CL0P
· Published 21/12/2025 00:50 · Modified 21/12/2025 18:20
· Source: AlienVault
Essential information
- Confidence
- 100/100
- Published
- 21/12/2025 00:50
- Modified
- 21/12/2025 18:20
- Updated at
- 21/12/2025 18:20
- Revoked
- No
- Author / Source
- AlienVault
- Resource level
- —
- Primary motivation
- —
- Related entities
- 2 reports, 61 attack patterns (mitre), 9 malware, 3 sectors, 2 countries, 46 indicators, 3 vulnerabilities (cve)
Description
No description.
Marking (TLP)
TLP:CLEAR
Related entities
Attack patterns, malware, vulnerabilities, indicators and other entities linked to this intrusion set.
Reports (2)
-
13 MITREs 4 Malwares 1 APT
-
1 CVE 35 MITREs 1 Malware 6 Observables 1 APT
Attack patterns (MITRE) (61)
Malware (9)
-
Cobalt Strike usesFamily
-
SAGEGIFT usesFamily
-
SAGEWAVE usesFamily
-
FlawedAmmyy uses
-
Cl0p usesFamily
-
SAGELEAF usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
FlawedGrace uses
-
Truebot uses
-
GOLDVEIN.JAVA usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
Sectors (3)
-
Transportation targets
-
Manufacturing targets
-
Retail targets
Countries (2)
-
United States of America targets
-
Canada targets
Indicators (46)
-
ea433739fb708f5d25c937925e499c8d2228bf245653ee89a6f3d26a5fd00b7aindicates -
93137272f3654d56b9ce63bec2e40dd816c82fb6bad9985bed477f17999a47dbindicates -
38e69f4a6d2e81f28ed2dc6df0daf31e73ea365bd2cfc90ebc31441404cca264indicates -
1285aa7e6ee729be808c46c069e30a9ee9ce34287151076ba81a0bea0508ff7eindicates -
09d6dab9b70a74f61c41eaa485b37de9a40c86b6d2eae7413db11b4e6a8256efindicates -
c58c2c2ea608c83fad9326055a8271d47d8246dc9cb401e420c0971c67e19cbfindicates -
b1c299a9fe6076f370178de7b808f36135df16c4e438ef6453a39565ff2ec272indicates -
dd2289669f1488351eb455d3650b2e051a453a5findicates -
58ccfb603cdc4d305fddd52b84ad3f58ff554f1af4d7ef164007cb8438976166indicates -
jirostrogud.comindicates -
387cee566aedbafa8c114ed1c6b98d8b9b65e9f178cf2f6ae2f5ac441082747aindicates -
769f77aace5eed4717c7d3142989b53bd5bac9297a6e11b2c588c3989b397e6bindicates
Vulnerabilities (CVE) (3)
9.8
Critical
Vulnerability in the Oracle Concurrent Processing product of Oracle E-Business Suite (component: BI Publisher Integration). Supported versions that are affected are 12.2.3-12.2.14. …
- Attack vector
- Network
- Published
- 06/10/2025
- Modified
- 21/12/2025
9.0
Critical
Sitecore Experience Manager (XM), Experience Platform (XP), Experience Commerce (XC), and Managed Cloud contain a deserialization of untrusted data vulnerability involving the …
- Attack vector
- Network
- Published
- 04/09/2025
- Modified
- 21/12/2025
9.8
Critical
Cleo Harmony, VLTrader, and LexiCom, which are managed file transfer products, contain an unrestricted file upload and download vulnerability that can lead …
- Attack vector
- Network
- Published
- 13/12/2024
- Modified
- 21/12/2025