CL

Clop Ransomware

Active

Threat actor group tracked in the global ransomware database · Last disclosure: Aug 14, 2026

Ransomware-as-a-Service (RaaS) Double Extortion Target: Technology
829
Total Victims
3.9% of all tracked
55
Countries Targeted
21
Sectors Targeted
2024
First Seen

ThreatAI Analysis

Compiled from the ransomware.live profile for Clop and from this database. Figures and technique mappings are quoted from the source data, not inferred.

Ransomware group Clop has recorded 829 victims and hit 55 countries, primarily targeting tech firms, consumer services, and manufacturing sectors through financially-motivated cyberattacks.

Who Clop is

The ransomware group known as Cl0p is a variant of a previously known strain dubbed CryptoMix. It is worth noting that this variant was delivered as the final payload in a phishing campaign in 2019 and was exclusively financially motivated, with attacks carried out by the threat actors TA505. At that time, malicious actors sent phishing emails that led to a macro-enabled document that would drop a loader called 'Get2.' After gaining an initial foothold in the system or infrastructure, the actors began using reconnaissance, lateral movement, and exfiltration techniques to prepare for the deployment of the ransomware. After the execution of the ransomware, Cl0p appends the extension '.clop' to the end of files, or other types of extensions such as '.CIIp, .Cllp, and .C_L_O_P,' as well as different versions of the ransom note that were also observed after encryption. Depending on the varian

Recorded activity

Disclosures attributed to Clop in this database run from January 2024 to August 2026, totalling 829 victims — 3.9% of everything tracked here. Clop has listed victims in 55 countries in this database, most often United States, followed by Canada and United Kingdom. The sectors appearing most in its listings are Technology, Consumer Services, Manufacturing.

How Clop is documented to operate

Valid Accounts T1078 Stealth Persistence

Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network.

Mitigations: Application Developer Guidance, User Training, Password Policies, User Account Management, Privileged Account Management, Multi-factor Authentication

MITRE ATT&CK reference →
Exploit Public-Facing Application T1190 Initial Access

Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration. Exploited applications are often websites/web servers, but can also include databases (like SQL), standard services (like SMB or SSH), network device administration and management protocols (like SNMP and Smart Install), and any other system with Internet-accessible open sockets. On ESXi infrastructure, adversaries may exploit exposed OpenSLP services; they may alternatively exploit exposed VMware vCenter servers.

Mitigations: Vulnerability Scanning, Limit Access to Resource Over Network, Filter Network Traffic, Network Segmentation, Privileged Account Management, Application Isolation and Sandboxing

MITRE ATT&CK reference →
Command and Scripting Interpreter T1059 Execution

Adversaries may abuse command and script interpreters to execute commands, scripts, or binaries. These interfaces and languages provide ways of interacting with computer systems and are a common feature across many different platforms. Most systems come with some built-in command-line interface and scripting capabilities, for example, macOS and Linux distributions include some flavor of Unix Shell while Windows installations include the Windows Command Shell and PowerShell. There are also cross-platform interpreters such as Python, as well as those commonly associated with client applications such as JavaScript and Visual Basic.

Mitigations: Restrict Web-Based Content, Limit Software Installation, Execution Prevention, Code Signing, Behavior Prevention on Endpoint, Privileged Account Management

MITRE ATT&CK reference →
Native API T1106 Execution

Adversaries may interact with the native OS application programming interface (API) to execute behaviors. Native APIs provide a controlled means of calling low-level OS services within the kernel, such as those involving hardware/devices, memory, and processes. These native APIs are leveraged by the OS during system boot (when other system components are not yet initialized) as well as carrying out tasks and requests during routine operations. Adversaries may abuse these OS API functions as a means of executing behaviors.

Mitigations: Execution Prevention, Behavior Prevention on Endpoint

MITRE ATT&CK reference →
User Execution T1204 Execution

An adversary may rely upon specific actions by a user in order to gain execution. Users may be subjected to social engineering to get them to execute malicious code by, for example, opening a malicious document file or link. These user actions will typically be observed as follow-on behavior from forms of Phishing. While User Execution frequently occurs shortly after Initial Access it may occur at other phases of an intrusion, such as when an adversary places a file in a shared directory or on a user's desktop hoping that a user will click on it. This activity may also be seen shortly after Internal Spearphishing.

