Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started

Also known as: TA505, FIN11, Shiny Hunters, UNC5936

Description

A comprehensive analysis of Cl0p ransomware operations spanning six years reveals a sophisticated threat actor with systematic focus on managed file transfer infrastructure. The group has exploited zero-day vulnerabilities in nine distinct campaigns targeting platforms including Accellion FTA, SolarWinds Serv-U, Fortra GoAnywhere, MOVEit Transfer, and Oracle E-Business Suite. Cl0p demonstrates exceptional operational discipline through multi-year reconnaissance, strategic Q4 timing coinciding with holidays, and infrastructure diversification across 79 autonomous systems. The group maintains 10-14 month dormancy periods between campaigns, with pre-attack scanning documented up to two years before exploitation. Their success stems from exploiting a fundamental architectural weakness where internet-facing applications coexist with encryption keys within single trust boundaries, rendering encryption-at-rest controls ineffective.

Goals & Targeting

Targeted Sectors

Financial services
Government
Defense
Energy
Transportation
Media
Pharmaceutical
Critical infrastructure
Food agriculture
Education
Retail
Healthcare
Manufacturing
Information technology

Targeted Countries / Regions

US
SG
RU

AI Analysis

No AI analysis yet.

ATT&CK Techniques

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

IPv4 Address 10 Domain 7 IPv6 Address 3

References

  1. www.sentinelone.com — Cited by web research for: TA505
  2. cloud.google.com — Cited by web research for: Shiny Hunters
  3. www.kaspersky.com — Cited by web research for: Trojan
  4. www.cyber.gc.ca — Cited by web research for: Zero-day exploits
  5. unit42.paloaltonetworks.com — Cited by web research for: WebShell

Intel Summary

2

Techniques

40

Tools

0

Campaigns

40

IOCs

0

Observed Data

1

Tactics

Details

Type
Unknown
Primary Motivation
Financial gain
Confidence
55%
Added
Aug 13, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.