Clop Ransomware
ActiveThreat actor group tracked in the global ransomware database · Last disclosure: Aug 14, 2026
ThreatAI Analysis
Compiled from the ransomware.live profile for Clop and from this database. Figures and technique mappings are quoted from the source data, not inferred.
Ransomware group Clop has recorded 829 victims and hit 55 countries, primarily targeting tech firms, consumer services, and manufacturing sectors through financially-motivated cyberattacks.
Who Clop is
The ransomware group known as Cl0p is a variant of a previously known strain dubbed CryptoMix. It is worth noting that this variant was delivered as the final payload in a phishing campaign in 2019 and was exclusively financially motivated, with attacks carried out by the threat actors TA505. At that time, malicious actors sent phishing emails that led to a macro-enabled document that would drop a loader called 'Get2.' After gaining an initial foothold in the system or infrastructure, the actors began using reconnaissance, lateral movement, and exfiltration techniques to prepare for the deployment of the ransomware. After the execution of the ransomware, Cl0p appends the extension '.clop' to the end of files, or other types of extensions such as '.CIIp, .Cllp, and .C_L_O_P,' as well as different versions of the ransom note that were also observed after encryption. Depending on the varian
Recorded activity
Disclosures attributed to Clop in this database run from January 2024 to August 2026, totalling 829 victims — 3.9% of everything tracked here. Clop has listed victims in 55 countries in this database, most often United States, followed by Canada and United Kingdom. The sectors appearing most in its listings are Technology, Consumer Services, Manufacturing.
How Clop is documented to operate
Valid Accounts T1078 Stealth Persistence
Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network.
Mitigations: Application Developer Guidance, User Training, Password Policies, User Account Management, Privileged Account Management, Multi-factor Authentication
MITRE ATT&CK reference →Exploit Public-Facing Application T1190 Initial Access
Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration. Exploited applications are often websites/web servers, but can also include databases (like SQL), standard services (like SMB or SSH), network device administration and management protocols (like SNMP and Smart Install), and any other system with Internet-accessible open sockets. On ESXi infrastructure, adversaries may exploit exposed OpenSLP services; they may alternatively exploit exposed VMware vCenter servers.
Mitigations: Vulnerability Scanning, Limit Access to Resource Over Network, Filter Network Traffic, Network Segmentation, Privileged Account Management, Application Isolation and Sandboxing
MITRE ATT&CK reference →Command and Scripting Interpreter T1059 Execution
Adversaries may abuse command and script interpreters to execute commands, scripts, or binaries. These interfaces and languages provide ways of interacting with computer systems and are a common feature across many different platforms. Most systems come with some built-in command-line interface and scripting capabilities, for example, macOS and Linux distributions include some flavor of Unix Shell while Windows installations include the Windows Command Shell and PowerShell. There are also cross-platform interpreters such as Python, as well as those commonly associated with client applications such as JavaScript and Visual Basic.
Mitigations: Restrict Web-Based Content, Limit Software Installation, Execution Prevention, Code Signing, Behavior Prevention on Endpoint, Privileged Account Management
MITRE ATT&CK reference →Native API T1106 Execution
Adversaries may interact with the native OS application programming interface (API) to execute behaviors. Native APIs provide a controlled means of calling low-level OS services within the kernel, such as those involving hardware/devices, memory, and processes. These native APIs are leveraged by the OS during system boot (when other system components are not yet initialized) as well as carrying out tasks and requests during routine operations. Adversaries may abuse these OS API functions as a means of executing behaviors.
Mitigations: Execution Prevention, Behavior Prevention on Endpoint
MITRE ATT&CK reference →User Execution T1204 Execution
An adversary may rely upon specific actions by a user in order to gain execution. Users may be subjected to social engineering to get them to execute malicious code by, for example, opening a malicious document file or link. These user actions will typically be observed as follow-on behavior from forms of Phishing. While User Execution frequently occurs shortly after Initial Access it may occur at other phases of an intrusion, such as when an adversary places a file in a shared directory or on a user's desktop hoping that a user will click on it. This activity may also be seen shortly after Internal Spearphishing.
