Ukrainian authorities, working with law enforcement partners in the United States and South Korea, arrested six suspected members of the Clop ransomware operation and conducted 21 searches in Kyiv and surrounding areas. Investigators said they seized computers, smartphones, server equipment, cash, and luxury vehicles, and shut down infrastructure allegedly used in earlier attacks. The suspects were reported to face prison terms of up to eight years if convicted.
The action targeted a group tied to ransomware and data-extortion attacks dating back to 2019, including incidents involving South Korean companies and the attack on retailer E-Land. Reporting also linked Clop to the exploitation of four zero-day vulnerabilities in Accellion FTA, intrusions that led to data theft and extortion affecting organizations including Kroger, Jones Day, Qualys, Singtel, Stanford University Medical School, the University of California, and the University of Maryland. Researchers and investigators have described Clop as a major double-extortion operation, though some assessments said the raids likely disrupted affiliates and money-laundering elements more than the group’s core leadership.

TTPs, infrastructure, and targeting history in one profile.
6 events from the most recent confirmed update back to the earliest known activity.
A FireEye report said the Clop gang appeared to have struck a deal with FIN11. According to the report, FIN11 operators were allowed to list data stolen from hacked Accellion FTA devices.
A Fox-IT report said the Clop gang had close ties to malware distribution group TA505. The report added that TA505 often enabled Clop deployments on systems previously infected with SDBbot malware.
South Korean police intensified their investigation after Clop infected e-commerce giant E-Land. The attack forced the company to close almost half of its stores.
The references state that Clop ransomware incidents had been documented as early as February 2019, marking the group's emergence. Krebs also describes CLOP as debuting in early 2019.
Investigations later tied to the Ukrainian arrests began in 2019 after the Clop gang breached four South Korean companies, encrypted their files, and demanded large ransom payments. This incident became an early anchor for the multinational investigation.
Ukrainian authorities, working with law enforcement from South Korea and the United States, arrested six alleged Clop members. The operation included 21 searches in Kyiv and nearby regions, seizure of cash, devices, and luxury vehicles, and the shutdown of server infrastructure allegedly used in past attacks.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
4 references tracked. Mallory keeps watching after this page renders.
malpedia.caad.fkie.fraunhofer.de
Open sourcetherecord.media
Open sourcekrebsonsecurity.com
Open sourcefireeye.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.