DETECTO/ThreatDossier
DashboardPricingThreatsRun Free ScanSign In
DETECTO/ThreatDossier

Security intelligence for MSPs, consultants, and businesses. Find breached credentials, compliance gaps, and exposed infrastructure before attackers do.

Product

  • Scan a Domain
  • Pricing
  • Dashboard
  • Sign In

Resources

  • Threat Intelligence
  • Ransomware Groups

Legal

  • Privacy Policy
  • Terms of Service

© 2026 DETECTO. All rights reserved.

Threats/Groups/Cl0p

Cl0p

Active

clop

First seen: 2020-03-13 00:00:00.000000Total victims: 1,253

The ransomware group known as Cl0p is a variant of a previously known strain dubbed CryptoMix. It is worth noting that this variant was delivered as the final payload in a phishing campaign in 2019 and was exclusively financially motivated, with attacks carried out by the threat actors TA505.<br> <br> At that time, malicious actors sent phishing emails that led to a macro-enabled document that would drop a loader called 'Get2.' After gaining an initial foothold in the system or infrastructure, the actors began using reconnaissance, lateral movement, and exfiltration techniques to prepare for the deployment of the ransomware.<br> <br> After the execution of the ransomware, Cl0p appends the extension '.clop' to the end of files, or other types of extensions such as '.CIIp, .Cllp, and .C_L_O_P,' as well as different versions of the ransom note that were also observed after encryption. Depending on the variant, any of the ransom text files were created with names like 'ClopReadMe.txt, README_README.txt, Cl0pReadMe.txt, and READ_ME_!!!.TXT.'<br> <br> The Clop operation has shifted from delivering its final payload via phishing and has begun initiating attacks using vulnerabilities that resulted in the exploitation and infection of victims' infrastructures.<BR>Source: https://github.com/crocodyli/ThreatActors-TTPs

0Total Victims
0Countries Targeted
0Sectors Targeted
0Avg Attacks/Month

Activity Timelinelast 24 months

Top Targeted Sectors

Top Targeted Countries

Recent Victimsshowing 50 of 1253

NameCountrySectorDate
AIGHEALTHCARE.ININHealthcare2026-03-30 07:59:47.092937
CLOUD.CLEARWAYGROUP.COM—Technology2026-03-30 07:58:56.663916
DAD.CO.THTHNot Found2026-02-14 10:55:58.163302
THEMORTGAGEFIRM.COMUSFinancial Services2026-02-14 10:55:21.878217
FISHWINDOWCLEANING.COMUSBusiness Services2026-02-14 10:54:45.654361
SOLUTIONSINSAFETY.COM—Business Services2026-02-14 10:54:09.499258
BOYDEN.COMUSNot Found2026-02-14 10:53:30.649260
CFDT.FRFRNot Found2026-02-14 10:52:54.020049
SPOHNASSOCIATES.COMUSTechnology2026-02-14 10:52:17.980381
GARNERGROUP.NET—Not Found2026-02-14 10:51:40.888817
THEPERPETUAL.COMUSTechnology2026-02-14 10:51:05.419369
AIGBUSINESS.COM—Financial Services2026-02-14 10:50:30.865171
HYDEPARKUMC.ORGUSEducation2026-02-14 10:49:54.969440
GIACARE.COMUSHealthcare2026-02-14 10:49:20.607509
GIASPACE.COMUSTechnology2026-02-14 10:48:45.544479
ONESUPPORT.COMUSTechnology2026-02-14 10:48:09.594250
HUDSONSUSTAINABLE.COMUSEnergy2026-02-14 10:47:31.906931
GOKALLIT.COM—Technology2026-02-14 10:46:55.448234
CHEHARDY.COMUSNot Found2026-02-14 10:46:18.699261
RBDCONSTRUCTION.COMUSConstruction2026-02-14 10:45:44.483880
BROADREACHRETAIL.COMUSNot Found2026-02-14 10:45:08.827784
BE09.FRFRNot Found2026-02-14 10:44:33.397357
SMITHIPSERVICES.COM—Not Found2026-02-14 10:43:59.280846
PROACTIVEMEDICAL.COMUSHealthcare2026-02-14 10:43:22.852924
ITARCHITECHS.COMUSTechnology2026-02-14 10:42:46.496954
HUDSONEXECUTIVE.COMUSFinancial Services2026-02-14 10:42:11.956342
ANSTECHINC.COMUSTechnology2026-02-14 10:41:34.408242
MNKASSOCIATES.COM—Not Found2026-02-07 21:14:06.719824
VIPPLLC.COM—Not Found2026-02-07 21:13:31.630405
TRJLTD.CO.UKUKNot Found2026-02-07 21:12:56.344297
STRATEGICOBJECTIVES.COMCABusiness Services2026-02-07 21:12:22.220121
IDEALWELDERS.COMCAManufacturing2026-02-07 21:11:44.642504
CROWDEDISLAND.COM—Not Found2026-02-07 21:11:08.025195
DUKOSI.COMGBTechnology2026-02-07 21:10:33.217938
CONWEST.COMCANot Found2026-02-07 21:09:55.346952
NGATTORNEYS.COM—Not Found2026-02-07 21:09:20.089291
LABINF.ITITTechnology2026-02-07 21:08:45.361753
AUGUSTEA.COMITNot Found2026-02-07 21:08:09.024162
MEDIAWORLD.COM.HKHKTechnology2026-02-07 21:07:32.512119
WARDHAVENCAPITAL.COM—Financial Services2026-02-07 21:06:58.373814
LONGHORNORGANICS.COMUSAgriculture and Food Production2026-02-07 21:06:22.078039
DCSNORWAY.COMNONot Found2026-02-07 21:05:44.664396
SHACKELFORD.LAW—Not Found2026-02-07 21:05:09.949285
SERVE-CLOUD.COM—Technology2026-02-07 21:04:33.267392
MARK-FINN.CO.UKUKNot Found2026-02-07 21:03:57.264331
EMEG.CO.UKUKNot Found2026-02-07 21:03:19.725186
LOGICALMICRO.COMGBTechnology2026-02-07 21:02:30.590625
HODERO HOLDINGS LTDBMNot Found2026-02-07 21:01:55.604930
NVHG.COMUSNot Found2026-02-07 21:01:40.306931
WHEELOCKST.COMUSNot Found2026-02-07 21:01:03.000046

Data from ransomware.live