Financially motivated cybercriminal operation widely assessed to be run by or closely overlapping with the Russian-speaking group TA505 (and the related distribution cluster FIN11). CISA's AA23-158A explicitly equates the 'CL0P Ransomware Gang' with TA505. Attribution to a Russia/CIS nexus is based on Russian-language artifacts, operator tradecraft and the group's avoidance of CIS victims, and is assessed with medium confidence; precise membership and the TA505/FIN11/Cl0p boundary remain blurry in public reporting.
Origin
Russia (suspected, CIS/Russian-speaking; medium confidence)
First seen
2019
Last active
2025
Motivation
Financial gain through ransomware and, increasingly, pure data-theft extortion.
Rows marked inferred are OSINT-extracted enrichment for actors without a MITRE Group ID — treat as analyst assessment, not authoritative ATT&CK attribution.
[TA505](https://attack.mitre.org/groups/G0092) has used fast flux to mask botnets by distributing payloads across multiple IPs.(Citation: Trend Micro TA505 June 2019)
[TA505](https://attack.mitre.org/groups/G0092) has downloaded additional malware to execute on victim systems.(Citation: Cybereason TA505 April 2019)(Citation: Deep Instinct TA505 Apr 2019)(Citation: ProofPoint SettingContent-ms July 2018)
[TA505](https://attack.mitre.org/groups/G0092) has used malware to gather credentials from FTP clients and Outlook.(Citation: Proofpoint TA505 Sep 2017)
[TA505](https://attack.mitre.org/groups/G0092) has signed payloads with code signing certificates from Thawte and Sectigo.(Citation: Cybereason TA505 April 2019)(Citation: Deep Instinct TA505 Apr 2019)(Citation: Trend Micro TA505 June 2019)
[TA505](https://attack.mitre.org/groups/G0092) has used malware to disable Windows Defender through modification of the Registry.(Citation: Korean FSI TA505 2020)
[TA505](https://attack.mitre.org/groups/G0092) has used TinyMet to enumerate members of privileged groups.(Citation: IBM TA505 April 2020) [TA505](https://attack.mitre.org/groups/G0092) has also run <code>net group /domain</code>.(Citation: Trend Micro TA505 June 2019)
[TA505](https://attack.mitre.org/groups/G0092) has used the tool EmailStealer to steal and send lists of e-mail addresses to a remote server.(Citation: Trend Micro TA505 June 2019)
[TA505](https://attack.mitre.org/groups/G0092) has used lures to get users to click links in emails and attachments. For example, [TA505](https://attack.mitre.org/groups/G0092) makes their malware look like legitimate Microsoft Word documents, .pdf and/or .lnk files. (Citation: Proofpoint TA505 Sep
[TA505](https://attack.mitre.org/groups/G0092) has used JavaScript for code execution.(Citation: Proofpoint TA505 Sep 2017)(Citation: Proofpoint TA505 June 2018)
[TA505](https://attack.mitre.org/groups/G0092) has used VBS for code execution.(Citation: Proofpoint TA505 Sep 2017)(Citation: Proofpoint TA505 June 2018)(Citation: Trend Micro TA505 June 2019)(Citation: IBM TA505 April 2020)
[TA505](https://attack.mitre.org/groups/G0092) has used PowerShell to download and execute malware and reconnaissance scripts.(Citation: Proofpoint TA505 Sep 2017)(Citation: ProofPoint SettingContent-ms July 2018)(Citation: Cybereason TA505 April 2019)(Citation: Deep Instinct TA505 Apr 2019)
[TA505](https://attack.mitre.org/groups/G0092) has used lures to get users to enable content in malicious attachments and execute malicious files contained in archives. For example, [TA505](https://attack.mitre.org/groups/G0092) makes their malware look like legitimate Microsoft Word documents, .pdf
[TA505](https://attack.mitre.org/groups/G0092) has deployed payloads that use Windows API calls on a compromised host.(Citation: Korean FSI TA505 2020)
[TA505](https://attack.mitre.org/groups/G0092) has used a wide variety of ransomware, such as [Clop](https://attack.mitre.org/software/S0611), Locky, Jaff, Bart, Philadelphia, and GlobeImposter, to encrypt victim files and demand a ransom payment.(Citation: Proofpoint TA505 Sep 2017)
[TA505](https://attack.mitre.org/groups/G0092) has used spearphishing emails with malicious attachments to initially compromise victims.(Citation: Proofpoint TA505 Sep 2017)(Citation: Proofpoint TA505 June 2018)(Citation: Proofpoint TA505 Jan 2019)(Citation: Cybereason TA505 April 2019)(Citation: Pr
[TA505](https://attack.mitre.org/groups/G0092) has sent spearphishing emails containing malicious links.(Citation: Proofpoint TA505 Sep 2017)(Citation: Proofpoint TA505 Jan 2019)(Citation: Trend Micro TA505 June 2019)(Citation: Proofpoint TA505 October 2019)
