🇷🇺 Cl0p¶
Threat-actor battle card · maintained from public sources · last updated 2026-08-19 · also known as Clop, TA505, FIN11, Snakefly, Graceful Spider
Overview¶
Cl0p (also written Clop) is a Russian-linked data extortion group that emerged in February 2019 as a RaaS ransomware variant evolved from the CryptoMix family. Operated by the TA505 collective (also tracked as FIN11, Snakefly, Graceful Spider), Cl0p pioneered the model of exploiting zero-day vulnerabilities in widely deployed enterprise file-transfer and ERP platforms for mass data theft — targeting thousands of organizations simultaneously through a single vulnerability. Over 1,025 confirmed victims and $500M+ in extorted payments since 2019. Active in 2026 through two overlapping campaigns: residual Cleo file-transfer exploitation (Dec 2024 zero-day; 97+ extortion waves through Q1 2026) and an Oracle E-Business Suite campaign (CVE-2025-61882, CVSS 9.8; exploitation began August 2025; 234+ claimed victims, 103 named on DLS as of early 2026). Food and Agriculture sector targeting emerged as a notable Q1 2026 trend: Cl0p accounted for 9.3% of food/ag attacks globally vs. a 4.2% sector baseline, per Food and Ag-ISAC analysis — consistent with the group's indiscriminate mass-exploitation model reaching ERP deployments in the agri-food supply chain.
Tradecraft¶
- Zero-day mass exploitation of enterprise file-transfer and ERP platforms: Accellion FTA (2020), SolarWinds Serv-U (2021), GoAnywhere MFT (2023), MOVEit Transfer (2023), Cleo MFT (2024), Oracle E-Business Suite (2025).
- Pure data exfiltration without encryption in recent campaigns — no encryption payload, focus entirely on exfiltration and extortion leverage.
- Quadruple extortion: (1) threat of DLS publication; (2) personal email to victim executives and board; (3) direct contact to victim's customers; (4) selling stolen data to third parties if ransom refused.
- Initial access historically via spear-phishing (SDBot + FlawedAmmy RAT); pivot to zero-day exploitation for mass campaigns since 2020.
- Cobalt Strike for C2 in legacy operations; recent campaigns are primarily network-level exploitation with no persistent implant required.
- Exploits vulnerabilities 1–2 months before public disclosure and patch (CVE-2025-61882: exploited from August 2025; patches released September/October 2025).
- Ransom demands reach $50M (Oracle EBS campaign); seven- and eight-figure demands documented.
Notable victims¶
- PTC Windchill/FlexPLM campaign (2026): Shell (investigating, 89GB engineering data claimed), Philips (confirmed compromise of specific enterprise server), General Electric, FIS Global (874GB claimed), Zebra Technologies (8TB claimed — largest volume in campaign), Fiserv (denies customer data compromise), and 38+ additional organizations named on DLS. Exploitation of CVE-2026-12569 (CVSS 9.3) via JSP webshells since early June 2026; data exfiltration-only (no encryption). 44+ named victims across industrial, financial, technology, and energy sectors as of August 2026.
- Oracle EBS campaign (2025–2026): Logitech, The Washington Post, Cox Enterprises, Pan American Silver, LKQ Corporation, GlobalLogic (Hitachi subsidiary), Barts Health NHS Trust (London), University of Phoenix (3.5M individuals), Copeland, Schneider Electric; 103+ organizations named on DLS, 77 datasets released via torrent.
- MOVEit (2023): British Airways, BBC, Boots, Shell, US Department of Energy, multiple US state governments; est. 2,000+ organizations affected globally.
- GoAnywhere MFT (2023): Procter & Gamble, City of Toronto, Hitachi Energy, Community Health Systems.
- Cleo MFT (2024–2026): 97+ victims in extortion wave continuing through Q1 2026.
Assessment¶
Cl0p's operational model — stockpiling zero-days in enterprise platforms used for bulk data processing — makes it episodically devastating at a scale no individual target can anticipate or prevent. The PTC Windchill/FlexPLM campaign (CVE-2026-12569, exploited since early June 2026) is the group's most significant wave since MOVEit 2023 by victim count and sector breadth: 44+ named organizations across industrial (Shell, GE, Zebra Technologies), financial technology (FIS Global, Fiserv), healthcare technology (Philips), and others. The campaign's focus on PLM platforms — which hold CAD files, engineering drawings, proprietary manufacturing data, and product R&D — represents a deliberate pivot to high-value industrial IP exfiltration, potentially enabling follow-on economic espionage or sale to state actors. Best enterprise mitigations: isolate PTC Windchill/FlexPLM from internet-facing networks, monitor for large outbound exfiltration via JSP execution, and maintain tested incident-response playbooks. Episodes are typically separated by months of apparent inactivity before the next zero-day campaign surfaces; this campaign is active as of August 2026.
Sources¶
- BleepingComputer — Clop ransomware targets Windchill, FlexPLM in data theft attacks (August 2026)
- CISO Platform — Breach Watch August 17, 2026: Clop Hits Shell, GE, Philips via PTC Windchill Flaw
- DEXpose — Clop Ransomware Targets Zebra.com in Major Data Breach
- Ransom-ISAC — Cl0p Exploitation of PTC Windchill & FlexPLM
- Tech Insider — Cl0p Ransomware Hits PTC Windchill: CVE-2026-12569
- Google Mandiant — Oracle E-Business Suite Zero-Day Exploited in Widespread Extortion Campaign
- CISA / FBI — #StopRansomware: CL0P Ransomware Gang Exploits CVE-2023-34362 MOVEit
- SecurityWeek — Nearly 30 Alleged Victims of Oracle EBS Hack Named on Cl0p Ransomware Site
- Halcyon — Cl0p threat group
- Blackpoint Cyber — Cl0p Ransomware Threat Profile (Feb 2026)
- Industrial Cyber / Food and Ag-ISAC — Cl0p among top ransomware threats to food and agriculture sector (Q1 2026)
🗂️ Attacks & victims¶
All disclosed victims attributed to this actor, newest first.
August 2026
July 2026