TA505 is a prolific financially motivated cybercrime threat actor widely associated with large-scale phishing, malware delivery, banking fraud, data theft, and ransomware or extortion operations. The cluster is commonly linked to the Cl0p ransomware and extortion brand and is also tracked under aliases including Graceful Spider, Gold Tahoe, Hive0065, Monty Spider, Spandex Tempest, Chimborazo, and Clop/Cl0p. Some reporting also discusses overlap or association with FIN11 in Oracle E-Business Suite intrusion activity, but that relationship is not uniformly resolved and should be treated cautiously. TA505 has a long history of targeting enterprises across multiple sectors and geographies, often favoring organizations that can yield high-value financial or operational leverage. Victimology has included large commercial enterprises, technology providers, managed file transfer users, and organizations running exposed enterprise application infrastructure. The actor has been tied to mass exploitation campaigns against internet-facing enterprise software, including the 2023 MOVEit Transfer zero-day campaign and later Oracle E-Business Suite exploitation used for data theft and extortion. Those operations affected large numbers of organizations globally and demonstrated the group’s ability to rapidly operationalize newly discovered or zero-day vulnerabilities at scale. Operationally, TA505 is known for combining opportunistic scale with disciplined post-compromise tradecraft. Reported behavior includes exploitation of public-facing applications, credential abuse, use of valid accounts, data exfiltration prior to extortion, and reliance on living-off-the-land techniques and legitimate administrative tooling to reduce detection. The group has been associated with ATT&CK techniques including exploitation of public-facing applications, valid accounts, credentials in files, remote services, command and scripting interpreters, file and directory discovery, and exfiltration over command and control channels. In ransomware and extortion operations, encryption may be paired with theft-based pressure, though some campaigns have emphasized data theft and extortion over disruptive encryption. The Cl0p-branded arm associated with TA505 is especially notable for supply-chain and mass-victim extortion campaigns. Its exploitation of managed file transfer and enterprise business application platforms showed a preference for centralized technologies that provide broad downstream victim access. In Oracle E-Business Suite campaigns, the actor was reported exploiting unauthenticated internet-facing flaws to steal data from exposed environments and extort affected organizations. In the MOVEit campaign, the actor conducted widespread zero-day exploitation before public disclosure, resulting in one of the largest data-theft and extortion waves tied to a single software platform. TA505 is generally assessed as a Russian-speaking cybercriminal actor rather than a nation-state operator. Its activity is best characterized as profit-driven, highly adaptive, and operationally mature, with the capability to run both broad malware distribution campaigns and targeted enterprise intrusions. The actor’s enduring relevance stems from its scale, repeated reinvention of delivery and monetization methods, and demonstrated ability to pivot from phishing-led intrusion sets to vulnerability-driven extortion campaigns.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
54 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
44 malware families attributed to this actor across reporting.
39 additional families tracked in Mallory.
14 CVEs this actor has used in observed campaigns. 14 of them exploited in the wild.
Vulnerable Oracle products have been heavily targeted in the past, with a critical Oracle EBS flaw patched in October 2025, tracked as CVE-2025-61882, subjected to attacks by the Clop ransomware gang.
The most significant incident was the 2023 MOVEit Transfer zero day (CVE-2023-34362), a SQL injection vulnerability exploited by the CL0P/TA505 ransomware group beginning May 27, 2023, before Progress disclosed it on May 31, 2023.
In late January 2023, the CL0P ransomware group launched a campaign using a zero-day vulnerability, now catalogued as CVE-2023-0669, to target the GoAnywhere MFT platform.
TA505 (Clop) is one of the oldest groups, active since 2019... It has been exploiting the Cleo zero-day vulnerability (CVE-2024–55956) since late 2024, which makes it the most active of all groups in the first half of 2025.
In the months prior, Oracle issued emergency patches for E-Business Suite vulnerabilities (CVE-2025-61882, CVE-2025-61884) after active exploitation by groups such as Cl0p.
9 more CVEs tied to this actor tracked in Mallory.
427 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned only in related content about a separate law enforcement operation.
Referenced as a ransomware group that previously exploited a different Oracle EBS vulnerability (CVE-2025-61882) in a campaign affecting more than 100 organizations.
Ransomware/extortion group associated with exploitation of an unauthenticated Oracle E-Business Suite Payments vulnerability.
Referenced only as a comparison point for the sophistication of GoldenEyeDog.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.