Skip to content
Multiple / Non-stateCriminalActive

Cl0p

Abandoned encryption for pure data-theft extortion. Its MOVEit campaign hit 2,700+ organisations from a single vulnerability.

Download profile JSON
Active
2019–present
Motivation
Financial Gain
Aliases
8
Exploited CVEs
4
ATT&CK techniques
8
Cited sources
9

Overview

Cl0p perfected a model that made ransomware encryption largely unnecessary: find a zero-day in a widely deployed managed file transfer product, exploit every internet-facing instance in a single automated burst, steal the data, and extort the victims.

Managed file transfer products are an unusually good target. Organisations use them precisely because they move sensitive data — HR records, financial reports, health information, legal documents — and because they are often internet-facing by design, connected to many partners, and administered by teams with no security remit.

The May 2023 MOVEit Transfer campaign is the clearest example. Cl0p exploited a SQL injection zero-day across essentially every reachable MOVEit instance over a single holiday weekend. The victim count exceeded 2,700 organisations and the affected-individual count exceeded 90 million, including many organisations that had never heard of MOVEit — it was in use by their payroll processor, benefits administrator, or state agency. The group did not deploy ransomware at all in most cases; encryption would have added nothing to the leverage that possession of the data already provided.

It ran the same play against Accellion FTA in 2020, GoAnywhere MFT in early 2023, and Cleo Harmony and VLTrader in late 2024.

The group is assessed as related to the FIN11 and TA505 clusters, and operates a leak site where victims are published on a schedule if they do not pay. The U.S. State Department has offered a reward of up to $10 million for information on the actors.

Attribution

Down to the named unit where public evidence supports it.

None — financially motivated criminal groupAssessed Russian-speaking, related to the FIN11 and TA505 clustersHigh confidence

A financially motivated criminal operation with no state sponsorship, assessed as Russian-speaking based on language artifacts, infrastructure, and operational patterns. Mandiant assesses overlap with FIN11 and the broader TA505 ecosystem. Six individuals connected to the operation were arrested in Ukraine in June 2021 in a joint international action, though the group resumed activity shortly afterwards. The U.S. State Department has offered a reward of up to $10 million for identifying information.

Attributing sources

Cross-vendor naming crosswalk

8 designators across 8 organisations.

2 designators are marked partial — the vendor's cluster overlaps this group but is not synonymous with it. Treating a partial correlation as an equivalence is the most common source of attribution error when pivoting between vendor reports.

Microsoft Threat Intelligence

index ↗
  • Lace TempestFormerly DEV-0950

Weather-event family encodes the attributed origin; the adjective is arbitrary. Renamed from the older element taxonomy (STRONTIUM, NOBELIUM, HAFNIUM) in April 2023. 'Storm-####' is a temporary designator for a cluster still in development.

CrowdStrike

index ↗
  • Graceful Spider

Animal denotes attributed nation-state or motive; the adjective distinguishes clusters. The original public adversary taxonomy, in use since 2012.

Mandiant / Google Threat Intelligence

index ↗
  • FIN11partialMandiant assesses Cl0p deployment as a subset of FIN11 activity; the clusters are related but not identical

APTxx for state-nexus espionage, FINxx for financially motivated, UNCxxxx ('uncategorized') for clusters not yet graduated to a named group. Many UNC numbers are later merged into an APT/FIN designator.

Secureworks CTU

index ↗
  • GOLD TAHOE

Metal prefix encodes attributed origin, paired with an arbitrary uppercase codeword.

Palo Alto Networks Unit 42

index ↗
  • Baleful Scorpius

Constellation denotes attributed origin or motive, adopted in 2023 to replace ad-hoc naming.

Recorded Future Insikt Group

index ↗
  • Cl0p

Colour prefix encodes attributed origin (RedXxxx = China, BlueXxxx = Russia). TAG-## ('Threat Activity Group') is a provisional designator for clusters pending attribution.

Proofpoint

index ↗
  • TA505partialThe broader criminal ecosystem from which Cl0p emerged

TA### ('Threat Actor'), numbered sequentially in order of first tracking.

