HOME

TheInfoList



OR:

Clop (sometimes written “Cl0p”) is a
cybercriminal Cybercrime encompasses a wide range of criminal activities that are carried out using digital devices and/or networks. It has been variously defined as "a crime committed on a computer network, especially the Internet"; Cybercriminals may explo ...
organization known for its multilevel extortion techniques and global
malware Malware (a portmanteau of ''malicious software'')Tahir, R. (2018)A study on malware and malware detection techniques . ''International Journal of Education and Management Engineering'', ''8''(2), 20. is any software intentionally designed to caus ...
distribution. It has extorted more than $500 million in ransom payments, targeting major organizations worldwide. Clop gained notoriety in 2019 and has since conducted high-profile attacks, using large-scale
phishing Phishing is a form of social engineering and a scam where attackers deceive people into revealing sensitive information or installing malware such as viruses, worms, adware, or ransomware. Phishing attacks have become increasingly sophisticate ...
campaigns and sophisticated malware to infiltrate networks and demand ransom, threatening to expose data if demands are not met. Clop increasingly uses pure extortion approaches with "encryption-less ransomware". It also employs more complex attacks, such as zero-day, that have a significant impact and allows them to demand higher ransom payments.


Description

Clop is a Russian-speaking
ransomware Ransomware is a type of malware that Encryption, encrypts the victim's personal data until a ransom is paid. Difficult-to-trace Digital currency, digital currencies such as paysafecard or Bitcoin and other cryptocurrency, cryptocurrencies are com ...
gang. According to the US
Cybersecurity and Infrastructure Security Agency The Cybersecurity and Infrastructure Security Agency (CISA) is a component of the United States Department of Homeland Security (DHS) responsible for cybersecurity and infrastructure protection across all levels of government, coordinating cyber ...
(CISA), Clop is "driving global trends in criminal malware distribution". Clop avoids targets in former Soviet countries and its malware can't breach a computer that operates primarily in Russian. In 2023, Clop uses more and more pure extortion approaches with "encryption-less ransomware" that skips the
encryption In Cryptography law, cryptography, encryption (more specifically, Code, encoding) is the process of transforming information in a way that, ideally, only authorized parties can decode. This process converts the original representation of the inf ...
process but still threatens to leak data if a ransom is not paid. This technique allows threat actors to achieve the same results and generate larger profits. Clop is used to conducting malicious activities during holidays, when the number of staff members present in companies tends to be at its lowest. This is the case of the Accellion FTA software attack on December 23, 2020, and MOVEit attack during the summer 2023. The cybercriminals declared to Bleeping Computer to have erased "right away" data concerning "the military, children's hospitals, GOV etc".


History


First exploits

The gang was first spotted by researchers in February 2019. It evolved as a variant of the "CryptoMix" ransomware family. Clop is an example of ransomware as a service (RaaS). Clop ransomware used a verified and digitally signed binary, which made it look like a legitimate executable file that could evade security detection. In December 2019, the group attacked
Maastricht University Maastricht University (abbreviated as UM; ) is a public university, public research university in Maastricht, Netherlands. Founded in 1976, it is the second youngest of the thirteen List of universities in the Netherlands, Dutch universities. In ...
. The ransomware encrypted almost all Windows systems used by Maastricht University, making it impossible for students and staff members to access any university online services during the Christmas break. The offenders set a ransom, which allowed a decryption of the university systems after Maastricht University paid €200,000 in a
Bitcoin Bitcoin (abbreviation: BTC; Currency symbol, sign: ₿) is the first Decentralized application, decentralized cryptocurrency. Based on a free-market ideology, bitcoin was invented in 2008 when an unknown entity published a white paper under ...
transfer. The lessons resumed with no delays on 6 January, with most online services again available to both students and staff members. In 2020, the public prosecutor service seized the cryptocurrency account in which the ransom was paid. Once the ransom was converted from Bitcoin to Euros, the university was able to recover €500,000, double of what was paid.


Accellion FTA attack (2020)

Accellion, a company providing a legacy File Transfer Appliance (FTA), experienced a series of data breaches in mid-December 2020. Threat actors took advantage of zero-day vulnerabilities and a web shell known as DEWMODE to breach the systems of up to 100 companies using Accellion's FTA. The stolen data included sensitive files. The attacks were attributed to the Clop ransomware gang and the FIN11 threat group, although no ransomware was deployed during these specific incidents. After exfiltrating the data, the attackers threatened to make the stolen information public unless a ransom was paid. Several organizations were identified as victims of these breaches, including
Kroger The Kroger Company, or simply Kroger, is an American retail company that operates (either directly or through its subsidiaries) supermarkets and multi-department stores throughout the United States. Founded by Bernard Kroger in 1883 in Cinc ...
, Singtel, QIMR Berghofer Medical Research Institute, Reserve Bank of New Zealand, ASIC, and the Office of the Washington State Auditor, among others.


