# Cl0p

> As of 2026-09-08, Cl0p is a Russia-nexus threat actor tracked by Threadlinqs Intelligence across 4 threats spanning data breach, vulnerability, ransomware. ATT&CK coverage spans 62 techniques across 15 tactics in 4 of 4 tracked threats. Most-observed techniques: T1027 (Obfuscated Files or Information), T1041 (Exfiltration Over C2 Channel), T1059 (Command and Scripting Interpreter).

- **Nation:** Russia
- **Tracked threats:** 4
- **Categories:** DATA_BREACH, VULNERABILITY, RANSOMWARE
- **As of:** 2026-09-08

## ATT&CK techniques observed

62 techniques observed across 4 of 4 tracked threats. Tactics: Stealth (formerly Defense Evasion) (9), Discovery (8), Resource Development (7), Command and Control (6), Execution (6), Collection (5).

- [T1027](https://intel.threadlinqs.com/technique/T1027) Obfuscated Files or Information — Stealth (formerly Defense Evasion) — observed in 4 of 4 tracked threats
- [T1041](https://intel.threadlinqs.com/technique/T1041) Exfiltration Over C2 Channel — Exfiltration — observed in 4 of 4 tracked threats
- [T1059](https://intel.threadlinqs.com/technique/T1059) Command and Scripting Interpreter — Execution — observed in 4 of 4 tracked threats
- [T1071](https://intel.threadlinqs.com/technique/T1071) Application Layer Protocol — Command and Control — observed in 4 of 4 tracked threats
- [T1083](https://intel.threadlinqs.com/technique/T1083) File and Directory Discovery — Discovery — observed in 4 of 4 tracked threats
- [T1105](https://intel.threadlinqs.com/technique/T1105) Ingress Tool Transfer — Command and Control — observed in 4 of 4 tracked threats
- [T1190](https://intel.threadlinqs.com/technique/T1190) Exploit Public-Facing Application — Initial Access — observed in 4 of 4 tracked threats
- [T1505](https://intel.threadlinqs.com/technique/T1505) Server Software Component — Persistence — observed in 4 of 4 tracked threats
- [T1657](https://intel.threadlinqs.com/technique/T1657) Financial Theft — Impact — observed in 4 of 4 tracked threats
- [T1005](https://intel.threadlinqs.com/technique/T1005) Data from Local System — Collection — observed in 3 of 4 tracked threats
- [T1036](https://intel.threadlinqs.com/technique/T1036) Masquerading — Stealth (formerly Defense Evasion) — observed in 3 of 4 tracked threats
- [T1078](https://intel.threadlinqs.com/technique/T1078) Valid Accounts — Initial Access — observed in 3 of 4 tracked threats
- [T1082](https://intel.threadlinqs.com/technique/T1082) System Information Discovery — Discovery — observed in 3 of 4 tracked threats
- [T1140](https://intel.threadlinqs.com/technique/T1140) Deobfuscate/Decode Files or Information — Stealth (formerly Defense Evasion) — observed in 3 of 4 tracked threats
- [T1203](https://intel.threadlinqs.com/technique/T1203) Exploitation for Client Execution — Execution — observed in 3 of 4 tracked threats

## Tracked threats

- [Estée Lauder Data Breach via Oracle E-Business Suite Zero-Day (CVE-2025-61882) — Clop Exploitation](https://intel.threadlinqs.com/threat/TL-2026-1590) — CRITICAL
- [CVE-2026-12569: PTC Windchill PDMLink / FlexPLM Unauthenticated Deserialization RCE (CISA KEV, JSP Web Shell Campaign)](https://intel.threadlinqs.com/threat/TL-2026-0954) — CRITICAL
- [CISA KEV Adds CVE-2026-12569 (PTC Windchill/FlexPLM Unauthenticated RCE via Deserialization) and CVE-2026-20230 (Cisco Unified CM WebDialer SSRF to Root)](https://intel.threadlinqs.com/threat/TL-2026-1244) — CRITICAL
- [Q1 2026 Ransomware Landscape: Qilin Dominance, LockBit 5.0 Comeback, and FortiGate (CVE-2024-55591) / Oracle EBS (CVE-2025-61882) Mass Exploitation](https://intel.threadlinqs.com/threat/TL-2026-0758) — CRITICAL

## Related CVEs

9 CVEs referenced by tracked Cl0p activity.

- [CVE-2026-46817](https://intel.threadlinqs.com/cve/CVE-2026-46817)
- [CVE-2026-4681](https://intel.threadlinqs.com/cve/CVE-2026-4681)
- [CVE-2026-20230](https://intel.threadlinqs.com/cve/CVE-2026-20230)
- [CVE-2026-12569](https://intel.threadlinqs.com/cve/CVE-2026-12569)
- [CVE-2025-61884](https://intel.threadlinqs.com/cve/CVE-2025-61884)
- [CVE-2025-61882](https://intel.threadlinqs.com/cve/CVE-2025-61882)
- [CVE-2025-33073](https://intel.threadlinqs.com/cve/CVE-2025-33073)
- [CVE-2025-32433](https://intel.threadlinqs.com/cve/CVE-2025-32433)
- [CVE-2024-55591](https://intel.threadlinqs.com/cve/CVE-2024-55591)

## Full data

Infrastructure, IOC values and detection queries (Splunk SPL / Microsoft KQL / Sigma) require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/actor/Cl0p