Mitigations: Network Intrusion Prevention, Restrict Web-Based Content, Limit Software Installation, User Training, Execution Prevention, Behavior Prevention on Endpoint

MITRE ATT&CK reference →
Boot or Logon Autostart Execution T1547 Persistence Privilege Escalation

Adversaries may configure system settings to automatically execute a program during system boot or logon to maintain persistence or gain higher-level privileges on compromised systems. Operating systems may have mechanisms for automatically running a program on system boot or account logon. These mechanisms may include automatically executing programs that are placed in specially designated directories or are referenced by repositories that store configuration information, such as the Windows Registry. An adversary may achieve the same goal by modifying or extending features of the kernel.

MITRE ATT&CK reference →
Exploitation for Privilege Escalation T1068 Privilege Escalation

Adversaries may exploit software vulnerabilities in an attempt to elevate privileges. Exploitation of a software vulnerability occurs when an adversary takes advantage of a programming error in a program, service, or within the operating system software or kernel itself to execute adversary-controlled code. Security constructs such as permission levels will often hinder access to information and use of certain techniques, so adversaries will likely need to perform privilege escalation to include use of software exploitation to circumvent those restrictions.

Mitigations: Execution Prevention, Threat Intelligence Program, Application Isolation and Sandboxing, Exploit Protection, Update Software

MITRE ATT&CK reference →

MITRE ATT&CK techniques attributed to Clop across its recorded activity. They describe the group overall, not any single incident.

Vulnerabilities Clop is recorded exploiting

5 of these 5 are in the CISA Known Exploited Vulnerabilities catalog, 5 of them recorded by CISA as used in ransomware campaigns. CVEs attributed to Clop in threat intelligence reporting. Patching these does not by itself rule the group out, and their presence here is not evidence of how any single organisation was reached.

Tooling observed in Clop operations

  • Cobalt Strike
  • PowerShell Empire
  • TinyMet

Software reported in use by Clop. Most are legitimate administration or transfer utilities; their presence in an environment is a signal to investigate, not proof of compromise.

Threat Actor Analysis

Clop is a ransomware threat group that has disclosed 829 victims in publicly accessible leak site data, representing 3.9% of all ransomware attacks tracked in this database. The earliest victim disclosure attributed to Clop in our dataset dates to January 2024.

Geographically, Clop has targeted organisations in 55 countries. The most frequently targeted nation is United States with 426 victim organisations. Other heavily targeted nations include Canada, United Kingdom, Australia.

Industry-wise, Clop shows a concentration in the Technology, Consumer Services, Manufacturing sectors. These industries are frequently targeted because they manage sensitive data, critical operations, or have lower tolerance for operational downtime — conditions that increase ransom payment likelihood.

Like most modern ransomware operations, Clop likely employs a double extortion model: encrypting victim files while simultaneously exfiltrating data, creating dual pressure to pay the ransom. Victim organisations that refuse payment face having their data published on the group's dark web leak site.

Note: This profile is generated from public leak site disclosures aggregated via the ransomware.live API. Data is updated automatically. The table below lists the 100 most recent of the 829 disclosures we hold for this group; use the link beneath it to page through all of them.

Recent Victim Disclosures (showing 100 of 829)

