← Back to all threat actors

Clop

Also known as Cl0p, CL0P
Tracked as CVE-2026-12569

Clop, commonly stylized CL0P, is a financially motivated extortion operation that emerged in February 2019 from the CryptoMix ransomware lineage. Its tradecraft shifted from phishing-led ransomware deployment toward mass exploitation of managed file-transfer products, rapid data theft, and extortion. Major campaigns have targeted Accellion FTA, GoAnywhere MFT, and MOVEit Transfer.

How we source and review actor profiles
Motivation
ransomware
First seen
2019-02-01
Last seen
2026-09-10
Sectors
technology, professional-services, retail-e-commerce, manufacturing, transportation, financial-services, healthcare, education, agriculture-and-food-production, energy-utilities, hospitality, government-defense
Status
Active

Threat intelligence assessment

At a glance

Facts

  • E-crime group known for ransomware operations
  • Commonly goes inactive between campaigns but springs to life with custom-built web shells for mass exploitation

Activity timeline

Facts

  • Deployed JSP web shells against vulnerable PTC Windchill and FlexPLM instances following CVE-2026-12569 exploitation
  • Attribution highly likely based on references to 'Clop' throughout the web shell

Attribution assessment

Facts

  • Clop previously deployed DEWMODE after exploiting CVE-2021-27101 in Accellion
  • Clop previously deployed LEMURLOOT after exploiting CVE-2023-34362 in MOVEit Transfer

Operational playbook

Stages

  • Identify exposed managed file-transfer products at scale.
  • Exploit product-specific zero-days to place a web shell or gain access to the transfer appliance.
  • Enumerate application databases, cloud-storage settings, user records, and stored files.
  • Create or remove privileged service accounts when needed for access.
  • Exfiltrate files directly from the managed transfer platform, often without lateral movement into the wider network.
  • Research senior contacts, send ransom demands, and threaten publication through the CL0P leak site.

Initial access and identity targets

Facts

  • Exploitation of CVE-2026-12569 (CVSS 9.3) in PTC Windchill and FlexPLM servers involving improper input validation

Capabilities and evasion

Facts

  • Web shell capable of mapping sensitive vault data
  • Decrypts every credential in the Windchill keystore
  • Runs additional code via custom Java class loader
  • Supports commands for credential harvesting, file enumeration, file download, file deletion, and arbitrary file reading
  • Ability to load and execute Java classes from ZIP via class loader for secondary payload deployment
  • Vault enumeration targeting application database to identify high-value engineering data
  • Executes queries through Windchill's existing database identity to reduce forensic visibility

Infrastructure patterns

Facts

  • Web shell embeds detailed knowledge of PTC Windchill and FlexPLM APIs, database schema, keystore, and file-vault structure

Communication and pressure channels

Facts

  • Extortion emails containing addresses used on the ransomware gang's data leak site

Observed targeting

Facts

  • Targets PTC Windchill and FlexPLM instances used to store engineering data and product designs
  • Focuses on obtaining proprietary data and sensitive credentials for lateral movement

Defender guidance

Facts

  • Web shell blends in with regular Windchill traffic and uses application's own database connections to evade signature-based defenses
  • Movement from initial access through data theft occurs entirely within application's trust boundary with limited forensic visibility

Reported detail

Facts

  • Clop deployed a custom JSP web shell against PTC Windchill and FlexPLM servers after exploiting CVE-2026-12569, designed specifically for those products
  • The web shell decrypts stored credentials including LDAP manager and administrative passwords, enabling potential enterprise-wide compromise
  • It includes commands for credential harvesting, vault enumeration, file operations, and loading arbitrary Java code for secondary payloads
  • The implant operates within the application's process using its own database connections to minimize detectability compared to traditional web shells
  • This represents part of Clop's pattern of developing application-specific web shells when mass-exploitation opportunities emerge in data-rich software

Activity timeline

A dated ledger of actor-claimed victims, campaigns, indicators, identity mappings, relationships, and CVE links. Each date states what it measures. For extensive leak-site histories, victim entries are limited to the 100 most recent distinct listings.