CISA / NSA / FBI

index ↗
  • CL0P / TA505

U.S. government advisories generally reference groups by the most common industry name plus the attributed unit. Joint advisories are the authoritative source for unit-level attribution.

Targeting

Target geography

United StatesUnited KingdomCanadaGermanySwitzerlandAustraliaNetherlands

Tools & malware

Custom tooling is a strong clustering signal; shared and commodity tooling is not.

Custom / bespoke

LEMURLOOTutility

Bespoke ASP.NET web shell deployed to MOVEit servers, enumerating and exfiltrating stored files and Azure storage credentials.

Malpedia ↗
DEWMODEutility

Web shell used against Accellion FTA appliances to enumerate and steal transferred files.

Cl0p ransomwareransomware

Encryption payload, increasingly optional — in the MOVEit campaign the group largely skipped encryption entirely.

Malpedia ↗

Shared, commodity & living-off-the-land

TrueBotloader

Loader used for initial access in campaigns preceding data theft.

Leak siteutility

Tor-hosted publication schedule used to escalate pressure on non-paying victims.

Exploited vulnerabilities

Filtered on the date this actor was first reported exploiting the flaw — not the CVE's publication date.

CVEUsage by Cl0p
CVE-2024-506230-dayKEVransomware9.81 Dec 2024Cleo Harmony and VLTrader unrestricted file upload exploited for mass data theft from managed file transfer deployments.SRCHuntress
CVE-2023-343620-dayKEVransomware9.827 May 2023MOVEit Transfer SQL injection exploited across essentially every reachable internet-facing instance over the U.S. Memorial Day weekend. Over 2,700 organisations and 90 million individuals affected — most of them customers of a customer, with no direct relationship to the product.SRCCISA / FBI
CVE-2023-06690-dayKEVransomware7.218 Jan 2023Fortra GoAnywhere MFT pre-authentication command injection exploited before patch, affecting over 130 organisations.SRCHuntress
CVE-2021-27065KEVransomware7.81 Mar 2021Exchange ProxyLogon chain exploited following public disclosure for access to enterprise networks.SRCMandiant / FireEye

Actors sharing exploited CVEs

Kill chain

How this actor moves through an intrusion, stage by stage, titled by ATT&CK tactic. Read left to right.

7 stages · 8 techniques
  1. 01

    Initial Access

    1 technique

    One zero-day, every reachable instance, one weekend. Managed file transfer products are the ideal target: internet-facing by design, connected to many partners, holding exactly the data worth extorting, and administered by teams with no security remit. MOVEit, GoAnywhere, Accellion and Cleo were all run the same way.

  2. 02

    Persistence

    1 technique

    A bespoke web shell on the appliance — LEMURLOOT, DEWMODE — that enumerates stored files and harvests the cloud storage credentials the product itself uses.

  3. 04

    Collection

    1 technique

    Bulk theft of whatever was staged in transit: payroll, benefits, health records, legal documents. In the MOVEit campaign that reached 2,700+ organisations and over 90 million individuals, most of whom had never heard of the product because it belonged to their payroll processor.

  4. 07

    Impact

    2 techniques

    Extortion on possession alone. Encryption was largely skipped in MOVEit because it would have added nothing — the leverage was already the data, and a leak-site publication schedule supplies the deadline.

Scroll horizontally · characteristic chain across documented operations, not a single incident

MITRE ATT&CK techniques

Grouped in kill-chain order.

8 techniques across 7 tactics · 6 with actor-specific notes

Initial Access

1

Persistence

1

Credential Access

1

Collection

1

Impact

2

Campaign timeline

  1. landmark

    MOVEit Transfer Mass Exploitation

    Zero-day SQL injection exploited across essentially every internet-facing MOVEit Transfer instance over a single holiday weekend. Over 2,700 organisations and 90 million individuals affected — most of them customers of a customer, with no direct relationship to the product. Encryption was largely skipped; possession of the data was the leverage.

    CVE-2023-34362Financial ServicesGovernmentHealthcareEducation

Known to work with

Relationship type and confidence stated explicitly — 'related' without qualification is not an assessment.

Primary-source reporting

Curated links to the reports that established what is known about this group.