Description
Clop is a ransomware operation associated with the FIN11 threat group that conducts large scale data theft and extortion campaigns. Its operators exploit file transfer software, managed file transfer appliances, and other server side vulnerabilities to breach organizations at scale, and they extort victims through a leak site. The family has run mass exploitation campaigns that rank among the most disruptive in recent years, affecting thousands of downstream organizations through a single supplier breach.
Stats
- First seen
- March 2022
- Last seen
- October 2026
MITRE ATT&CK techniques
17 techniques across 5 tactics.
TA0005 Stealth
TA0007 Discovery
Associated groups
Alert name variants
| Alert Name |
|---|
| Gen:Variant.Ransom.Clop.12 |
| Gen:Variant.Ransom.Clop.15 |
| Gen:Variant.Ransom.Clop.17 |
| Gen:Variant.Ransom.Clop.3 |
| Gen:Variant.Ransom.Clop.4 |
| Gen:Variant.Ransom.Clop.9 |
| Generic.Ransom.Clop.0F1C4EC3 |
| Generic.Ransom.Clop.17FF1404 |
| Generic.Ransom.Clop.34F27C13 |
| Generic.Ransom.Clop.435DD3AA |
Related IPS Signatures
| Signature Name |
|---|
| MALWARE-OTHER Win.Ransomware.Clop download attempt |


