Sourced from leak-site trackers — reflects the group's claim of a victim, not a confirmed breach.
Cl0p is a financially motivated ransomware and data-extortion operation active since February 2019 and tied to the long-running Russian-speaking cybercrime group TA505. It is best known for pioneering large-scale, campaign-style exploitation of zero-day and n-day vulnerabilities in enterprise managed file transfer (MFT) products, breaching hundreds to thousands of organizations in a single wave. Over time the group has shifted from traditional encrypt-and-extort ransomware toward pure data theft and extortion, publishing victims on its 'CL0P^_- LEAKS' dark-web site.
Additional names this actor is known by across other vendors' naming schemes — cross-referenced from external crosswalk sources, not RaqibCTI's own curated aliases (shown at the top of this page). Each source is attributed to its own licence.
+83 more relationships — see the relationships browser.
Cl0p ransomware first appeared in February 2019 as a CryptoMix variant and was deployed in targeted 'big-game hunting' intrusions attributed to TA505, a criminal group active since at least 2014 known for mass malspam (Dridex, FlawedAmmyy, Get2/SDBbot) and driving global malware-distribution trends. Early Cl0p attacks used spearphishing and loaders to gain access, followed by hands-on-keyboard lateral movement and encryption, with double-extortion emerging as the group stood up a dedicated leak site.
The defining shift came with Cl0p's serial abuse of managed file transfer (MFT) appliances, which let it compromise many organizations at once through a single vulnerable, internet-facing product. In December 2020 through early 2021 the group mass-exploited zero-days in Accellion's legacy File Transfer Appliance (FTA), stealing data from dozens of organizations. In early 2023 it exploited CVE-2023-0669 in Fortra's GoAnywhere MFT. Its highest-impact campaign began on 27 May 2023 with exploitation of CVE-2023-34362, a SQL-injection zero-day in Progress Software's MOVEit Transfer, using the LEMURLOOT web shell to exfiltrate data; this campaign ultimately affected well over 2,000 organizations and tens of millions of individuals worldwide and was the subject of joint FBI/CISA advisory AA23-158A. In December 2024 Cl0p again claimed mass exploitation of file-transfer software, this time Cleo's LexiCom, VLTrader and Harmony products (CVE-2024-50623 and the CVE-2024-55956 zero-day), deploying a Java backdoor dubbed 'Malichus' and naming victims such as Blue Yonder.
Across these campaigns Cl0p progressively de-emphasized file encryption in favor of pure data-theft extortion: in several MFT campaigns little or no ransomware was actually detonated, and leverage came entirely from the threat to publish stolen data. The group is notable for its unusual public communications, occasional 'discounts,' and direct emailing of victims. In late 2025, extortion emails and exploitation of an Oracle E-Business Suite zero-day (CVE-2025-61882) were tied to actors claiming Cl0p affiliation, though that attribution was partly disputed in public reporting (low-to-medium confidence). As of this writing the operation is assessed active.
MENA relevance: Cl0p's victimology is opportunistic and vulnerability-driven, not geographically deliberate — targets are whoever runs an exposed, exploitable MFT appliance, and confirmed victim lists (Accellion, MOVEit, Cleo) are dominated by US and European organizations. I found no authoritative public reporting confirming intentional targeting of Egypt, Saudi Arabia or the UAE; any MENA entities affected would most plausibly appear incidentally via global third-party MFT usage. The current RaqibCTI Egypt/Saudi Arabia/UAE tags should therefore be treated as UNVERIFIED (likely aggregator/leak-site-derived or over-tagging) rather than confirmed deliberate MENA targeting — low confidence, recommend downgrading or annotating pending a named, sourced MENA victim.
These entities are frequently mentioned together in source material; co-occurrence is not a verified relationship.