[TA505](https://attack.mitre.org/groups/G0092) has used malware such as [Azorult](https://attack.mitre.org/software/S0344) and [Cobalt Strike](https://attack.mitre.org/software/S0154) in their operations.(Citation: NCC Group TA505)
[TA505](https://attack.mitre.org/groups/G0092) has registered domains to impersonate services such as Dropbox to distribute malware.(Citation: Korean FSI TA505 2020)
[TA505](https://attack.mitre.org/groups/G0092) has used a variety of tools in their operations, including [AdFind](https://attack.mitre.org/software/S0552), [BloodHound](https://attack.mitre.org/software/S0521), [Mimikatz](https://attack.mitre.org/software/S0002), and [PowerSploit](https://attack.mi
[TA505](https://attack.mitre.org/groups/G0092) has leveraged <code>rundll32.exe</code> to execute malicious DLLs.(Citation: Cybereason TA505 April 2019)(Citation: Deep Instinct TA505 Apr 2019)
[TA505](https://attack.mitre.org/groups/G0092) has used base64 encoded PowerShell commands.(Citation: Cybereason TA505 April 2019)(Citation: Deep Instinct TA505 Apr 2019)
[TA505](https://attack.mitre.org/groups/G0092) has used <code>msiexec</code> to download and execute malicious Windows Installer files.(Citation: Cybereason TA505 April 2019)(Citation: Deep Instinct TA505 Apr 2019)(Citation: Trend Micro TA505 June 2019)
Associated software
16 linked · 16 ATT&CK-attributed, 0 curated
Malware and tools this actor is known to use. ATT&CK-attributed rows are MITRE's own software↔group relationships; curated rows fill the gap for MENA actors ATT&CK doesn't track — treat those as analyst assessment, not authoritative attribution.
ATT&CK-attributed · 16
Sourced from MITRE ATT&CK's own uses relationships for this group.
Regional co-occurrence is association, not prediction. These techniques appeared alongside Cl0p's activity across the tracked MENA roster — a TIE-style association computed on our corpus (not CTID's model), not a prediction of the next move. Ranked by support-adjusted lift (over-representation among actors like this one vs. the roster base rate, damped when few actors back it), so neither a merely-common technique nor a tiny-sample coincidence floats to the top. A hunting lead only; never recorded as observed. ICS techniques are excluded.
Which Microsoft 365 controls protect, detect, or respond to this actor's techniques — from the CTID Mappings Explorer (technique-level). Strength: significant / partial / minimal.
protect · 15 techniques
Password PolicyT1078significantInformation ProtectionT1070significantIdentity Secure ScoreT1078minimalIdentity Secure ScoreT1078.002minimalMultifactor AuthenticationT1078minimalPrivileged Identity ManagementT1078minimalAdvanced Anti-Phishing T1566partialRole Based Access ControlT1087minimalAnti-SpoofingT1566significantIdentity Secure ScoreT1552minimalAntimalwareT1204.002significantMultifactor AuthenticationT1566partialMultifactor AuthenticationT1566.001partialMultifactor AuthenticationT1566.002partialPrivileged Identity ManagementT1136partialAnti-SpoofingT1566.002significantAudit SolutionsT1566.002partialAntimalwareT1204significantConditional AccessT1078minimalAntimalwareT1059significantAntimalwareT1059.001significantAdvanced Anti-Phishing T1566.001partialAntiSpamT1566significantAntiSpamT1566.001significantAntimalwareT1566significantAntimalwareT1566.001significantAnti-PhishingT1027.013partialRole Based Access ControlT1059minimalRole Based Access ControlT1078minimalRole Based Access ControlT1136minimalPassword ProtectionT1078partialAudit SolutionsT1078partialAdvanced Anti-Phishing T1566.002partialAntiSpamT1566.002significantAntimalwareT1027significantAnti-PhishingT1566significantAnti-PhishingT1566.001significantAnti-PhishingT1566.002significantAudit SolutionsT1552partial
Quarantine PoliciesT1566significantQuarantine PoliciesT1566.001significantIncident ResponseT1078minimalZero Hour Auto PurgeT1204significantZero Hour Auto PurgeT1204.001significantAdvanced Anti-Phishing T1566.001partialZero Hour Auto PurgeT1204.002significantAutomated Investigation and ResponseT1566.002significantIncident ResponseT1552minimalIncident ResponseT1566minimalATT&CK Simulation TrainingT1204partialATT&CK Simulation TrainingT1566.002partialQuarantine PoliciesT1027significant
Countermeasures · D3FEND
Defensive techniques that counter Cl0p's TTPs, from MITRE D3FEND. The ATT&CK↔D3FEND link is mitigation-mediated — treat these as candidate countermeasures, not prescriptions.