Clop
Essential information
- Confidence
- 100/100
- Published
- 20/12/2025 08:54
- Modified
- 28/01/2026 15:52
- Updated at
- 28/01/2026 15:52
- Revoked
- No
- Author / Source
- Ransomware.Live
- Resource level
- —
- Primary motivation
- —
- Related entities
- 3 reports, 34 attack patterns (mitre), 41 malware, 26 sectors, 15 countries, 63 indicators, 21 vulnerabilities (cve), 4 organization
Description
Marking (TLP)
TLP:CLEAR
Labels
ransomware
Related entities
Attack patterns, malware, vulnerabilities, indicators and other entities linked to this intrusion set.
Reports (3)
-
16 CVEs 20 MITREs 40 Malwares 37 Observables 1 APT
-
17 MITREs 2 Malwares 200 Observables 1 APT
-
11 MITREs 1 Malware 2 Observables 1 APT
Attack patterns (MITRE) (34)
-
T1566 usesPhishing MITRE
-
T1049 usesSystem Network Connections Discovery MITRE
-
T1090 usesProxy MITRE
-
T1568 usesDynamic Resolution MITRE
-
T1053 usesScheduled Task/Job MITRE
-
T1078 usesValid Accounts MITRE
-
T1068 usesExploitation for Privilege Escalation MITRE
-
T1498 usesNetwork Denial of Service MITRE
-
T1005 usesData from Local System MITRE
-
T1083 usesFile and Directory Discovery MITRE
-
T1490 usesInhibit System Recovery MITRE
-
T1071 usesApplication Layer Protocol MITRE
Malware (41)
-
Bash0day usesFamily
-
CryptoMix usesFamily
-
XMRig usesFamily
-
Rondo usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
BPFDoor usesFamily
-
Wicked usesFamily
-
Beacon usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
Gafgyt usesFamily
-
Satori usesFamily
-
Qilin usesFamily
-
Lizkebab usesFamily
-
LZRD usesFamily
Sectors (26)
-
Cloud Infrastructure targets
-
Logistics targets
-
Manufacturing targets
-
Transportation targets
-
Government targets
-
Agriculture Food Production targets
-
Public Sector targets
-
Education targets
-
Technology Hardware targets
-
Consulting targets
-
Multimedia targets
-
Road transport targets
Countries (15)
-
Sri Lanka targets
-
Netherlands targets
-
India targets
-
United States of America targets
-
Italy targets
-
Romania targets
-
Iran, Islamic Republic of targets
-
Panama targets
-
China targets
-
Japan targets
-
Australia targets
-
Germany targets
Indicators (63)
-
stix 100/100· Valid until 01/11/2026 · Source: AlienVault
-
stix 100/100· Valid until 15/01/2027 · Source: AlienVault
-
https://ns1.ubunutpackages.storeindicatesstix 100/100 Revoked· Valid until 26/02/2026 · Source: AlienVault -
stix 100/100 Revoked· Valid until 26/02/2026 · Source: AlienVault
-
stix 100/100· Valid until 01/11/2026 · Source: AlienVault
-
stix 100/100· Valid until 24/01/2027 · Source: AlienVault
-
https://ns1.bafairforce.armyindicatesstix 100/100 Revoked· Valid until 26/02/2026 · Source: AlienVault -
stix 100/100· Valid until 02/10/2026 · Source: AlienVault
Vulnerabilities (CVE) (21)
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.7 before 18.6.4, 18.7 before 18.7.2, and 18.8 before 18.8.2 …
- Attack vector
- NETWORK
- Published
- 22/01/2026
- Modified
- 28/01/2026
Cleo Harmony, VLTrader, and LexiCom, which are managed file transfer products, contain an unrestricted file upload vulnerability that could allow an unauthenticated …
- Attack vector
- Network
- Published
- 17/12/2024
- Modified
- 21/12/2025
A pre-authentication denial of service vulnerability exists in React Server Components versions 19.0.0, 19.0.1 19.1.0, 19.1.1, 19.1.2, 19.2.0 and 19.2.1, including the …
- Attack vector
- NETWORK
- Published
- 11/12/2025
- Modified
- 21/12/2025
A Local File Inclusion (LFI) vulnerability exists in the Webmail Classic UI of Zimbra Collaboration (ZCS) 10.0 and 10.1 because of improper …
- Attack vector
- Network
- Published
- 22/12/2025
- Modified
- 28/01/2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 including the following packages: react-server-dom-parcel, …
- Attack vector
- Network
- Published
- 05/12/2025
- Modified
- 29/05/2026
Fortra (formerly, HelpSystems) GoAnywhere MFT contains a pre-authentication remote code execution vulnerability in the License Response Servlet due to deserializing an attacker-controlled …
- Attack vector
- Network
- Published
- 10/02/2023
- Modified
- 21/12/2025
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.6 before 18.6.4, 18.7 before 18.7.2, and 18.8 before 18.8.2 …
- Attack vector
- NETWORK
- Published
- 22/01/2026
- Modified
- 28/01/2026
Vite is a frontend tooling framework for javascript. Vite exposes content of non-allowed files using ?inline&import or ?raw?import. Only apps explicitly exposing …
- Attack vector
- Network
- Published
- 31/03/2025
- Modified
- 28/01/2026
TP-Link Archer AX-21 contains a command injection vulnerability that allows for remote code execution.
- Attack vector
- Adjacent
- Published
- 01/05/2023
- Modified
- 21/12/2025
Organization (4)
-
MUTTI-PARMA.COM targets
-
BORING.COM targets
-
KOEL.CO.IN targets
-
CPJ.ORG targets