← All Threat Actors
Threat Actor Profile

Cl0p

TA505 Evil Corp affiliate LACE TEMPEST
▲ High Threat
MOVEit mass exploitation (2023) hitting 1000+ organizations, GoAnywhere zero-day
Origin Russia/Ukraine
Sponsor Financially motivated criminal group
Active Since 2019
Motivation Financial gain (ransomware)

Target Sectors

Financial Healthcare Manufacturing Technology Education

Known TTPs

MOVEit exploitation
GoAnywhere exploitation
Accellion FTA exploitation
Double extortion ransomware
Mass exploitation

Related Intelligence

Hacking the mainframe…

LINK COPIED TO CLIPBOARD