******

[CVE‑2026‑12569] Data exfiltrated included the following: project, backup database, logs

Unknown

ir******

[CVE‑2026‑12569] Data exfiltrated included the following: Cad-files, PDF drawings, diagrams, product presentations, specifications, manuals and instructions

Unknown

ald*******

[CVE‑2026‑12569] Data exfiltrated included the following: TSV files, soft, Projects, Cad-files

Unknown

phi*******

[CVE‑2026‑12569] Data exfiltrated included the following: PDF drawings, diagrams, blueprints

Unknown

fis*******

[CVE‑2026‑12569] Data exfiltrated included the following: Projects, Cad-files, files Windchil, Soft

Financial Services
Unknown

g*******

[CVE‑2026‑12569] Data exfiltrated included the following: Software backups, system files, projects

Technology
Unknown

sh*******

[CVE‑2026‑12569] Data exfiltrated included the following: Engineering drawings, photos of the facilities, scans of facility testing reports, project plans

Unknown

net*******

[CVE‑2026‑12569] Data exfiltrated included the following: Projects, Cad-files, Backup files Windchil

🇺🇸 United States

BLUEVISTALLC.COM

BLUEVISTALLC.COM

[AI generated] N/A

🇺🇸 United States

INJURYLAWYERS.COM

INJURYLAWYERS.COM

[AI generated] INJURYLAWYERS.COM is a US-based legal services platform that connects individuals who have suffered personal injuries with qualified attorneys. Operating i...

Business Services