Clankerusecase
Threat-actor profile
← Back to main site
Home/ Threat Actors/ Cl0p

🇷🇺Cl0p

🇷🇺 Cl0p is a tracked threat actor in the Clankerusecase corpus. Attributed to RU. Primary motivation: Criminal. We map 22 detection use cases to this actor across 44 MITRE ATT&CK techniques, with 1 threat-intel article citing them. Active in our corpus from 2026-08-17 to 2026-08-17.

high 1
View full actor card → All threat actors MITRE ATT&CK group spec (G0092) ↗
22Use cases
1Articles
44Techniques
4IOCs

Known aliases

Cl0pClopTA505FIN11GRACEFUL SPIDERHive0065Spandex TempestCHIMBORAZO

Top techniques

All other tracked techniques

Detection use cases (22)

Clop hex-named JSP webshell dropped under PTC Windchill /login (CVE-2026-12569) Bespoke POST to hex-named JSP webshell under /Windchill/login/ in web/proxy logs Bespoke PTC Windchill Java/Tomcat process spawning shell or flst.txt recon Bespoke Outbound connection to known Clop CVE-2026-12569 C2 / exploitation IPs Bespoke Asset exposure — vulnerability matches article CVE(s) Internal Ransomware-style mass file rename / extension change Internal LSASS process access / dump (credential theft) Internal Remote service execution — PsExec / SMB lateral movement Internal Network connections to article IPs / domains Internal File hash IOCs — endpoint file/process match Internal Brand-Impersonation Domain Fetch Followed by User-Context Loader Within 10 Minutes MITRE match Cross-category credential-store enumeration with rapid egress to anonymizing tunnel/CDN MITRE match Cross-Platform ClickFix Paste-to-Pipe Loader (UI-Parent Shell with Decode-and-Execute Payload) MITRE match Developer package install spawning script-host with non-registry C2 within 5 minutes MITRE match Developer/Data-tooling Daemon Spawns Shell Child Seconds After POST to Runner/Exec Endpoint MITRE match Internet-Facing Service Daemon Spawns Shell or Ingress Tool Then Beacons Out MITRE match Internet-Facing Service Process Spawning Unix Shell or Ingress-Tool LOLBin (Edge Zero-Day Post-Exploit) MITRE match Internet-facing service process spawns shell/LOLBin within minutes of public inbound connection — post-RCE command execution MITRE match Low-Code / AI Workflow Runtime Sandbox-Escape — Server Process Spawns Shell + Public Egress MITRE match Non-Browser Process Reads Browser Credential / Cookie SQLite Then Egresses to Public Destination Within 10 Minutes MITRE match npm/yarn/pnpm Install-Hook Spawn → Credential-Store Read or Worm-Payload Drop in node_modules MITRE match OAuth Device-Code Consent Phish to Cross-IP Cloud Token Replay MITRE match

Threat-intel articles (1)

Tracked indicators

IP addresses (4)

104.243.35.63 216.152.148.54 216.152.151.204 5.180.41.35

CVEs (1)

CVE-2026-12569