TA505 is a prolific financially motivated cybercrime actor widely associated with the Cl0p ransomware and extortion ecosystem. The group has been active since at least the mid-2010s and is commonly linked to large-scale phishing operations, malware delivery, and later ransomware monetization. Cl0p, also written Clop or Cl0p, is closely tied to TA505 and has operated in ransomware-as-a-service and data-extortion campaigns. Reported aliases and related tracking names include Graceful Spider, Gold Tahoe, Lace Tempest, DEV-0950, Monty Spider, Spandex Tempest, and Hive0065, although some of these labels may refer to overlapping clusters, affiliates, or vendor-specific sub-groupings within the broader Cl0p/TA505 ecosystem. TA505 and the Cl0p ecosystem have repeatedly targeted high-value enterprise software and public-facing applications, especially managed file transfer and enterprise back-office platforms. Campaigns have been linked to exploitation of Accellion FTA, GoAnywhere MFT, MOVEit Transfer, Oracle E-Business Suite, Cleo software, SysAid, and PTC Windchill and FlexPLM. In multiple cases, the actor exploited zero-day or newly disclosed vulnerabilities at scale, deployed web shells for persistence, enumerated victim environments, staged and exfiltrated sensitive data, and then used extortion emails and leak-site pressure to coerce payment. In some campaigns, particularly those involving file-transfer appliances and enterprise applications, the actor emphasized data theft and extortion over encryption-only operations. Observed intrusion methods include spear-phishing, exploitation of public-facing applications, use of compromised remote access credentials, PowerShell and command-shell execution, web-shell persistence, process injection, and use of Cobalt Strike for command and control and post-exploitation. Historical reporting also links TA505-associated activity to malware such as SDBot, FlawedAmmy RAT, and Gracewire in certain intrusion chains. In recent Windchill and FlexPLM campaigns, Cl0p-linked operators were reported deploying JSP web shells, conducting file-system discovery, stealing engineering and product-design data, and pursuing double-extortion against organizations holding valuable intellectual property. Victimology spans multiple sectors, with repeated targeting of financial services, healthcare, manufacturing, retail/apparel, aerospace and defense-adjacent engineering environments, and government-related entities. The United States has been a prominent target, with additional activity reported against organizations in Canada, India, China, Singapore, Italy, and the United Kingdom. The actor's dominant motivation is financial gain through ransomware, data theft, and extortion.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
26 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
40 malware families attributed to this actor across reporting.
35 additional families tracked in Mallory.
15 CVEs this actor has used in observed campaigns. 15 of them exploited in the wild.
According to reports by Google and Mandiant, the hacking group utilized several Oracle EBS vulnerabilities, including the zero-day flaw with the reference number CVE-2025-61882, to initiate attacks against other companies. The vulnerability that was most likely used in the attack allowed malicious cyber actors to deploy arbitrary code via an unauthenticated HTTP request and affected all Oracle EBS versions from 12.2.3 to 12.2.14. Notably, Oracle released a security patch on October 4, 2025, after detecting that the vulnerability was being actively exploited.
Clop ransomware specifically targets the MOVEIT Transfer vulnerability... The threat actors took advantage of a SQL injection vulnerability present in the web application of MOVEIT Transfer. They exploited this vulnerability by installing a webshell known as LEMURLOOT.
Clop has reportedly been exploiting a critical improper input validation vulnerability tracked as CVE-2026-12569, which allows attackers to execute arbitrary code on vulnerable Windchill and FlexPLM instances. The flaw is described as a critical unsafe deserialization vulnerability (CVSS 9.3) affecting PTC Windchill and FlexPLM; exploitation enables unauthenticated remote code execution and JSP web shell deployment for remote command execution and sensitive product data exfiltration.
Zraniteľnosť CVE-2024-55956 možno zneužiť na získanie neoprávneného prístupu k citlivým údajom, vykonanie neoprávnených zmien v systéme a vzdialené vykonanie kódu... V súčasnosti je dostupný Proof of Concept (PoC)... Zraniteľnosť aktívne zneužívajú útočníci minimálne od 3. decembra 2024. Ransomvérová skupina CLOP ju v rámci útokov zneužíva na krádež citlivých údajov.
Spoločnosť Oracle vydala bezpečnostnú aktualizáciu na svoj produkt E-Business Suite, ktorá opravuje vysoko závažnú zraniteľnosť. CVE-2025-61884 by vzdialený neautentifikovaný útočník zaslaním špeciálne vytvorených HTTP požiadaviek mohol zneužiť na kompromitáciu Oracle Configurator a získanie neoprávneného prístupu k citlivým údajom. [aktualizácia 21.10.2025] zraniteľnosť CVE-2025-61884 bola pridaná do zoznamu aktívne zneužívaných
10 more CVEs tied to this actor tracked in Mallory.
461 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Targeted exposed AI and product-lifecycle platforms for encryption, data theft, and extortion.
Conducting a ransomware attack resulting in a data breach against MINDRAY.COM.
Mentioned only as a comparison point for GoldenEyeDog’s sophistication.
Exploited the MOVEit SQL injection vulnerability in a mass data-theft campaign affecting thousands of organizations.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.