The Clop ransomware operation has repeatedly targeted enterprise networks with intrusions that begin with phishing or exploitation of exposed systems, followed by manual lateral movement, credential theft, and domain-wide deployment. Reporting from ANSSI and AhnLab linked earlier campaigns to TA505, describing attacks in which operators used tools such as Cobalt Strike and Mimikatz, encrypted files with .Clop or .CIop extensions, and disrupted business operations at victims including E-Land Group, Software AG, and reportedly Indiabulls Group. Analysts also observed Clop using signed malware components, targeting Active Directory environments, stopping business-critical services before encryption, and in some cases preserving shadow copies depending on the variant.
The group increasingly shifted from encryption-only attacks to double extortion and broader data-leak pressure tactics. Clop operators published stolen files on leak sites, demanded multimillion-dollar payments, contacted victims' customers directly to intensify pressure, and were tied to mass data-theft campaigns exploiting managed file transfer flaws such as CVE-2023-0669 in Fortra GoAnywhere MFT, which was linked to theft from about 130 companies. More recent victim listings attributed to Clop include organizations in the U.S., Canada, Peru, China, Taiwan, and Europe across technology, manufacturing, retail, and other sectors, underscoring the group's continued global focus on enterprise-scale ransomware and data-breach operations.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
35 events from the most recent confirmed update back to the earliest known activity.
HookPhish reported a Clop-attributed ransomware data breach affecting WATERLANDPE.COM in Peru, with breach and discovery time listed as 2026-08-12 15:40 UTC.
HookPhish reported a Clop-attributed ransomware data breach affecting 9ALTITUDES.COM, a Belgium-headquartered technology consulting company, with breach time listed as 2026-08-12 15:39 UTC.
HookPhish reported a Clop-attributed ransomware data breach affecting HONGHE-TECH.COM, a China-based technology-sector organization, with breach and discovery time listed as 2026-08-12 15:38 UTC.
HookPhish reported a Clop-attributed ransomware data breach affecting LARGAN.COM.TW, identified as Largan Precision Co., Ltd. in Taiwan's manufacturing sector, with breach time listed as 2026-08-12 15:30 UTC.
HookPhish reported a Clop-attributed ransomware incident affecting IRCO.COM, associated with Industrial Rubber Company, with breach and discovery time listed as 2026-08-12 15:29 UTC.
HookPhish reported a Clop-attributed ransomware data breach affecting ALDOGROUP.COM/ALDOSHOES.COM, a Canadian retail and e-commerce company, with breach time listed as 2026-08-12 15:28 UTC.
HookPhish reported a Clop-attributed ransomware data breach affecting NETPOWER.COM, a U.S. technology-sector organization, with breach and discovery time listed as 2026-08-12 15:26 UTC.
NCC Group recorded 129 Clop attacks in March 2023, making it the most active ransomware group that month and helping drive a record 459 ransomware incidents overall.
SentinelOne researchers said the Linux ELF variant of Cl0p was first spotted in late December 2022 and appeared to be in an early stage of development.
BleepingComputer said Clop leveraged a zero-day in Accellion's legacy File Transfer Appliance in early 2021, quickly amassing over 100 victims.
AhnLab reported that E-Land Group was infected by Clop ransomware in November 2020, affecting more than half of its brick-and-mortar stores and disrupting operations.
AhnLab said the Clop binaries used in the E-Land Group incident were compiled on November 21 and November 22, 2020, shortly before deployment.
ZDNet reported that Clop breached Software AG's internal network on Saturday, October 3, 2020, encrypted files, and demanded more than $20 million for a decryption key.
AhnLab reported that malware signed with the same certificate later seen on E-Land-related Clop samples had been distributed since October 2020, including ransomware and auxiliary components.
AhnLab said that since October 2020, Clop ransom notes have included threats to publish stolen sensitive company data on a deep-web site if victims refuse to pay, reflecting a shift to double extortion.
BleepingComputer reported that in March 2020 Clop attacked U.S. pharmaceutical company ExecuPharm, stealing 163GB of unencrypted files that were later leaked after the victim allegedly did not pay.
ANSSI reported multiple Clop ransomware incidents in France in recent weeks, noting that encryption was preceded by several days of manual lateral movement inside victim networks.
ANSSI said Clop attacks in France appeared to stem from a large phishing campaign around 16 October 2019 and linked that campaign to TA505.
AhnLab reported that one September 2019 Clop-related intrusion used TinyMet to install an EXE-form Cobalt Strike Beacon that injected into Rundll32.exe and used default-style named pipes.
AhnLab described a May 2019 case in which FlawedAmmyy installed a fileless HTTP Beacon via a PowerShell script fetched from 89.144.25.172/a, showing use of Cobalt Strike during Clop intrusions.
AhnLab reported that in March 2019 a FlawedAmmyy downloader variant checked WORKGROUP information to focus on enterprise environments, reflecting Clop operators' targeting of organizational networks.
AhnLab states that the Clop/CIop ransom note was first publicly posted on Pastebin as ClopReadMe.txt on February 8, 2019, marking an early public indicator of the ransomware family.
AhnLab assessed that Clop ransomware impacted 369 companies and 13,497 systems during 2019 across sectors including manufacturing, finance, IT, retail, education, and public institutions.
NCC Group said Clop exploited CVE-2023-0669 in Fortra GoAnywhere MFT as a zero-day and stole data from 130 companies within ten days.
SentinelOne researchers found a flaw in the Linux Cl0p variant's encryption logic and created a free decryptor that could recover affected victims' files.
BleepingComputer reported that Clop directly emailed customers of an unnamed online maternity clothing store with the subject 'Your personal data has been stolen and will be published' to pressure the victim into paying.
Before late March 2021, Clop used direct-contact extortion tactics against Flagstar Bank customers and people affected by the University of Colorado's Accellion-related breach.
A week after leaking Bombardier data, Clop emailed journalists to warn that additional stolen data would be released.
BleepingComputer reported that after stealing data from Bombardier in the Accellion hack, Clop leaked a small amount of the stolen information on its leak site.
ZDNet reported that Software AG later recanted its earlier statement and admitted it had found evidence that data was stolen in the Clop attack.
After negotiations failed, Clop published screenshots of allegedly stolen Software AG data on its dark web leak site, including employee IDs, emails, financial documents, and internal directories.
Software AG disclosed on Monday that it was facing disruptions on its internal network due to a malware attack, initially saying customer services were unaffected and that it was unaware of customer data access.
Clop operators claimed to have breached Indiabulls Group and posted screenshots of six allegedly stolen files tied to Indiabulls Pharmaceuticals and Indiabulls Housing Finance Limited, demanding contact within 24 hours.
A GitHub technical reference identified Maastricht University in the Netherlands as a victim of a Clop ransomware incident.
A new CryptoMix ransomware variant branded as Clop/CIop was discovered, appending .CLOP or .CIop to encrypted files and using the CIopReadMe.txt ransom note. The article says the malware was code-signed and appeared aimed at enterprise-wide impact.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
18 references tracked. Mallory keeps watching after this page renders.
hookphish.com
Open sourcehookphish.com
Open sourcehookphish.com
Open sourcehookphish.com
Open sourcecert.ssi.gouv.fr
Open sourcebleepingcomputer.com
Open sourceasec.ahnlab.com
Open sourcecert.ssi.gouv.fr
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.