# Organization Country Sector Date
1 ZEBRA.COM ZEBRA.COM 🇺🇸 United States Manufacturing Aug 14, 2026
2 9ALTITUDES.COM 9ALTITUDES.COM 🇮🇳 India Technology Aug 12, 2026
3 ALDOGROUP.COM (ALDOSHOES.COM) ALDOSHOES.COM 🇨🇦 Canada Retail & E-Commerce Aug 12, 2026
4 AOL.COM AOL.COM 🇺🇸 United States Technology Aug 12, 2026
5 ARCHERGREY.COM ARCHERGREY.COM 🇺🇸 United States Other Aug 12, 2026
6 ATOMBERG.COM ATOMBERG.COM 🇮🇳 India Manufacturing Aug 12, 2026
7 BRILLONCONSUMER.COM (BRILLONCONSUMER.COM) BRILLONCONSUMER.COM 🇲🇽 Mexico Retail & E-Commerce Aug 12, 2026
8 CLOVER.COM CLOVER.COM 🇺🇸 United States Retail & E-Commerce Aug 12, 2026
9 CORNELIUS.COM CORNELIUS.COM 🇺🇸 United States Other Aug 12, 2026
10 ECCELLENT.COM ECCELLENT.COM 🇮🇹 Italy Other Aug 12, 2026
11 ENTERATEK.MXESBERBEVERAGE.COM ENTERATEK.MXESBERBEVERAGE.COM 🇲🇽 Mexico Agriculture and Food Production Aug 12, 2026
12 FISERV.COM FISERV.COM 🇺🇸 United States Financial Services Aug 12, 2026
13 FLUIDLOGIC.COM FLUIDLOGIC.COM 🇺🇸 United States Technology Aug 12, 2026
14 G3AEROSPACE.COM G3AEROSPACE.COM 🇺🇸 United States Government & Defense Aug 12, 2026
15 GATE7LLC.COMGBBEV.COM GATE7LLC.COMGBBEV.COM 🇬🇧 United Kingdom Aug 12, 2026
16 GE.COM GE.COM 🇺🇸 United States Technology Aug 12, 2026
17 HONGHE-TECH.COM HONGHE-TECH.COM 🇨🇳 China Technology Aug 12, 2026
18 INTELLIGENTGROWTHSOLUTIONS.COM INTELLIGENTGROWTHSOLUTIONS.COM 🇺🇸 United States Professional Services Aug 12, 2026
19 INTELLIHOT.COM INTELLIHOT.COM 🇺🇸 United States Hospitality Aug 12, 2026
20 IPMSOLUTIONS.SK IPMSOLUTIONS.SK 🇸🇰 Slovakia Professional Services Aug 12, 2026
21 IRCO.COM IRCO.COM IR Aug 12, 2026
22 ITKHOLDING.HU ITKHOLDING.HU 🇭🇺 Hungary Technology Aug 12, 2026
23 IVALUESYS.COM IVALUESYS.COM 🇺🇸 United States Technology Aug 12, 2026
24 JPMGROUP.CO.IN JPMGROUP.CO.IN 🇮🇳 India Financial Services Aug 12, 2026
25 LARGAN.COM.TW LARGAN.COM.TW 🇹🇼 Taiwan Manufacturing Aug 12, 2026
26 LIFESTRAW.COM LIFESTRAW.COM 🇺🇸 United States Retail & E-Commerce Aug 12, 2026
27 MAMASANDPAPAS.COM MAMASANDPAPAS.COM 🇬🇧 United Kingdom Retail & E-Commerce Aug 12, 2026
28 MAMMUT.COM MAMMUT.COM 🇨🇭 Switzerland Retail & E-Commerce Aug 12, 2026
29 MIDLANDIND.COM.AU MIDLANDIND.COM.AU 🇦🇺 Australia Manufacturing Aug 12, 2026
30 NETPOWER.COM NETPOWER.COM Technology Aug 12, 2026
31 NUOVACMM.COM NUOVACMM.COM 🇮🇹 Italy Other Aug 12, 2026
32 NUVITIA.COM NUVITIA.COM 🇫🇷 France Technology Aug 12, 2026
33 OMNITANKER.COM OMNITANKER.COM 🇺🇸 United States Transportation Aug 12, 2026
34 PARTECH.COM PARTECH.COM 🇺🇸 United States Technology Aug 12, 2026
35 PHILIPS.COM PHILIPS.COM 🇳🇱 Netherlands Healthcare Aug 12, 2026
36 QCPL.IN QCPL.IN 🇮🇳 India Manufacturing Aug 12, 2026
37 SHELL.COM (August 2026) SHELL.COM 🇬🇧 United Kingdom Energy & Utilities Aug 12, 2026
38 SMAPCENTER.UAH.EDU SMAPCENTER.UAH.EDU 🇺🇸 United States Education Aug 12, 2026
39 SPKAA.COM SPKAA.COM KZ Aug 12, 2026
40 STARKEY.COM STARKEY.COM 🇺🇸 United States Healthcare Aug 12, 2026
41 STNET.IT STNET.IT 🇮🇹 Italy Technology Aug 12, 2026
42 SUUNTO.CN (SUUNTO.COM) SUUNTO.COM 🇫🇮 Finland Retail & E-Commerce Aug 12, 2026
43 THERMOS.COM THERMOS.COM 🇺🇸 United States Retail & E-Commerce Aug 12, 2026
44 TOASTTAB.COM TOASTTAB.COM 🇺🇸 United States Hospitality Aug 12, 2026
45 TRISTAR.COM TRISTAR.COM 🇺🇸 United States Other Aug 12, 2026