Mitigations: Network Intrusion Prevention, Restrict Web-Based Content, Limit Software Installation, User Training, Execution Prevention, Behavior Prevention on Endpoint
MITRE ATT&CK reference →Boot or Logon Autostart Execution T1547 Persistence Privilege Escalation
Adversaries may configure system settings to automatically execute a program during system boot or logon to maintain persistence or gain higher-level privileges on compromised systems. Operating systems may have mechanisms for automatically running a program on system boot or account logon. These mechanisms may include automatically executing programs that are placed in specially designated directories or are referenced by repositories that store configuration information, such as the Windows Registry. An adversary may achieve the same goal by modifying or extending features of the kernel.
MITRE ATT&CK reference →Exploitation for Privilege Escalation T1068 Privilege Escalation
Adversaries may exploit software vulnerabilities in an attempt to elevate privileges. Exploitation of a software vulnerability occurs when an adversary takes advantage of a programming error in a program, service, or within the operating system software or kernel itself to execute adversary-controlled code. Security constructs such as permission levels will often hinder access to information and use of certain techniques, so adversaries will likely need to perform privilege escalation to include use of software exploitation to circumvent those restrictions.
Mitigations: Execution Prevention, Threat Intelligence Program, Application Isolation and Sandboxing, Exploit Protection, Update Software
MITRE ATT&CK reference →MITRE ATT&CK techniques attributed to Clop across its recorded activity. They describe the group overall, not any single incident.
Vulnerabilities Clop is recorded exploiting
- CVE-2024-55956 — Cleo VLTrader, Harmony, LexiCom (CRITICAL 9.8) · CISA KEV (patch due 7 Jan 2025)
- CVE-2025-61882 — Oracle E-Business (CRITICAL 9.8) · CISA KEV (patch due 27 Oct 2025)
- CVE-2023-34362 — Progress Software MOVEit (CRITICAL 9.8) · CISA KEV (patch due 23 Jun 2023)
- CVE-2021-35211 — SolarWinds Serv-U FTP (CRITICAL 9) · CISA KEV (patch due 17 Nov 2021)
- CVE-2023-0669 — Fortra GoAnywhere Managed File Transfer (HIGH 7.2) · CISA KEV (patch due 3 Mar 2023)
5 of these 5 are in the CISA Known Exploited Vulnerabilities catalog, 5 of them recorded by CISA as used in ransomware campaigns. CVEs attributed to Clop in threat intelligence reporting. Patching these does not by itself rule the group out, and their presence here is not evidence of how any single organisation was reached.
Tooling observed in Clop operations
- Cobalt Strike
- PowerShell Empire
- TinyMet
Software reported in use by Clop. Most are legitimate administration or transfer utilities; their presence in an environment is a signal to investigate, not proof of compromise.
Threat Actor Analysis
Clop is a ransomware threat group that has disclosed 829 victims in publicly accessible leak site data, representing 3.9% of all ransomware attacks tracked in this database. The earliest victim disclosure attributed to Clop in our dataset dates to January 2024.
Geographically, Clop has targeted organisations in 55 countries. The most frequently targeted nation is United States with 426 victim organisations. Other heavily targeted nations include Canada, United Kingdom, Australia.
Industry-wise, Clop shows a concentration in the Technology, Consumer Services, Manufacturing sectors. These industries are frequently targeted because they manage sensitive data, critical operations, or have lower tolerance for operational downtime — conditions that increase ransom payment likelihood.
Like most modern ransomware operations, Clop likely employs a double extortion model: encrypting victim files while simultaneously exfiltrating data, creating dual pressure to pay the ransom. Victim organisations that refuse payment face having their data published on the group's dark web leak site.
Note: This profile is generated from public leak site disclosures aggregated via the ransomware.live API. Data is updated automatically. The table below lists the 100 most recent of the 829 disclosures we hold for this group; use the link beneath it to page through all of them.
