Clop, commonly stylized CL0P, is a financially motivated extortion operation that emerged in February 2019 from the CryptoMix ransomware lineage. Its tradecraft shifted from phishing-led ransomware deployment toward mass exploitation of managed file-transfer products, rapid data theft, and extortion. Major campaigns have targeted Accellion FTA, GoAnywhere MFT, and MOVEit Transfer.
Commonly goes inactive between campaigns but springs to life with custom-built web shells for mass exploitation
Activity timeline
Facts
Deployed JSP web shells against vulnerable PTC Windchill and FlexPLM instances following CVE-2026-12569 exploitation
Attribution highly likely based on references to 'Clop' throughout the web shell
Attribution assessment
Facts
Clop previously deployed DEWMODE after exploiting CVE-2021-27101 in Accellion
Clop previously deployed LEMURLOOT after exploiting CVE-2023-34362 in MOVEit Transfer
Operational playbook
Stages
Identify exposed managed file-transfer products at scale.
Exploit product-specific zero-days to place a web shell or gain access to the transfer appliance.
Enumerate application databases, cloud-storage settings, user records, and stored files.
Create or remove privileged service accounts when needed for access.
Exfiltrate files directly from the managed transfer platform, often without lateral movement into the wider network.
Research senior contacts, send ransom demands, and threaten publication through the CL0P leak site.
Initial access and identity targets
Facts
Exploitation of CVE-2026-12569 (CVSS 9.3) in PTC Windchill and FlexPLM servers involving improper input validation
Capabilities and evasion
Facts
Web shell capable of mapping sensitive vault data
Decrypts every credential in the Windchill keystore
Runs additional code via custom Java class loader
Supports commands for credential harvesting, file enumeration, file download, file deletion, and arbitrary file reading
Ability to load and execute Java classes from ZIP via class loader for secondary payload deployment
Vault enumeration targeting application database to identify high-value engineering data
Executes queries through Windchill's existing database identity to reduce forensic visibility
Infrastructure patterns
Facts
Web shell embeds detailed knowledge of PTC Windchill and FlexPLM APIs, database schema, keystore, and file-vault structure
Communication and pressure channels
Facts
Extortion emails containing addresses used on the ransomware gang's data leak site
Observed targeting
Facts
Targets PTC Windchill and FlexPLM instances used to store engineering data and product designs
Focuses on obtaining proprietary data and sensitive credentials for lateral movement
Defender guidance
Facts
Web shell blends in with regular Windchill traffic and uses application's own database connections to evade signature-based defenses
Movement from initial access through data theft occurs entirely within application's trust boundary with limited forensic visibility
Reported detail
Facts
Clop deployed a custom JSP web shell against PTC Windchill and FlexPLM servers after exploiting CVE-2026-12569, designed specifically for those products
The web shell decrypts stored credentials including LDAP manager and administrative passwords, enabling potential enterprise-wide compromise
It includes commands for credential harvesting, vault enumeration, file operations, and loading arbitrary Java code for secondary payloads
The implant operates within the application's process using its own database connections to minimize detectability compared to traditional web shells
This represents part of Clop's pattern of developing application-specific web shells when mass-exploitation opportunities emerge in data-rich software
Activity timeline
A dated ledger of actor-claimed victims, campaigns, indicators, identity mappings, relationships, and CVE links. Each date states what it measures. For extensive leak-site histories, victim entries are limited to the 100 most recent distinct listings.
First listed
Victim claimHENRYPRATT.COM listed by Clop
Actor-claimed victim evidence. This listing is not independent confirmation of compromise.
Actor Claimed
First listed
Victim claimHARLEY-DAVIDSON.COM listed by Clop
Actor-claimed victim evidence. This listing is not independent confirmation of compromise.
Actor Claimed
Last observed
Indicator3 indicators cataloged
Types: onion.
Cataloged
IdentityAlias: Cl0p
Reviewed identity mapping approved on this date.
Cataloged
Indicator6 indicators cataloged
Types: domain, tool.
Cataloged
Indicator3 indicators cataloged
Types: domain, tool.
Cataloged
IdentityAlias: Cl0p
Reviewed identity mapping approved on this date.
Cataloged
IdentityTracking identifier: CVE-2026-12569
Reviewed identity mapping approved on this date.
First observed
CVECVE-2026-12569 linked to this actor
Clop-Linked Windchill Web Shell Decrypts Credentials and Maps Engineering Data
First observed
CVECVE-2021-27101 linked to this actor
Clop-Linked Windchill Web Shell Decrypts Credentials and Maps Engineering Data
First observed
CVECVE-2023-34362 linked to this actor
Clop-Linked Windchill Web Shell Decrypts Credentials and Maps Engineering Data
First observed
CVECVE-2026-58231 linked to this actor
Clop-Linked Windchill Web Shell Decrypts Credentials and Maps Engineering Data
First observed
CVECVE-2026-12569 linked to this actor
Clop created custom web shell for Windchill data theft attacks
Cataloged
Indicator13 indicators cataloged
Types: email, filename, sha256.
Cataloged
RelationshipOverlaps relationship with TA505
FBI and CISA associate CL0P campaigns with TA505. TA505 remains a separate broader cybercrime cluster because its malware distribution, botnet, access-broker, and fraud activity extends beyond Clop.
High
Cataloged
IdentityAlias: CL0P
Reviewed identity mapping approved on this date.
Claimed
Victim claimZEBRA.COM listed by Clop
Actor-claimed victim evidence. This listing is not independent confirmation of compromise.
Actor Claimed
First listed
Victim claimAOL.COM listed by Clop
Actor-claimed victim evidence. This listing is not independent confirmation of compromise.
Actor Claimed
First listed
Victim claimGATE7LLC.COMGBBEV.COM listed by Clop
Actor-claimed victim evidence. This listing is not independent confirmation of compromise.
Actor Claimed
First listed
Victim claimENTERATEK.MXESBERBEVERAGE.COM listed by Clop
Actor-claimed victim evidence. This listing is not independent confirmation of compromise.
Actor Claimed
First listed
Victim claimNUVITIA.COM listed by Clop
Actor-claimed victim evidence. This listing is not independent confirmation of compromise.
Actor Claimed
First listed
Victim claimIPMSOLUTIONS.SK listed by Clop
Actor-claimed victim evidence. This listing is not independent confirmation of compromise.
Actor Claimed
First listed
Victim claimECCELLENT.COM listed by Clop
Actor-claimed victim evidence. This listing is not independent confirmation of compromise.
Actor Claimed
First listed
Victim claimSTNET.IT listed by Clop
Actor-claimed victim evidence. This listing is not independent confirmation of compromise.
Actor Claimed
First listed
Victim claimQCPL.IN listed by Clop
Actor-claimed victim evidence. This listing is not independent confirmation of compromise.
Actor Claimed
The interactive view includes 114 dated events with category filters and paging.
Identity and attribution
Exact names and tracking identifiers resolve to this canonical profile. Rebrands, affiliations, and overlapping clusters remain separate confidence-rated relationships.