Attribution
Financially motivated cybercriminal operation widely assessed to be run by or closely overlapping with the Russian-speaking group TA505 (and the related distribution cluster FIN11). CISA's AA23-158A explicitly equates the 'CL0P Ransomware Gang' with TA505. Attribution to a Russia/CIS nexus is based on Russian-language artifacts, operator tradecraft and the group's avoidance of CIS victims, and is assessed with medium confidence; precise membership and the TA505/FIN11/Cl0p boundary remain blurry in public reporting.
Origin
Russia (suspected, CIS/Russian-speaking; medium confidence)
Motivation
Financial gain through ransomware and, increasingly, pure data-theft extortion.
Attribution confidence
medium
MENA targeting
Egypt, Saudi Arabia, UAE
Sectors
Energy/utilities, manufacturing, retail
Sourced from leak-site trackers — reflects the group's claim of a victim, not a confirmed breach.
Why it mattersRansomware actor, medium confidence, documented targeting Egypt, Saudi Arabia, UAE (Energy/utilities, manufacturing, retail sectors).
What's nextNo pipeline reports reference this actor yet — Radar mentions may still surface early signal.