Recent Victim Disclosures (showing 100 of 829)
| # | Organization | Country | Sector | Date |
|---|---|---|---|---|
| 1 | ZEBRA.COM ZEBRA.COM | 🇺🇸 United States | Manufacturing | Aug 14, 2026 |
| 2 | 9ALTITUDES.COM 9ALTITUDES.COM | 🇮🇳 India | Technology | Aug 12, 2026 |
| 3 | ALDOGROUP.COM (ALDOSHOES.COM) ALDOSHOES.COM | 🇨🇦 Canada | Retail & E-Commerce | Aug 12, 2026 |
| 4 | AOL.COM AOL.COM | 🇺🇸 United States | Technology | Aug 12, 2026 |
| 5 | ARCHERGREY.COM ARCHERGREY.COM | 🇺🇸 United States | Other | Aug 12, 2026 |
| 6 | ATOMBERG.COM ATOMBERG.COM | 🇮🇳 India | Manufacturing | Aug 12, 2026 |
| 7 | BRILLONCONSUMER.COM (BRILLONCONSUMER.COM) BRILLONCONSUMER.COM | 🇲🇽 Mexico | Retail & E-Commerce | Aug 12, 2026 |
| 8 | CLOVER.COM CLOVER.COM | 🇺🇸 United States | Retail & E-Commerce | Aug 12, 2026 |
| 9 | CORNELIUS.COM CORNELIUS.COM | 🇺🇸 United States | Other | Aug 12, 2026 |
| 10 | ECCELLENT.COM ECCELLENT.COM | 🇮🇹 Italy | Other | Aug 12, 2026 |
| 11 | ENTERATEK.MXESBERBEVERAGE.COM ENTERATEK.MXESBERBEVERAGE.COM | 🇲🇽 Mexico | Agriculture and Food Production | Aug 12, 2026 |
| 12 | FISERV.COM FISERV.COM | 🇺🇸 United States | Financial Services | Aug 12, 2026 |
| 13 | FLUIDLOGIC.COM FLUIDLOGIC.COM | 🇺🇸 United States | Technology | Aug 12, 2026 |
| 14 | G3AEROSPACE.COM G3AEROSPACE.COM | 🇺🇸 United States | Government & Defense | Aug 12, 2026 |
| 15 | GATE7LLC.COMGBBEV.COM GATE7LLC.COMGBBEV.COM | 🇬🇧 United Kingdom | — | Aug 12, 2026 |
| 16 | GE.COM GE.COM | 🇺🇸 United States | Technology | Aug 12, 2026 |
| 17 | HONGHE-TECH.COM HONGHE-TECH.COM | 🇨🇳 China | Technology | Aug 12, 2026 |
| 18 | INTELLIGENTGROWTHSOLUTIONS.COM INTELLIGENTGROWTHSOLUTIONS.COM | 🇺🇸 United States | Professional Services | Aug 12, 2026 |
| 19 | INTELLIHOT.COM INTELLIHOT.COM | 🇺🇸 United States | Hospitality | Aug 12, 2026 |
| 20 | IPMSOLUTIONS.SK IPMSOLUTIONS.SK | 🇸🇰 Slovakia | Professional Services | Aug 12, 2026 |
| 21 | IRCO.COM IRCO.COM | IR | — | Aug 12, 2026 |
| 22 | ITKHOLDING.HU ITKHOLDING.HU | 🇭🇺 Hungary | Technology | Aug 12, 2026 |
| 23 | IVALUESYS.COM IVALUESYS.COM | 🇺🇸 United States | Technology | Aug 12, 2026 |
| 24 | JPMGROUP.CO.IN JPMGROUP.CO.IN | 🇮🇳 India | Financial Services | Aug 12, 2026 |
| 25 | LARGAN.COM.TW LARGAN.COM.TW | 🇹🇼 Taiwan | Manufacturing | Aug 12, 2026 |
| 26 | LIFESTRAW.COM LIFESTRAW.COM | 🇺🇸 United States | Retail & E-Commerce | Aug 12, 2026 |
| 27 | MAMASANDPAPAS.COM MAMASANDPAPAS.COM | 🇬🇧 United Kingdom | Retail & E-Commerce | Aug 12, 2026 |
| 28 | MAMMUT.COM MAMMUT.COM | 🇨🇭 Switzerland | Retail & E-Commerce | Aug 12, 2026 |
| 29 | MIDLANDIND.COM.AU MIDLANDIND.COM.AU | 🇦🇺 Australia | Manufacturing | Aug 12, 2026 |
