Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
“Deploy Oct. 4, 2025 Security Alert patches for 9.8 CVE-2025-61882.”
In 2023, the notorious Clop ransomware gang exploited a zero-day vulnerability in GoAnywhere, tracked as CVE-2023-0669, to gain access to the sensitive data of Fortra customers.
"During multiple incident response investigations, NCC Group found that a vulnerable version of SolarWinds Serv-U server appeared to be the initial access used by TA505... The vulnerability being exploited is known as CVE-2021-35211."
29 distinct techniques documented for this family, organized by ATT&CK tactic.
Operators pulled off this attack by taking advantage of vulnerabilities in the Accellion file transfer appliance (FTA) software, which has been linked to a series of high-profile compromises...
Distributes and runs CLOP Ransomware by using task scheduler or remote command to the system connected to AD domain
The initial vector is a malicious excel file which used an XLM macro (macro v4).
Distributes and runs CLOP Ransomware by using task scheduler or remote command to the system connected to AD domain
The following analytic identifies the creation of a service with a known name used by CLOP ransomware for persistence and high-privilege code execution. It detects this activity by monitoring Windows Event Logs (EventCode 7045) for specific service names ("SecurityCenterIBM", "WinCheckDRVs"). | This activity is significant because the creation of such services is a common tactic used by ransomware to maintain control over infected systems. If confirmed malicious, this could allow attackers to execute code with elevated privileges, maintain persistence, and potentially disrupt or encrypt critical data.
Distributes and runs CLOP Ransomware by using task scheduler or remote command to the system connected to AD domain
The following analytic identifies the creation of a service with a known name used by CLOP ransomware for persistence and high-privilege code execution. It detects this activity by monitoring Windows Event Logs (EventCode 7045) for specific service names ("SecurityCenterIBM", "WinCheckDRVs"). | This activity is significant because the creation of such services is a common tactic used by ransomware to maintain control over infected systems. If confirmed malicious, this could allow attackers to execute code with elevated privileges, maintain persistence, and potentially disrupt or encrypt critical data.
On the HTML document, we can see that the fake page usurps dropbox in using external references and the path on the malicious excel document.
The following analytic identifies a process attempting to delete its own file path, a behavior often associated with defense evasion techniques.
The following analytic detects the shutdown of the Windows Event Log service using Windows Event ID 1100. This event is logged every time the service stops, including during normal system shutdowns. Monitoring this activity is crucial as it can indicate attempts to cover tracks or disable logging.
References MITRE ATT&CK Matrix List of all the references with MITRE ATT&CK Matrix Enterprise tactics Technics used Ref URL Discovery Query Registry https://attack.mitre.org/techniques/T1012/
Once this, this checks the system informations, the process executed on the computer and try to detect if this run in a sandbox (low size of the disk).
Once this, this checks the system informations, the process executed on the computer and try to detect if this run in a sandbox (low size of the disk).
Also a lot of sensitive data has been downloaded from your network... If you refuse to cooperate, all data will be published for free download on our portal
...involve the use of ransomware payloads along with exfiltration of data... threaten deletion and exposure of exfiltrated data.
113 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Clop is a ransomware family used by the Clop gang to encrypt victim data and demand ransom payments, often employing double extortion tactics.
Ransomware targeting organizations, especially Active Directory environments. It is delivered via spear-phishing and staged intrusion activity, uses remote-control malware and Cobalt Strike for lateral movement and privilege escalation, encrypts files with per-file symmetric keys protected by public-key cryptography, and more recent variants also threaten data leakage via a leak site.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.