🇷🇺Cl0p
🇷🇺 Cl0p is a tracked threat actor in the Clankerusecase corpus. Attributed to RU. Primary motivation: Criminal. We map 26 detection use cases to this actor across 53 MITRE ATT&CK techniques, with 1 threat-intel article citing them. Active in our corpus from 2026-07-25 to 2026-07-25.
crit 1
26Use cases
1Articles
53Techniques
4IOCs
Known aliases
Cl0pClopTA505FIN11GRACEFUL SPIDERHive0065Spandex TempestCHIMBORAZO
Top techniques
All other tracked techniques
T1003 · OS Credential DumpingT1003.001 · LSASS MemoryT1021.002 · SMB/Windows Admin SharesT1027 · Obfuscated Files or InformationT1027.002 · Software PackingT1027.010 · Command ObfuscationT1027.013 · Encrypted/Encoded FileT1041 · Exfiltration Over C2 ChannelT1055.001 · Dynamic-link Library InjectionT1059.001 · PowerShellT1059.003 · Windows Command ShellT1059.005 · Visual BasicT1059.007 · JavaScriptT1069 · Permission Groups DiscoveryT1071 · Application Layer ProtocolT1071.001 · Web ProtocolsT1074.001 · Local Data StagingT1078.002 · Domain AccountsT1083 · File and Directory DiscoveryT1087.003 · Email AccountT1098.001 · Additional Cloud CredentialsT1105 · Ingress Tool TransferT1106 · Native APIT1112 · Modify RegistryT1140 · Deobfuscate/Decode Files or InformationT1176 · Software ExtensionsT1204.001 · Malicious LinkT1204.002 · Malicious FileT1218 · System Binary Proxy ExecutionT1218.007 · MsiexecT1218.011 · Rundll32T1486 · Data Encrypted for ImpactT1505.003 · Web ShellT1528 · Steal Application Access TokenT1539 · Steal Web Session CookieT1552.001 · Credentials In FilesT1553.002 · Code SigningT1553.005 · Mark-of-the-Web BypassT1555.003 · Credentials from Web BrowsersT1559.002 · Dynamic Data ExchangeT1566 · PhishingT1566.001 · Spearphishing AttachmentT1566.002 · Spearphishing LinkT1568.001 · Fast Flux DNST1569.002 · Service ExecutionT1583.001 · DomainsT1588.001 · MalwareT1588.002 · ToolT1608.001 · Upload MalwareT1685 · Disable or Modify Tools
Detection use cases (26)
Cl0p MFT zero-day → LEMURLOOT/DEWMODE web shell drop on MOVEit / GoAnywhere / Accellion Cl0p MFT web shell hands-on-keyboard: w3wp/java spawns cmd, and mass data exfil / staging Cl0p hex-named JSP web shell dropped under /Windchill/login/ (CVE-2026-12569) PTC Windchill Java/Tomcat web tier spawning OS command shell (web shell RCE) Network connections to Cl0p CVE-2026-12569 C2 / staging infrastructure Windchill filesystem-enumeration artifact flst.txt written by web tier (CVE-2026-12569 discovery) Suspicious browser extension installation Infostealer — non-browser process accessing browser cookie/login DBs Asset exposure — vulnerability matches article CVE(s) Phishing-link click correlated to endpoint execution Email attachment opened from external sender Office app spawning script/LOLBin child process OAuth consent / suspicious app grant Ransomware-style mass file rename / extension change Brand-Impersonation Domain Fetch Followed by User-Context Loader Within 10 Minutes Cross-category credential-store enumeration with rapid egress to anonymizing tunnel/CDN Cross-Platform ClickFix Paste-to-Pipe Loader (UI-Parent Shell with Decode-and-Execute Payload) Developer package install spawning script-host with non-registry C2 within 5 minutes Developer/Data-tooling Daemon Spawns Shell Child Seconds After POST to Runner/Exec Endpoint Internet-Facing Service Process Spawning Unix Shell or Ingress-Tool LOLBin (Edge Zero-Day Post-Exploit) Internet-facing service process spawns shell/LOLBin within minutes of public inbound connection — post-RCE command execution Low-Code / AI Workflow Runtime Sandbox-Escape — Server Process Spawns Shell + Public Egress Non-Browser Process Reads Browser Credential / Cookie SQLite Then Egresses to Public Destination Within 10 Minutes npm/yarn/pnpm Install-Hook Spawn → Credential-Store Read or Worm-Payload Drop in node_modules OAuth Device-Code Consent Phish to Cross-IP Cloud Token Replay Package Manager / Dev-Tool Auto-Execution Triggers Non-Registry Egress or Credential-Store AccessThreat-intel articles (1)
Tracked indicators
IP addresses (4)
104.243.35.63 216.152.148.54 216.152.151.204 5.180.41.35CVEs (1)
CVE-2026-12569