| 30 | NETPOWER.COM NETPOWER.COM | — | Technology | Aug 12, 2026 |
| 31 | NUOVACMM.COM NUOVACMM.COM | 🇮🇹 Italy | Other | Aug 12, 2026 |
| 32 | NUVITIA.COM NUVITIA.COM | 🇫🇷 France | Technology | Aug 12, 2026 |
| 33 | OMNITANKER.COM OMNITANKER.COM | 🇺🇸 United States | Transportation | Aug 12, 2026 |
| 34 | PARTECH.COM PARTECH.COM | 🇺🇸 United States | Technology | Aug 12, 2026 |
| 35 | PHILIPS.COM PHILIPS.COM | 🇳🇱 Netherlands | Healthcare | Aug 12, 2026 |
| 36 | QCPL.IN QCPL.IN | 🇮🇳 India | Manufacturing | Aug 12, 2026 |
| 37 | SHELL.COM (August 2026) SHELL.COM | 🇬🇧 United Kingdom | Energy & Utilities | Aug 12, 2026 |
| 38 | SMAPCENTER.UAH.EDU SMAPCENTER.UAH.EDU | 🇺🇸 United States | Education | Aug 12, 2026 |
| 39 | SPKAA.COM SPKAA.COM | KZ | — | Aug 12, 2026 |
| 40 | STARKEY.COM STARKEY.COM | 🇺🇸 United States | Healthcare | Aug 12, 2026 |
| 41 | STNET.IT STNET.IT | 🇮🇹 Italy | Technology | Aug 12, 2026 |
| 42 | SUUNTO.CN (SUUNTO.COM) SUUNTO.COM | 🇫🇮 Finland | Retail & E-Commerce | Aug 12, 2026 |
| 43 | THERMOS.COM THERMOS.COM | 🇺🇸 United States | Retail & E-Commerce | Aug 12, 2026 |
| 44 | TOASTTAB.COM TOASTTAB.COM | 🇺🇸 United States | Hospitality | Aug 12, 2026 |
| 45 | TRISTAR.COM TRISTAR.COM | 🇺🇸 United States | Other | Aug 12, 2026 |
| 46 | WATERLANDPE.COM WATERLANDPE.COM | 🇵🇪 Peru | Other | Aug 12, 2026 |
| 47 | CONTINENTAL.AERO CONTINENTAL.AERO | 🇺🇸 United States | Transportation | Aug 7, 2026 |
| 48 | MINDRAY.COM MINDRAY.COM | 🇨🇳 China | Healthcare | Aug 7, 2026 |
| 49 | 9al******* | — | — | Aug 5, 2026 |
| 50 | ald******* | — | — | Aug 5, 2026 |
| 51 | arc******* | — | Technology | Aug 5, 2026 |
| 52 | ato******* | — | — | Aug 5, 2026 |
| 53 | bri******* | — | Financial Services | Aug 5, 2026 |
| 54 | clo******* | — | — | Aug 5, 2026 |
| 55 | cor******* | — | — | Aug 5, 2026 |
| 56 | ecc******* | — | — | Aug 5, 2026 |
| 57 | fis******* | — | Financial Services | Aug 5, 2026 |
| 58 | flu******* | — | — | Aug 5, 2026 |
| 59 | g******* | — | Technology | Aug 5, 2026 |
| 60 | G3A******* | — | — | Aug 5, 2026 |
| 61 | hon******* | — | — | Aug 5, 2026 |
| 62 | int******* | — | Technology | Aug 5, 2026 |
| 63 | ipm******* | — | — | Aug 5, 2026 |
| 64 | ir****** | — | — | Aug 5, 2026 |
| 65 | itk******* | — | — | Aug 5, 2026 |
| 66 | iva******* | — | — | Aug 5, 2026 |
| 67 | jpm******* | — | Financial Services | Aug 5, 2026 |
| 68 | lar******* | — | — | Aug 5, 2026 |
| 69 | lif******* | — | — | Aug 5, 2026 |
| 70 | mam******* | — | — | Aug 5, 2026 |
| 71 | mid******* | — | — | Aug 5, 2026 |
| 72 | net******* | — | — | Aug 5, 2026 |
| 73 | nuo******* | — | — | Aug 5, 2026 |
| 74 | nuv******* | — | — | Aug 5, 2026 |
| 75 | omn******* | — | — | Aug 5, 2026 |
