Also known as: Cl0p
The ransomware group known as Cl0p is a variant of a previously known strain dubbed CryptoMix. It is worth noting that this variant was delivered as the final payload in a phishing campaign in 2019 and was exclusively financially motivated, with attacks carried out by the threat actors TA505.<br> <br> At that time, malicious actors sent phishing emails that led to a macro-enabled document that would drop a loader called 'Get2.' After gaining an initial foothold in the system or infrastructure, the actors began using reconnaissance, lateral movement, and exfiltration techniques to prepare for the deployment of the ransomware.<br> <br> After the execution of the ransomware, Cl0p appends the extension '.clop' to the end of files, or other types of extensions such as '.CIIp, .Cllp, and .C_L_O_P,' as well as different versions of the ransom note that were also observed after encryption. Depending on the variant, any of the ransom text files were created with names like 'ClopReadMe.txt, README_README.txt, Cl0pReadMe.txt, and READ_ME_!!!.TXT.'<br> <br> The Clop operation has shifted from delivering its final payload via phishing and has begun initiating attacks using vulnerabilities that resulted in the exploitation and infection of victims' infrastructures.<BR>Source: https://github.com/crocodyli/ThreatActors-TTPs Known victims: 1254 4 ransom note(s) on file
Objectives
Executive Summary
The CLOP (Cl0p) threat actor group is a medium-sophisticated criminal organization primarily engaged in ransomware activities to achieve financial gain. Known since March 2020, they have shifted from phishing-based infections to exploiting vulnerabilities for deploying their ransomware, targeting organizations globally with significant campaign activity.
Goals & Targeting
CLOP primarily targets organizations for financial gain via ransomware. Their strategic objectives include disrupting operations to coerce payments, with a focus on sectors where data breaches have high costs and slower recovery times. Known campaigns suggest targeting industries with less robust cybersecurity measures, such as legal services and healthcare.
Enhanced Description
CLOP is a variant of the CryptoMix ransomware, historically linked to TA505 operators. Their initial campaigns used phishing emails with macro-enabled documents to deploy loaders like 'Get2,' followed by advanced TTPs including reconnaissance and lateral movement. Post-encryption, files are appended with extensions such as '.clop' and ransom notes in varying formats. The group has notably targeted sectors like healthcare and legal services through campaigns like INJURYLAWYERS.COM and AIGHEALTHCARE.IN. Their adaptability includes evolving from phishing to exploit-based attacks.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
CLOP has executed campaigns targeting sectors such as healthcare, legal services, and cloud infrastructure. Notable operations include attacks on INJURYLAWYERS.COM, CLOUD.CLEARWAYGROUP.COM. Their shift to exploit-based infections indicates evolution in tactics, suggesting a focus on higher-value targets.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Confidence in CLOP's data is high for general activity but lower in specific sector and country targeting. Gaps include detailed TTP mapping beyond typical ransomware operations.
No techniques linked yet.
No tools linked yet.
No observed data linked yet.
No IOCs linked yet.
No references recorded yet.
0
Techniques
0
Tools
47
Campaigns
0
IOCs
0
Observed Data
0
Tactics