SentinelLABS reported the first observed Linux ELF variant of Cl0p ransomware, linking it to an attack that likely hit a university in Colombia in late 2022. The malware mirrors parts of Cl0p’s Windows logic but appears less mature, lacking features such as exclusion logic, command-line options, and RSA-based protection for encryption keys. Researchers said the victim’s data was later posted to Cl0p’s onion leak site, showing the intrusion combined file encryption with data extortion.
The Linux strain contains a critical cryptographic flaw that allows recovery of encrypted files without paying the ransom. SentinelLABS found the malware uses a hardcoded RC4 master key to wrap per-file RC4 keys, and also leaks stack and file metadata into generated key files. Based on those weaknesses, the researchers released a free decryptor and warned that ransomware targeting Linux systems continues to grow across server and cloud environments.

TTPs, infrastructure, and targeting history in one profile.
4 events from the most recent confirmed update back to the earliest known activity.
SentinelLABS disclosed that the Linux Cl0p variant contains a hardcoded RC4 master key flaw that allows victim files to be decrypted without paying the ransom, and published a free decryptor for affected victims.
The report states that data from the victim associated with the Linux Cl0p incident was leaked on Cl0p's onion site on January 5.
Researchers reported the first observed Linux ELF variant of Cl0p ransomware, identifying the sample on December 26, 2022. The variant was described as less mature than the Windows version but similar in overall logic.
SentinelLABS linked the Linux ELF variant of Cl0p ransomware to a broader attack that likely targeted a university in Colombia around December 24, 2022.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 17 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
1 reference tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.