| 76 | par******* | — | Technology | Aug 5, 2026 |
| 77 | phi******* | — | — | Aug 5, 2026 |
| 78 | qc******* | — | — | Aug 5, 2026 |
| 79 | sh******* | — | — | Aug 5, 2026 |
| 80 | sma******* | — | — | Aug 5, 2026 |
| 81 | sp******* | — | — | Aug 5, 2026 |
| 82 | st******* | — | — | Aug 5, 2026 |
| 83 | sta******* | — | — | Aug 5, 2026 |
| 84 | suu******* | — | — | Aug 5, 2026 |
| 85 | the******* | — | — | Aug 5, 2026 |
| 86 | toa******* | — | — | Aug 5, 2026 |
| 87 | tri******* | — | — | Aug 5, 2026 |
| 88 | wat******* | — | — | Aug 5, 2026 |
| 89 | BLUEVISTALLC.COM BLUEVISTALLC.COM | 🇺🇸 United States | — | Jul 31, 2026 |
| 90 | INJURYLAWYERS.COM INJURYLAWYERS.COM | 🇺🇸 United States | Business Services | May 1, 2026 |
| 91 | INTEGRALIFE.COM INTEGRALIFE.COM | 🇺🇸 United States | Healthcare | May 1, 2026 |
| 92 | AIGHEALTHCARE.IN AIGHEALTHCARE.IN | 🇮🇳 India | Healthcare | Mar 30, 2026 |
| 93 | CLOUD.CLEARWAYGROUP.COM CLOUD.CLEARWAYGROUP.COM | — | Technology | Mar 30, 2026 |
| 94 | AIGBUSINESS.COM AIGBUSINESS.COM | — | Financial Services | Feb 14, 2026 |
| 95 | ANSTECHINC.COM ANSTECHINC.COM | 🇺🇸 United States | Technology | Feb 14, 2026 |
| 96 | BE09.FR BE09.FR | 🇫🇷 France | — | Feb 14, 2026 |
| 97 | BOYDEN.COM BOYDEN.COM | 🇺🇸 United States | Business Services | Feb 14, 2026 |
| 98 | BROADREACHRETAIL.COM BROADREACHRETAIL.COM | 🇺🇸 United States | Consumer Services | Feb 14, 2026 |
| 99 | CFDT.FR CFDT.FR | 🇫🇷 France | Public Sector | Feb 14, 2026 |
| 100 | CHEHARDY.COM CHEHARDY.COM | 🇺🇸 United States | — | Feb 14, 2026 |
Frequently Asked Questions
What is Clop ransomware?
Clop is a ransomware threat group that has claimed 829 victims since its first known activity in January 2024. The group operates by infiltrating target networks, exfiltrating data, encrypting files, and threatening to publish stolen data on a dark web leak site if the ransom is not paid.
How many victims has Clop attacked?
Clop has claimed 829 victims in our database, representing 3.9% of all tracked ransomware attacks. The most targeted countries are United States, Canada, United Kingdom, Australia.
Which countries does Clop target?
Clop has attacked organizations in 55 countries. The top targeted countries are: United States, Canada, United Kingdom, Australia.
Which industries does Clop target?
Clop most frequently targets the Technology, Consumer Services, Manufacturing sectors based on victim disclosures in our database.
Is Clop still active?
Clop's most recent victim disclosure in our database was on August 14, 2026. Ransomware groups frequently rebrand or go dormant; monitor this page and our ransomware map for the latest activity.