Clop ransomware
Hunt this family in your stack
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
Vulnerabilities exploited
3 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
“Deploy Oct. 4, 2025 Security Alert patches for 9.8 CVE-2025-61882.”
In 2023, the notorious Clop ransomware gang exploited a zero-day vulnerability in GoAnywhere, tracked as CVE-2023-0669, to gain access to the sensitive data of Fortra customers.
"During multiple incident response investigations, NCC Group found that a vulnerable version of SolarWinds Serv-U server appeared to be the initial access used by TA505... The vulnerability being exploited is known as CVE-2021-35211."
Techniques & procedures
16 distinct techniques documented for this family, organized by ATT&CK tactic.
Initial Access
2 techniques
Initial Access
Execution
1 technique
Execution
Persistence
2 techniques
Persistence
The following analytic identifies the creation of a service with a known name used by CLOP ransomware for persistence and high-privilege code execution. It detects this activity by monitoring Windows Event Logs (EventCode 7045) for specific service names ("SecurityCenterIBM", "WinCheckDRVs"). | This activity is significant because the creation of such services is a common tactic used by ransomware to maintain control over infected systems. If confirmed malicious, this could allow attackers to execute code with elevated privileges, maintain persistence, and potentially disrupt or encrypt critical data.
Privilege Escalation
1 technique
Privilege Escalation
The following analytic identifies the creation of a service with a known name used by CLOP ransomware for persistence and high-privilege code execution. It detects this activity by monitoring Windows Event Logs (EventCode 7045) for specific service names ("SecurityCenterIBM", "WinCheckDRVs"). | This activity is significant because the creation of such services is a common tactic used by ransomware to maintain control over infected systems. If confirmed malicious, this could allow attackers to execute code with elevated privileges, maintain persistence, and potentially disrupt or encrypt critical data.
Stealth
3 techniques
Stealth
The following analytic identifies a process attempting to delete its own file path, a behavior often associated with defense evasion techniques.
Discovery
1 technique
Discovery
Exfiltration
4 techniques
Exfiltration
Only limited localized data without sensitive or technical IT details had been exposed as a result of the intrusion... Clop previously leaked over 315 GB of archives purportedly obtained from the tire giant's systems.
...involve the use of ransomware payloads along with exfiltration of data... threaten deletion and exposure of exfiltrated data.
Impact
3 techniques
Impact
Recent activity
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
The version that knows your environment.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.