Activity timeline
Cl0p appears in 4 tracked threats between and ; the busiest month was 2026-06 with 3 reports.
ATT&CK techniques observed
- T1027 Obfuscated Files or Information — Stealth (formerly Defense Evasion)observed in 4 of 4 tracked threats
- T1041 Exfiltration Over C2 Channel — Exfiltrationobserved in 4 of 4 tracked threats
- T1059 Command and Scripting Interpreter — Executionobserved in 4 of 4 tracked threats
- T1071 Application Layer Protocol — Command and Controlobserved in 4 of 4 tracked threats
- T1083 File and Directory Discovery — Discoveryobserved in 4 of 4 tracked threats
- T1105 Ingress Tool Transfer — Command and Controlobserved in 4 of 4 tracked threats
- T1190 Exploit Public-Facing Application — Initial Accessobserved in 4 of 4 tracked threats
- T1505 Server Software Component — Persistenceobserved in 4 of 4 tracked threats
- T1657 Financial Theft — Impactobserved in 4 of 4 tracked threats
- T1005 Data from Local System — Collectionobserved in 3 of 4 tracked threats
- T1036 Masquerading — Stealth (formerly Defense Evasion)observed in 3 of 4 tracked threats
- T1078 Valid Accounts — Initial Accessobserved in 3 of 4 tracked threats
- T1082 System Information Discovery — Discoveryobserved in 3 of 4 tracked threats
- T1140 Deobfuscate/Decode Files or Information — Stealth (formerly Defense Evasion)observed in 3 of 4 tracked threats
- T1203 Exploitation for Client Execution — Executionobserved in 3 of 4 tracked threats
Tracked threats
- Estée Lauder Data Breach via Oracle E-Business Suite Zero-Day (CVE-2025-61882) — Clop ExploitationCRITICAL
- CVE-2026-12569: PTC Windchill PDMLink / FlexPLM Unauthenticated Deserialization RCE (CISA KEV, JSP Web Shell Campaign)CRITICAL
- CISA KEV Adds CVE-2026-12569 (PTC Windchill/FlexPLM Unauthenticated RCE via Deserialization) and CVE-2026-20230 (Cisco Unified CM WebDialer SSRF to Root)CRITICAL
- Q1 2026 Ransomware Landscape: Qilin Dominance, LockBit 5.0 Comeback, and FortiGate (CVE-2024-55591) / Oracle EBS (CVE-2025-61882) Mass ExploitationCRITICAL