GoAnywhere MFT attack (2023)

In January 2023, the gang claimed responsibility for breaching over 130 organizations by exploiting a zero-day vulnerability in the GoAnywhere MFT secure file transfer tool. This security flaw, identified as CVE-2023-0669, allows attackers to execute remote code on unpatched instances of GoAnywhere MFT that have their administrative console exposed to the Internet.


MOVEit exploitation (2023)

In 2023, Clop employs more complex attacks that make significant impacts and allow them to demand higher ransom payments. Specifically, the Clop gang targeted data theft by exploiting a zero-day vulnerability in MOVEit Transfer. Their objective is to overcome the overall decline in ransom payments by demanding substantial amounts from their victims. In 2023, the gang claims credit for the following hack :
BBC The British Broadcasting Corporation (BBC) is a British public service broadcaster headquartered at Broadcasting House in London, England. Originally established in 1922 as the British Broadcasting Company, it evolved into its current sta ...
and
British Airways British Airways plc (BA) is the flag carrier of the United Kingdom. It is headquartered in London, England, near its main Airline hub, hub at Heathrow Airport. The airline is the second largest UK-based carrier, based on fleet size and pass ...
, Estee Lauder companies, 1st Source, First National Bankers Bank (USA),
Putnam Investments Putnam Investments is an investment management firm founded in 1937 by George Putnam, who established one of the first balanced mutual funds, The George Putnam Fund of Boston. Headquartered in Boston, Massachusetts, it has offices in London, To ...
(USA), Landal Greenparks (Netherlands),
Shell Shell may refer to: Architecture and design * Shell (structure), a thin structure ** Concrete shell, a thin shell of concrete, usually with no interior columns or exterior buttresses Science Biology * Seashell, a hard outer layer of a marine ani ...
(UK), the
New York City Department of Education The New York City Department of Education (NYCDOE) is the department of the government of New York City that manages the city's public school system. The City School District of the City of New York (more commonly known as New York City Publ ...
, and
Ernst & Young EY, previously known as Ernst & Young, is a multinational corporation, multinational professional services partnership, network based in London, United Kingdom. Along with Deloitte, KPMG and PwC, it is one of the Big Four accounting firms, Big F ...
. As of July 2023, the Clop ransomware gang is projected to earn an estimated $75-100 million from their extortion attacks using the MOVEit Transfer vulnerability.


Methods

Clop uses big
phishing Phishing is a form of social engineering and a scam where attackers deceive people into revealing sensitive information or installing malware such as viruses, worms, adware, or ransomware. Phishing attacks have become increasingly sophisticate ...
campaigns. The emails contain HTML attachments that redirect recipients to a macro-enabled document used to install a loader named Get2. This loader facilitates the download of other tools such as SDBOT, FlawedAmmyy, and Cobalt Strike. Once in the system, the gang proceeds to
reconnaissance In military operations, military reconnaissance () or scouting is the exploration of an area by military forces to obtain information about enemy forces, the terrain, and civil activities in the area of operations. In military jargon, reconnai ...
, lateral movement, and exfiltration to set the stage for the deployment of their ransomware. Then Clop coerces their victim by sending emails in a bid for negotiations. If their messages are ignored, they threaten to publicize the data on their data leak website “Cl0p^_-Leaks”. Clop has more recently been reported to use TrueBot malware for access to networks. The loader deployed by the "Silence" hacker group, affects over 1,500 systems worldwide in 2023.


See also

*
Conti (ransomware) Conti is malware developed and first used by the Russia-based hacking group "Wizard Spider" in December, 2019. It has since become a full-fledged Ransomware as a service, ransomware-as-a-service (RaaS) operation used by numerous threat actor gro ...
* LockBit * Royal (cyber gang) *
2023 MOVEit data breach Discovered in May 2023, a critical vulnerability in the MOVEit managed file transfer software triggered a wave of Cyberattack, cyberattacks and Data breach, data breaches. Exploited by the notorious ransomware group Clop (cyber gang), CL0P, the ...


References

{{Hacking in the 2020s Hacker groups Ransomware Cybercrime