Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started

Also known as: Cl0p

Description

The ransomware group known as Cl0p is a variant of a previously known strain dubbed CryptoMix. It is worth noting that this variant was delivered as the final payload in a phishing campaign in 2019 and was exclusively financially motivated, with attacks carried out by the threat actors TA505.<br> <br> At that time, malicious actors sent phishing emails that led to a macro-enabled document that would drop a loader called 'Get2.' After gaining an initial foothold in the system or infrastructure, the actors began using reconnaissance, lateral movement, and exfiltration techniques to prepare for the deployment of the ransomware.<br> <br> After the execution of the ransomware, Cl0p appends the extension '.clop' to the end of files, or other types of extensions such as '.CIIp, .Cllp, and .C_L_O_P,' as well as different versions of the ransom note that were also observed after encryption. Depending on the variant, any of the ransom text files were created with names like 'ClopReadMe.txt, README_README.txt, Cl0pReadMe.txt, and READ_ME_!!!.TXT.'<br> <br> The Clop operation has shifted from delivering its final payload via phishing and has begun initiating attacks using vulnerabilities that resulted in the exploitation and infection of victims' infrastructures.<BR>Source: https://github.com/crocodyli/ThreatActors-TTPs Known victims: 1254 4 ransom note(s) on file

Goals & Targeting

Objectives

Ransomware
Financial Gain

AI Analysis

· 1 week ago

Executive Summary

The CLOP (Cl0p) threat actor group is a medium-sophisticated criminal organization primarily engaged in ransomware activities to achieve financial gain. Known since March 2020, they have shifted from phishing-based infections to exploiting vulnerabilities for deploying their ransomware, targeting organizations globally with significant campaign activity.

Goals & Targeting

CLOP primarily targets organizations for financial gain via ransomware. Their strategic objectives include disrupting operations to coerce payments, with a focus on sectors where data breaches have high costs and slower recovery times. Known campaigns suggest targeting industries with less robust cybersecurity measures, such as legal services and healthcare.

Enhanced Description

CLOP is a variant of the CryptoMix ransomware, historically linked to TA505 operators. Their initial campaigns used phishing emails with macro-enabled documents to deploy loaders like 'Get2,' followed by advanced TTPs including reconnaissance and lateral movement. Post-encryption, files are appended with extensions such as '.clop' and ransom notes in varying formats. The group has notably targeted sectors like healthcare and legal services through campaigns like INJURYLAWYERS.COM and AIGHEALTHCARE.IN. Their adaptability includes evolving from phishing to exploit-based attacks.

Key Capabilities

  • Phishing campaigns using macro-enabled documents
  • Loader deployment (Get2)
  • Exploitation of vulnerabilities
  • Reconnaissance and lateral movement techniques
  • Ransomware deployment with varying file extensions

MITRE ATT&CK Tactics

Attack Execution
Credential Access
Defense Evasion
Persistence
Exfiltration
Discovery

ATT&CK Techniques

T1566.001 - Phishing
T1058 - Exploitation for Impact
T1078 - Discovery
T1093 - External Remote Control
T1094.004 - Exfiltration over Network Tools

Software / Tooling

Macro-enabled Documents (loader)
Get2 Loader
TA505-associated tools

Campaigns & Victims

CLOP has executed campaigns targeting sectors such as healthcare, legal services, and cloud infrastructure. Notable operations include attacks on INJURYLAWYERS.COM, CLOUD.CLEARWAYGROUP.COM. Their shift to exploit-based infections indicates evolution in tactics, suggesting a focus on higher-value targets.

IOC Patterns

  • Spear-phishing emails with macro-enabled Office documents
  • Deployment of Get2 loader after initial compromise
  • File extensions like .clop, .CIIp, .Cl0p following encryption
  • Ransom notes named 'ClopReadMe.txt', 'README_README.txt'

Recommended Actions

  • Implement advanced email filtering to detect phishing attempts.
  • Use sandboxing solutions to analyze macro-enabled documents.
  • Patch network vulnerabilities promptly.
  • Ensure regular backups of critical data systems.
  • Educate employees on spotting phishing indicators.

Suggested Tags

Ransomware
Financial-gain
TA505 affiliate

Confidence Assessment

Confidence in CLOP's data is high for general activity but lower in specific sector and country targeting. Gaps include detailed TTP mapping beyond typical ransomware operations.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

47

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

Ransomware
Phishing
Financial-gain
TA505 affiliate

Details

Type
Criminal
Sophistication
Medium
Primary Motivation
Organizational gain
Confidence
80%
First Seen
Mar 13, 2020
Last Seen
Aug 7, 2026
Added
May 4, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.