Active ransomware operator
← All groupsclop
aka Cl0p · 1,254 victims indexed · first seen 6 years ago · last activity 19 days ago
At a glance
- Status
- active
- Aliases
- Cl0p
- First seen
- 6 years ago
- Last activity
- 19 days ago
- Onion sites
- 3 known endpoints
- Primary sector
- Not Found · 239 hits
About
References
75 linksExternal sources curated by the MISP threat-intel community.
- cert.ssi.gouv.fr/uploads/CERTFR-2020-CTI-001.pdf
- microsoft.com/en-us/security/blog/2022/10/27/raspberry-robin-worm-part-of-larger-ecosystem-facilitating-pre-ransomware-activity/
- blog.malwarebytes.com/malwarebytes-news/2021/02/clop-targets-execs-ransomware-tactics-get-another-new-twist
- unit42.paloaltonetworks.com/clop-ransomware
- actu.fr/normandie/rouen_76540/une-rancon-apres-cyberattaque-chu-rouen-ce-reclament-pirates_29475649.html
- asec.ahnlab.com/en/19542/
- asec.ahnlab.com/wp-content/uploads/2021/01/Analysis_ReportCLOP_Ransomware.pdf
- blog.fox-it.com/2020/11/16/ta505-a-brief-history-of-their-time/
- blog.sensecy.com/2020/08/20/global-ransomware-attacks-in-2020-the-top-4-vulnerabilities/
- cisoclub.ru/doc/otchet-kompanii-group-ib-ransomware-uncovered-2020-2021/?bp-attachment=group-ib_ransomware_uncovered_2020-2021.pdf
- docs.google.com/spreadsheets/d/1MI8Z2tBhmqQ5X8Wf_ozv3dVjz5sJOs-3
- github.com/Tera0017/TAFOF-Unpacker
- github.com/albertzsigovits/malware-notes/blob/master/Clop.md
- github.com/albertzsigovits/malware-notes/blob/master/Ransomware/Clop.md
- go.crowdstrike.com/rs/281-OBQ-266/images/Report2020CrowdStrikeGlobalThreatReport.pdf
- go.crowdstrike.com/rs/281-OBQ-266/images/Report2021GTR.pdf
- ke-la.com/how-ransomware-gangs-find-new-monetization-schemes-and-evolve-in-marketing/
- krebsonsecurity.com/2021/06/ukrainian-police-nab-six-tied-to-clop-ransomware/
- labs.sentinelone.com/breaking-ta505s-crypter-with-an-smt-solver/
- media.kasperskycontenthub.com/wp-content/uploads/sites/43/2022/06/23093553/Common-TTPs-of-the-modern-ransomware_low-res.pdf
Timeline
24 monthsTop countries
Top sectors
MITRE ATT&CK
8 techniques · 7 tacticsTactics
Detection · YARA rules
1 ruleclop_ransom_note
YARA rule from ATR/Trellix: ransomware/RANSOM_ClopRansomNote.yar
source: ATR/Trellix
Recent victims
Loading…
Onion infrastructure
3 known- http://ekbgzchl6x2ias37.onion
- http://santat7kpllt6iyvqbr7q4amdv6dzrh6paatvyrzl7ry3zm72zigf4ad.onion
- http://toznnag5o3ambca56s2yacteu7q7x2avrfherzmz4nmujrjuib4iusad.onion
Source
Updated 19 days agoData on this page is sourced from the group's own leak posts, cross-checked with public ransomware trackers (RansomLook, ransomware.live, RansomWatch), MITRE ATT&CK, and our own Tor and Telegram crawlers. This is a public observatory page — share freely.