First listed
Victim claimHENRYPRATT.COM listed by Clop

Actor-claimed victim evidence. This listing is not independent confirmation of compromise.

Actor Claimed
First listed
Victim claimHARLEY-DAVIDSON.COM listed by Clop

Actor-claimed victim evidence. This listing is not independent confirmation of compromise.

Actor Claimed
Last observed
Indicator3 indicators cataloged

Types: onion.

Cataloged
IdentityAlias: Cl0p

Reviewed identity mapping approved on this date.

Cataloged
Indicator6 indicators cataloged

Types: domain, tool.

Cataloged
Indicator3 indicators cataloged

Types: domain, tool.

Cataloged
IdentityAlias: Cl0p

Reviewed identity mapping approved on this date.

Cataloged
IdentityTracking identifier: CVE-2026-12569

Reviewed identity mapping approved on this date.

First observed
CVECVE-2026-12569 linked to this actor

Clop-Linked Windchill Web Shell Decrypts Credentials and Maps Engineering Data

First observed
CVECVE-2021-27101 linked to this actor

Clop-Linked Windchill Web Shell Decrypts Credentials and Maps Engineering Data

First observed
CVECVE-2023-34362 linked to this actor

Clop-Linked Windchill Web Shell Decrypts Credentials and Maps Engineering Data

First observed
CVECVE-2026-58231 linked to this actor

Clop-Linked Windchill Web Shell Decrypts Credentials and Maps Engineering Data

First observed
CVECVE-2026-12569 linked to this actor

Clop created custom web shell for Windchill data theft attacks

Cataloged
Indicator13 indicators cataloged

Types: email, filename, sha256.

Cataloged
RelationshipOverlaps relationship with TA505

FBI and CISA associate CL0P campaigns with TA505. TA505 remains a separate broader cybercrime cluster because its malware distribution, botnet, access-broker, and fraud activity extends beyond Clop.

High
Cataloged
IdentityAlias: CL0P

Reviewed identity mapping approved on this date.

Claimed
Victim claimZEBRA.COM listed by Clop

Actor-claimed victim evidence. This listing is not independent confirmation of compromise.

Actor Claimed
First listed
Victim claimAOL.COM listed by Clop

Actor-claimed victim evidence. This listing is not independent confirmation of compromise.

Actor Claimed
First listed
Victim claimGATE7LLC.COMGBBEV.COM listed by Clop

Actor-claimed victim evidence. This listing is not independent confirmation of compromise.

Actor Claimed
First listed
Victim claimENTERATEK.MXESBERBEVERAGE.COM listed by Clop

Actor-claimed victim evidence. This listing is not independent confirmation of compromise.

Actor Claimed
First listed
Victim claimNUVITIA.COM listed by Clop

Actor-claimed victim evidence. This listing is not independent confirmation of compromise.

Actor Claimed
First listed
Victim claimIPMSOLUTIONS.SK listed by Clop

Actor-claimed victim evidence. This listing is not independent confirmation of compromise.

Actor Claimed
First listed
Victim claimECCELLENT.COM listed by Clop

Actor-claimed victim evidence. This listing is not independent confirmation of compromise.

Actor Claimed
First listed
Victim claimSTNET.IT listed by Clop

Actor-claimed victim evidence. This listing is not independent confirmation of compromise.

Actor Claimed
First listed
Victim claimQCPL.IN listed by Clop

Actor-claimed victim evidence. This listing is not independent confirmation of compromise.

Actor Claimed

The interactive view includes 114 dated events with category filters and paging.

Identity and attribution

Exact names and tracking identifiers resolve to this canonical profile. Rebrands, affiliations, and overlapping clusters remain separate confidence-rated relationships.

Name map

ClopCanonical Name
CL0PAlias
CVE-2026-12569Tracking Id

Loading CVEs, techniques, indicators, malware, victims, and activity...