Clop is a financially motivated cybercrime and ransomware/extortion operation, also tracked as TA505, Graceful Spider, and Lace Tempest-related activity; Lace Tempest was formerly tracked as DEV-0950. The operation has conducted campaigns since at least 2020 that exploit vulnerabilities, including zero-days, in widely deployed managed file-transfer and enterprise software. Prominent targeted products have included Accellion FTA, GoAnywhere MFT, MOVEit Transfer, Cleo products, PaperCut, and PTC Windchill and FlexPLM. Clop commonly uses software-vulnerability exploitation for initial access, steals centrally held enterprise data, and extorts affected organizations. Its operations have included both ransomware-enabled double extortion and encryption-less data-theft extortion, supported by public leak-site pressure. Clop-linked activity has targeted organizations holding sensitive government, health-care, educational, and manufacturing data. The group has also been associated with ransomware-as-a-service activity and affiliates, including Lace Tempest, which used PaperCut vulnerabilities for initial access in 2023. Clop's large-scale exploitation campaigns have affected organizations internationally.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
36 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
42 malware families attributed to this actor across reporting.
37 additional families tracked in Mallory.
19 CVEs this actor has used in observed campaigns. 19 of them exploited in the wild.
Oracle released a security advisory addressing a critical, zero-day vulnerability impacting its E-Business Suite (EBS), identified during their investigation into the recently disclosed extortion campaign targeting EBS customers. CVE-2025-61882 (CVSS: 9.8) resides within the Oracle Concurrent Processing component's BI Publisher Integration in the EBS. It allows an unauthenticated attacker with network access via HTTP to potentially compromise the Concurrent Processing product.
PTC disclosed CVE-2026-12569 and issued remediation guidance in June, and CISA added the flaw to its Known Exploited Vulnerabilities catalog on June 25. Researchers assess exploitation may have begun earlier that month.
This week, new updates related to the previous MOVEit Transfer vulnerability CVE-2023-34362 were disclosed. The company Horizon3 has released technical details and Proof-of-Concept (PoC) exploit code for the vulnerability. To date, only the CLOP (Lace Tempest) threat actor group has been identified exploiting the vulnerability.
The critical PaperCut remote-code-execution vulnerability CVE-2023-27350 and high-severity information-disclosure flaw CVE-2023-27351 were exploited together in April 2023 attacks linked to LockBit and Clop. Bl00dy later used CVE-2023-27350 for initial access.
CVE-2023-27351 is a high-severity information-disclosure vulnerability that was exploited together with CVE-2023-27350 in April 2023 PaperCut attacks linked to LockBit, Clop, MuddyWater, and APT35.
14 more CVEs tied to this actor tracked in Mallory.
1,464 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Previously exploited a Cleo product vulnerability to steal data from major organizations.
Historically linked to ransomware attacks exploiting PaperCut vulnerabilities.
Previously linked to April 2023 attacks chaining PaperCut vulnerabilities CVE-2023-27350 and CVE-2023-27351.
Historically, affiliates associated with Clop exploited known PaperCut vulnerabilities to compromise servers and deploy ransomware.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.