Clop (Cl0p) is a financially motivated ransomware group operated by TA505, targeting global sectors.
Analyst brief
Clop (Cl0p) is a financially motivated ransomware group, previously a variant of CryptoMix, operated by the TA505 threat actors. They target a wide range of sectors globally, including Technology, Healthcare, Manufacturing, and Financial Services, with victims in the US, UK, India, and China. Their core TTPs involve phishing campaigns delivering macro-enabled documents that drop the Get2 loader, followed by reconnaissance, lateral movement, and data exfiltration prior to ransomware deployment. Defenders should focus on blocking suspicious macros, securing email gateways, and monitoring for signs of lateral movement and unauthorized data staging.
clop
Cl0p
activecrime
The ransomware group known as Cl0p is a variant of a previously known strain dubbed CryptoMix. It is worth noting that this variant was delivered as the final payload in a phishing campaign in 2019 and was exclusively financially motivated, with attacks carried out by the threat actors TA505.<br> <br> At that time, malicious actors sent phishing emails that led to a macro-enabled document that would drop a loader called 'Get2.' After gaining an initial foothold in the system or infrastructure, the actors began using reconnaissance, lateral movement, and exfiltration techniques to prepare for the deployment of the ransomware.<br> <br> After the execution of the ransomware, Cl0p appends the extension '.clop' to the end of files, or other types of extensions such as '.CIIp, .Cllp, and .C_L_O_P,' as well as different versions of the ransom note that were also observed after encryption. Depending on the variant, any of the ransom text files were created with names like 'ClopReadMe.txt, README_README.txt, Cl0pReadMe.txt, and READ_ME_!!!.TXT.'<br> <br> The Clop operation has shifted from delivering its final payload via phishing and has begun initiating attacks using vulnerabilities that
observed victims (by country)
United StatesIndiaItalyUnited Kingdom
observed sectors
TechnologyRetail & E-CommerceManufacturingNot Found
How does the Clop ransomware group gain initial access to a system?+
They typically use phishing emails that deliver macro-enabled documents. When opened, this document drops a loader called 'Get2,' providing the initial foothold in the system.
What stages are executed after the initial access in a Clop ransomware attack?+
After gaining the initial foothold, TA505 actors use reconnaissance, lateral movement, and data exfiltration techniques to prepare for the deployment of the ransomware.