The Clop ransomware and data-extortion operation has been linked to the TA505 ecosystem and has targeted organizations since 2019 through a mix of spear-phishing, stolen or compromised RDP credentials, and exploitation of internet-facing applications. Reporting on the group describes a shift from conventional ransomware deployment toward large-scale data theft and extortion, with victims pressured through leak-site exposure after sensitive information was exfiltrated.
Clop has been repeatedly tied to attacks on managed file transfer software, including Accellion FTA, GoAnywhere MFT, and MOVEit Transfer. In the MOVEit campaign, attackers exploited a SQL injection flaw, deployed the LEMURLOOT web shell, and stole data from backend databases; broader intrusion activity associated with the group has also included PowerShell execution, privilege escalation, process injection, Cobalt Strike command-and-control, persistence via web shells, and encryption for impact in some cases.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
8 events from the most recent confirmed update back to the earliest known activity.
In June 2023, multiple organizations were reported compromised in Clop's MOVEit campaign, including U.S. federal agencies, the BBC, hospitals, and EY. This represents a major expansion in disclosed victims and impact.
In April 2022, researchers found several MOVEit Transfer servers compromised and containing sensitive information. The reference ties this to Clop's exploitation of the platform and data theft activity.
The timeline says that in November 2021, researchers observed Clop exploiting a SolarWinds vulnerability to breach several organizations. This marks a reported technical development in the group's intrusion methods.
In November 2021, maritime services in Singapore were hit by Clop, with commercial and employee bank data exfiltrated. The event is described as a specific victim-sector intrusion with theft of sensitive information.
The reference states that since late 2020, Clop threat actors have compromised over 100 companies. It presents this as a broader escalation in victim count tied to the group's campaigns.
In April 2020, Clop actors accessed a pharmaceutical company and leaked user data. This reflects an extortion-focused incident rather than only encryption activity.
The timeline states that in January 2020, Fin11 deployed Clop ransomware against Kiteworks Accellion FTA. The broader profile links Clop and Fin11 to exploitation of Accellion FTA zero-day vulnerabilities.
Clop ransomware was first noticed in the wild during large-scale spear-phishing activity. The reference describes this as the earliest observed appearance of the threat.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.