Ransomware Group: clop

Fecha
25 Jun 2026
Actor
clop
Tipo
Threat-actor
Pais
United States
Sector
-
Confianza
high
78
Prioridad analitica
Alta

Basado en actor, pais, IOCs, TTPs, filtracion y calidad de contexto.

4IOCs
1TTPs
clopActor
United StatesPais
Executive Summary
Perfil del grupo segun ransomware.anggipradana.com.

Key Points

  • Ransomware Dashboard

Grupo Ransomware: clop

Perfil del grupo segun ransomware.anggipradana.com.

CampoValor
Alias
Pais
Estado

Descripcion

The ransomware group known as Cl0p is a variant of a previously known strain dubbed CryptoMix. It is worth noting that this variant was delivered as the final payload in a phishing campaign in 2019 and was exclusively financially motivated, with attacks carried out by the threat actors TA505.<br> <br> At that time, malicious actors sent phishing emails that led to a macro-enabled document that would drop a loader called 'Get2.' After gaining an initial foothold in the system or infrastructure, the actors began using reconnaissance, lateral movement, and exfiltration techniques to prepare for the deployment of the ransomware.<br> <br> After the execution of the ransomware, Cl0p appends the extension '.clop' to the end of files, or other types of extensions such as '.CIIp, .Cllp, and .C_L_O_P,' as well as different versions of the ransom note that were also observed after encryption. Depending on the variant, any of the ransom text files were created with names like 'ClopReadMe.txt, README_README.txt, Cl0pReadMe.txt, and READ_ME_!!!.TXT.'<br> <br> The Clop operation has shifted from delivering its final payload via phishing and has begun initiating attacks using vulnerabilities that resulted in the exploitation and infection of victims' infrastructures.<BR>Source: https://github.com/crocodyli/ThreatActors-TTPs

Referencias

Diamond Model

Adversary
clop
Ver perfil →
Victim
Ransomware Group: clop
United States
Capability
Threat-actor
1 TTPs MITRE
Infrastructure
github.com

Indicadores de Compromiso (IOCs)

TipoValorContextoOSINT
File ClopReadMe.txt Artefacto observado VT OffSec SOCRadar
File README_README.txt Artefacto observado VT OffSec SOCRadar
File Cl0pReadMe.txt Artefacto observado VT OffSec SOCRadar
Domain github.com Extraido del contenido VT OffSec SOCRadar

Referencias y enlaces

→ Perfil del actor clop en el blog → Ver clop en IntelTracker → URL IntelTracker: ransomware.anggipradana.com → Fuente OSINT: ransomware.anggipradana.com → Buscar clop en APTTrail → Repositorio APTTrail → Mas incidentes en United States → Buscar en Google News → Analizar en VirusTotal → Feed RSS del blog
← Volver al panel de inteligencia

Incidentes recientes