Skip to content

other

Clop

Clop (Cl0p) is a ransomware and data-extortion group known for mass-exploiting enterprise file-transfer software flaws to steal data and extort victims.

Known aliases

  • Cl0p
  • Cl0p ransomware group
  • Clop extortion gang
  • Clop ransomware
  • Clop ransomware gang
  • UNC2546

Relationships

No evidence-backed relationships are recorded.

Current stories

security5 publishers

Kiteworks clears customers to restart file-transfer servers after a weekend shutdown on a federal tip

Kiteworks lifted its worldwide shutdown advice after patching a critical flaw in a feature used by under 1% of customers. Self-hosted operators stopped and restarted on the vendor's word alone, with no CVE yet to check the fix against.

Perspective Coverage

5 publishers
Builder
Builder 23%
Operator
Operator 60%
Investor
Investor 17%

Reality

Evidence55
Adoption
Insufficient
Hype gap+15
Incentives70
Confidence60
security1 publisher

ShinyHunters' leak samples expose named FBI agents' medical exams

ShinyHunters has shown journalists FBI medical exams that name agents and their addresses, from a set it says covers about 60,000 current and former staff. The FBI has so far confirmed only an incident in FBIJobs-related systems, and the group is threatening to publish within five days.

Publishers:malwarebytes.com

Reality

Evidence45
Adoption
Insufficient
Hype gap+20
Incentives60
Confidence45
security5 publishers

Kiteworks tells customers to shut down even internal file-sharing servers for six hours

Kiteworks told customers worldwide to power off its file-sharing servers for six hours on September 26 after a federal warning of a possible attack. Servers with no internet exposure are included, so being on release 9.5.1 with every known fix does not by itself clear a customer.

Perspective Coverage

5 publishers
Builder
Builder 18%
Operator
Operator 73%
Investor
Investor 9%

Reality

Evidence58
Adoption
Insufficient
Hype gap+20
Incentives45
Confidence62
security14 publishers

ShinyHunters pins its claimed FBI breach on an unpatched PeopleSoft RCE

The extortion crew defaced apply.fbijobs.gov on September 22 and told reporters it got remote code execution from a new Oracle PeopleSoft flaw, the same one it says it is now using against Fortune 500 targets. No technical details are public.

Perspective Coverage

14 publishers
Builder
Builder 20%
Operator
Operator 67%
Investor
Investor 13%

Reality

Evidence40
Adoption
Insufficient
Hype gap+40
Incentives75
Confidence60
security6 publishers

ShinyHunters claims the private keys to Clop's onion address after defacing the leak site

BleepingComputer confirmed the defacement and the file ShinyHunters uploaded to Clop's Tor site. The stolen logs and the onion keys are so far only the attacker's account, and Clop has 72 hours to make contact.

Perspective Coverage

6 publishers
Builder
Builder 18%
Operator
Operator 63%
Investor
Investor 19%

Reality

Evidence60
Adoption55
Hype gap+35
Incentives78
Confidence62