CL-CRI-1036 is a financially motivated ransomware threat cluster associated with deployment of the 01flip ransomware family. The actor has targeted critical infrastructure organizations in the Asia-Pacific region, with confirmed victimization in the Philippines and Taiwan. Its operations have been characterized as early-stage but comparatively sophisticated, combining hands-on intrusion activity with a custom cross-platform ransomware capability affecting both Windows and Linux environments. The group uses manual post-compromise tradecraft rather than relying solely on automated ransomware deployment. Reported intrusion activity includes exploitation of CVE-2019-11580 for initial access, followed by use of the Sliver adversary emulation framework to establish persistence and support lateral movement. The actor has also been linked to theft and sale of victim data, indicating extortion activity in addition to encryption. The 01flip malware is written in Rust, reflecting a modern development approach that supports cross-platform operations and may complicate defensive analysis. A code-level reference to files associated with LockBit has been observed in the ransomware’s exclusion logic, but no direct operational relationship with LockBit has been established. No additional aliases or sub-groups are currently available from the supplied facts.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Financially motivated activity cluster attributed with 01flip ransomware campaigns in Asia-Pacific; gains footholds by exploiting known vulnerabilities (example cited: CVE-2019-11580) and targets Windows and Linux.
Financially motivated ransomware group targeting critical infrastructure in the Asia-Pacific region using a custom Rust-based ransomware (01flip) capable of infecting both Windows and Linux systems. The group uses manual intrusion methods, exploits known vulnerabilities, and leverages Sliver C2 for persistence and lateral movement. They have been linked to data leaks and extortion on the dark web.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.