Cl0p

Also known as: TA505, FIN11, Lace Tempest

Overview

Financially motivated group specializing in mass exploitation of file transfer appliances. Responsible for MOVEit, GoAnywhere, Accellion, and Cleo campaigns affecting thousands of organizations.

MITRE ATT&CK Coverage

Recon
Res Dev
Init Access
Execution
Persistence
Priv Esc
Def Evasion
Cred Access
Discovery
Lat Move
Collection
C2
Exfil
Impact
5 of 14 tactics observed

Raw TTPs

Zero-Day ExploitationMass Data ExfiltrationFile Transfer TargetingExtortion without EncryptionAutomated Exploitation

Related Intelligence (6)

MEDIUMApt

Google adds to confusion with new names for threat actors

Google is creating a new naming scheme for the bad actors behind cybersecurity threats, hoping that it will help to standardize the way that attacks are reported. Spoiler: It won’t. Security researchers use these naming schemes so that they can attribute attacks without necessarily knowing exactly who is behind them. Google had naming schemes in use internally: one developed by its own Threat Anal

CSO Online
MEDIUMSupply Chain

Clop Tied to PTC Product Lifecycle Management Software Hits

<img src="https://ismg-cdn.nyc3.cdn.digitaloceanspaces.com/articles/clop-tied-to-ptc-product-lifecycle-management-software-hits-image_small-8-a-32333.jpg" align=right hspace=4><b>Signs Point to Cl0p Extortion Group Again Stealing Data and Holding It to Ransom</b><br>Digital extortion group Clop, aka Cl0p, has been tied to a fresh spate of supply-chain attacks, this time targeting users of popular

Bank Info Security
CRITICALRansomware

PTC Windchill Vulnerability Exploited in Ransomware Campaign

The critical unsafe deserialization flaw allows attackers to execute arbitrary code remotely, without authentication. The post PTC Windchill Vulnerability Exploited in Ransomware Campaign appeared first on SecurityWeek .

SecurityWeek
HIGHRansomware

Cl0p Affiliates Target Internet-Exposed PTC Windchill and FlexPLM with Unauthenticated RCE

Threat actors linked to the Cl0p (aka Chubby Scorpius, FIN11, Graceful Spider, and Lace Tempest) ransomware campaign are exploiting flaws in internet-exposed PTC Windmill and FlexPLM deployments as part of a new data extortion campaign. "Attackers chain a pre-authentication information disclosure in the FlexPLM WSDL endpoint with a server-side flaw in the Windchill login servlet, enabling

The Hacker News
CRITICALRansomware

Clop gang targets Windchill, FlexPLM in data theft attacks

Sergiu Gatlan reports: The Clop ransomware gang (also tracked as Cl0p) is targeting Internet-exposed PTC Windchill and FlexPLM instances in a new data theft extortion campaign. Clop has reportedly been exploiting a critical improper input validation vulnerability tracked as CVE-2026-12569, which allows attackers to execute arbitrary code on vulnerable Windchill and FlexPLM instances. As cybersecur

CVE-2026-12569
DataBreaches.net
HIGHRansomware

Clop ransomware targets Windchill, FlexPLM in data theft attacks

The Clop ransomware gang (also tracked as Cl0p) is targeting Internet-exposed PTC Windchill and FlexPLM instances in a new data theft extortion campaign. [...]

BleepingComputer