The Cl0p ransomware operation used data stolen through the Accellion File Transfer Appliance compromise to extort dozens of organizations, escalating pressure by emailing victims’ customers directly and threatening publication on its CL0P^-LEAKS site. Reporting and threat research describe a highly organized group that demanded multimillion-dollar payments, offered time-based discounts, and in some cases removed victims from its leak portal after payment, while uncertainty remained over whether Cl0p conducted the initial Accellion intrusion or primarily monetized the stolen data.
Security researchers linked Cl0p to TA505/FIN11 activity, citing years of overlapping phishing, malware delivery, and ransomware deployment patterns. Prior campaigns used mass email lures, malicious Excel XLM macros, custom packers, and tailored Cl0p binaries compiled per victim with unique RSA keys and individualized ransom notes, suggesting direct operator control rather than a typical affiliate-only model. Analysts also noted Tor-based negotiation portals, double-extortion tactics combining encryption with data theft, and operational patterns consistent with a mature financially motivated criminal enterprise believed to avoid infecting systems configured for Russian or other CIS language settings.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
19 events from the most recent confirmed update back to the earliest known activity.
Deutsche Telekom published analysis of CL0P operations during 2020, describing customized binaries, victim-specific ransom notes, and the group's leak and negotiation portals.
Deutsche Telekom reported that the CL0P^-LEAKS portal listed 19 victims in January 2021, most of them in Germany.
Vice reported that S2WLAB said in January it observed a victim pay 220 bitcoin in what appeared to be the same Cl0p extortion case tracked by FireEye.
Outpost24 published a method for unpacking TA505-packed malware with Qiling Framework, including hooks and bypasses for the packer's anti-emulation logic.
Deutsche Telekom cited rumors that one victim from the Christmas-period activity paid more than 200 bitcoin in ransom.
Deutsche Telekom reported a second TA505 spam period in mid-December 2020 lasting less than two weeks, likely aimed at securing access for holiday-period ransomware deployment.
Fox-IT published a brief history of TA505, contributing public reporting on the group's evolution and operations.
FireEye published research on FIN11's widespread email campaigns as a precursor to ransomware and data theft activity.
Deutsche Telekom said the observed TA505 spam activity ceased on 2020-09-11, the same day Secura announced the Zerologon vulnerability.
Deutsche Telekom observed Cl0p ransomware deployments at several victims during September and October 2020 following TA505 intrusions.
Deutsche Telekom reported a major TA505 spam period beginning on 2020-06-02 and ending on 2020-09-11, used to gain footholds in victim networks for later intrusions.
A published analysis documented a TA505 campaign using malicious Excel files with XLM macros, Dropbox-themed phishing infrastructure, and implants that performed host reconnaissance before later-stage malware delivery associated with Clop ransomware.
Intel 471 reported that REvil was first advertised on a Russian-language cybercrime forum in June 2019, promoted by the actor known as Unknown.
Intel 471 said REvil deployments were first observed in April 2019 exploiting Oracle WebLogic vulnerability CVE-2019-2725.
PRODAFT described TA505 as a financially motivated threat group that has been active since 2014.
Vice reported that 52 companies were listed on the CL0P^_- LEAKS site as of the prior week, reflecting the scale of the group's extortion campaign.
Kat Garcia of Emsisoft received an email from Cl0p stating the gang had stolen her personal and financial data from a breached maternity clothing retailer and threatening publication unless the company engaged the attackers.
Vice reported that Cl0p started directly contacting customers of breached companies by email to pressure victims into paying extortion demands, a tactic Emsisoft said was unprecedented at scale for ransomware groups.
Vice reported that Cl0p benefited from, and may have been responsible for, the Accellion File Transfer Appliance compromise that exposed data from dozens of organizations including Shell, Qualys, Flagstar, Jones Day, Stanford University, and the University of California.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
9 references tracked. Mallory keeps watching after this page renders.
intel471.com
Open sourcevice.com
Open sourcetelekom.com
Open sourceoutpost24.com
Open sourceblog.fox-it.com
Open sourcefireeye.com
Open sourcetelekom.com
Open sourcegithub.com
Open sourceprodaft.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.