Cl0p

Cl0p — Threat Actor Profile | ObscureIQ
ObscureIQ Threat Intelligence · Actor Profile

Cl0pConfidence: High

Ransomware · mass-exploitation specialist
Also known as: CL0P

Motivation: Financial

17Attributed Breaches
HighAttribution Confidence
RansomwareActor Type

Overview

Best known for mass exploitation of managed file transfer products, including the 2023 MOVEit Transfer campaign exploiting CVE-2023-34362. A mature extortion group associated in public reporting with the TA505 and FIN11-linked ecosystems.

Tactics, Targeting & TTPs

Signature: mass zero-day exploitation and data theft. Targeting: enterprise supply chains.

Related Clusters & Actors

Cl0pFIN11TA505

Source

Attribution draws on public threat-intelligence reporting · Established (multi-source). Primary source →

Were you exposed in one of these breaches?

Check your exposure privately, or request a tailored exposure audit.

Request Consultation