46 WATERLANDPE.COM WATERLANDPE.COM 🇵🇪 Peru Other Aug 12, 2026
47 CONTINENTAL.AERO CONTINENTAL.AERO 🇺🇸 United States Transportation Aug 7, 2026
48 MINDRAY.COM MINDRAY.COM 🇨🇳 China Healthcare Aug 7, 2026
49 9al******* Aug 5, 2026
50 ald******* Aug 5, 2026
51 arc******* Technology Aug 5, 2026
52 ato******* Aug 5, 2026
53 bri******* Financial Services Aug 5, 2026
54 clo******* Aug 5, 2026
55 cor******* Aug 5, 2026
56 ecc******* Aug 5, 2026
57 fis******* Financial Services Aug 5, 2026
58 flu******* Aug 5, 2026
59 g******* Technology Aug 5, 2026
60 G3A******* Aug 5, 2026
61 hon******* Aug 5, 2026
62 int******* Technology Aug 5, 2026
63 ipm******* Aug 5, 2026
64 ir****** Aug 5, 2026
65 itk******* Aug 5, 2026
66 iva******* Aug 5, 2026
67 jpm******* Financial Services Aug 5, 2026
68 lar******* Aug 5, 2026
69 lif******* Aug 5, 2026
70 mam******* Aug 5, 2026
71 mid******* Aug 5, 2026
72 net******* Aug 5, 2026
73 nuo******* Aug 5, 2026
74 nuv******* Aug 5, 2026
75 omn******* Aug 5, 2026
76 par******* Technology Aug 5, 2026
77 phi******* Aug 5, 2026
78 qc******* Aug 5, 2026
79 sh******* Aug 5, 2026
80 sma******* Aug 5, 2026
81 sp******* Aug 5, 2026
82 st******* Aug 5, 2026
83 sta******* Aug 5, 2026
84 suu******* Aug 5, 2026
85 the******* Aug 5, 2026
86 toa******* Aug 5, 2026
87 tri******* Aug 5, 2026
88 wat******* Aug 5, 2026
89 BLUEVISTALLC.COM BLUEVISTALLC.COM 🇺🇸 United States Jul 31, 2026
90 INJURYLAWYERS.COM INJURYLAWYERS.COM 🇺🇸 United States Business Services May 1, 2026
91 INTEGRALIFE.COM INTEGRALIFE.COM 🇺🇸 United States Healthcare May 1, 2026
92 AIGHEALTHCARE.IN AIGHEALTHCARE.IN 🇮🇳 India Healthcare Mar 30, 2026
93 CLOUD.CLEARWAYGROUP.COM CLOUD.CLEARWAYGROUP.COM Technology Mar 30, 2026
94 AIGBUSINESS.COM AIGBUSINESS.COM Financial Services Feb 14, 2026
95 ANSTECHINC.COM ANSTECHINC.COM 🇺🇸 United States Technology Feb 14, 2026
96 BE09.FR BE09.FR 🇫🇷 France Feb 14, 2026
97 BOYDEN.COM BOYDEN.COM 🇺🇸 United States Business Services Feb 14, 2026
98 BROADREACHRETAIL.COM BROADREACHRETAIL.COM 🇺🇸 United States Consumer Services Feb 14, 2026
99 CFDT.FR CFDT.FR 🇫🇷 France Public Sector Feb 14, 2026
100 CHEHARDY.COM CHEHARDY.COM 🇺🇸 United States Feb 14, 2026

Frequently Asked Questions

What is Clop ransomware?

Clop is a ransomware threat group that has claimed 829 victims since its first known activity in January 2024. The group operates by infiltrating target networks, exfiltrating data, encrypting files, and threatening to publish stolen data on a dark web leak site if the ransom is not paid.

How many victims has Clop attacked?

Clop has claimed 829 victims in our database, representing 3.9% of all tracked ransomware attacks. The most targeted countries are United States, Canada, United Kingdom, Australia.

Which countries does Clop target?

Clop has attacked organizations in 55 countries. The top targeted countries are: United States, Canada, United Kingdom, Australia.

Which industries does Clop target?

Clop most frequently targets the Technology, Consumer Services, Manufacturing sectors based on victim disclosures in our database.

Is Clop still active?

Clop's most recent victim disclosure in our database was on August 14, 2026. Ransomware groups frequently rebrand or go dormant; monitor this page and our ransomware map for the latest activity.