Clop
Attribution profile
- Type
- Crime Syndicate
- Location
- Russia
- Known incidents
- 9 incidents
- Sources
- 258 sources
- First seen
- 2023-03-23
- Last seen
- 2026-07-01
- Updated
- 2026-08-26 20:46
- Aliases
- 4 aliases
STIX characteristics
Threat actor characteristics are available to members.
Profile narrative
The threat actor known by the aliases FIN11, TA505, Lace Tempest and Clop is described in open sources as a Russian‑speaking cybercrime group that is based in Russia, with no public evidence indicating direct sponsorship or coordination by the Russian government. The group characterizes its motivation as purely financial, explicitly stating that it is “only financial motivated and do not care anything about politics,” and it has claimed to delete data stolen from government entities to avoid becoming a national‑security target. Clop operates under a ransomware‑as‑a‑service model, leasing its ransomware infrastructure to affiliates in exchange for a share of ransom payments, and it employs a double‑extortion tactic that involves stealing data, threatening to leak it, and, if the ransom is not paid, publishing the stolen information on its leak site.
The actor’s typical targeting spans multiple sectors and geographic regions, with observed victims including healthcare providers such as Medibank staff, the U.S. Department of Health and Human Services, Nova Scotia Health and the Vitality Group; financial institutions like Corebridge Financial, Clearwater Credit Union and various banks; educational organizations including the University of California Los Angeles, New York City Department of Education and several universities; energy and industrial firms such as Siemens Energy, Schneider Electric and Shell; government agencies at the federal level in the United States (Department of Energy, Department of Agriculture, Office of Personnel Management) and at the state level in Illinois, Missouri, Minnesota, Colorado, Oregon and Louisiana, as well as provincial bodies in Nova Scotia; professional services firms including the law firms Kirkland & Ellis LLP and K&L Gates LLP and the accounting firms PricewaterhouseCoopers and Ernst & Young. The group’s tactics, techniques and procedures repeatedly involve the exploitation of zero‑day vulnerabilities in managed file transfer software, notably the MOVEit Transfer flaw (CVE‑2023‑34362) exploited in May‑June 2023, the Fortra GoAnywhere zero‑day used in spring 2023, earlier intrusions involving Accellion FTA servers in December 2020 and SolarWinds Serv‑U servers in 2021. In these operations the actors gain unauthorized access to file transfer servers, exfiltrate sensitive data such as names, Social Security numbers, health information and financial records, and then attempt to monetize the stolen material through extortion, while claiming to delete any government‑related data they acquire.
Representative campaigns attributed to Clop include the widespread MOVEit Transfer exploitation campaign that began in late May 2023 and affected over 150 organizations worldwide, leading to the compromise of personal data for more than 16 million individuals according to breach notifications and threat‑intelligence reporting. The group also conducted a series of intrusions leveraging a zero‑day vulnerability in Fortra’s GoAnywhere managed file transfer tool earlier in 2023, which resulted in the compromise of at least 130 organizations. Prior to these events, Clop was linked to the Accellion FTA breach in December 2020 that exposed data from numerous companies and government bodies, and to the SolarWinds Serv‑U exploitation in 2021 that facilitated data theft from multiple targets. Public disclosures have named specific victims across sectors, such as the University of Missouri, the Metro Vancouver Transit Police, the American Board of Internal Medicine, the gas and oil giant Shell, the British broadcaster BBC, the pharmacy chain Boots and the communications regulator Ofcom, illustrating the broad scope of the actor’s activity. These incidents demonstrate the actor’s reliance on exploiting third‑party software vulnerabilities to obtain data that is then used for financially motivated extortion, without evidence of ideological or state‑directed objectives.
Incidents
Attributed incidents are available to members.
9 incidentsSources
Sources available to members: 258 sources.