# Cl0p Ransomware MFT Attack Pattern: Multi-Year Zero-Day Campaigns Against File Transfer and Enterprise Software (2020-2025)

> Team Cymru's analysis of the financially motivated Cl0p group describes a repeatable playbook across nine campaigns built mostly on zero-days in managed file transfer and enterprise software (Accellion FTA, Serv-U, GoAnywhere MFT, MOVEit Transfer, Cleo, Oracle EBS, Gladinet CentreStack). Key patterns are long pre-attack scanning, heavy infrastructure rotation across 79 ASNs, 10-14 month dormancy between campaigns, and Q4 clustering.

- **Published:** 2026-10-09T00:00:00Z
- **Last reviewed:** 2026-10-09T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-3070
- **ID:** TL-2026-3070
- **Severity:** HIGH
- **Category:** RANSOMWARE
- **Status:** ACTIVE
- **Actor:** Cl0p
- **Detections:** 9 · **IOCs:** 16 (full data via the Threadlinqs MCP server — Purple tier)
- **CVEs:** CVE-2023-34362, CVE-2021-35211, CVE-2023-0669, CVE-2023-27350, CVE-2023-47246, CVE-2024-50623, CVE-2024-55956, CVE-2025-61882, CVE-2025-11371, CVE-2025-30406, CVE-2021-27101

## Description

Team Cymru (Eli Woodward, published 2026-08-12, presented at FIRSTCON Denver 2026) analyzed six years of Cl0p activity and found that the group repeatedly targets internet-facing applications that process, store, or transfer files. Of nine confirmed campaigns, seven target managed file transfer (MFT) products; PaperCut MF/NG (print management) and SysAid (ITSM) are the exceptions. The source title cites ten campaigns while its body enumerates nine. Campaigns include Accellion FTA (2020), SolarWinds Serv-U (2021, CVE-2021-35211), Fortra GoAnywhere MFT (January 2023, CVE-2023-0669), Progress MOVEit Transfer (May 2023, CVE-2023-34362), PaperCut (CVE-2023-27350), SysAid (CVE-2023-47246), Cleo Harmony/VLTrader/LexiCom (December 2024, CVE-2024-50623 and CVE-2024-55956), Oracle E-Business Suite (July-September 2025, CVE-2025-61882), and Gladinet CentreStack (from 2025-11-27).

Exploitation mechanics vary by product but follow a pattern. In MOVEit, SQL injection reached via /moveitisapi/moveitisapi.dll led to deployment of the LEMURLOOT web shell (placed at /human2.aspx) and exfiltration of stored files. Team Cymru highlights that the web shell invoked the application's own key-management function (GetBaseKeyProvider()) to decrypt files, making encryption at rest irrelevant because the decrypting capability sat on the same compromised component. In Gladinet CentreStack, public reporting (Security Affairs/Huntress) describes an unauthenticated local file inclusion (CVE-2025-11371) used to retrieve the machine key from Web.config, followed by ViewState deserialization for remote code execution (see also CVE-2025-30406). The Oracle EBS campaign saw reconnaissance from July 2025, exploitation from August, and extortion emails on 2025-09-29, so victims learned of compromise roughly two months after exploitation.

Infrastructure and operational tempo: Team Cymru observed 79 ASNs used across campaigns, of which 53 (67%) were single-campaign and 26 (33%) were reused. The most frequently reused providers include Hostzealot (HZ-US/HZ-BG; seen in four of nine campaigns), Colocrossing, Datacampus, Datahome, Ghostnet and OVH. Reconnaissance preceded exploitation by up to roughly two years in the MOVEit case (45.129.137.232 probing in July 2021, 92.118.36.233 in April 2022). Dormancy between campaigns is typically 10-14 months, with a burst of four campaigns in ten months in 2023. Five of nine campaigns began October-December, and the Gladinet compromise began on Thanksgiving (2025-11-27). Cl0p does not use public forums or Telegram and, for CentreStack, used the pubstorm.com and pubstorm.net domains for email extortion. Other public reporting (Vectra) also lists DEWMODE web shell, Truebot, and Mimikatz in Cl0p's wider toolkit; these are not tied to specific campaigns in the primary source.

Defensive guidance from the source: enumerate every internet-facing MFT application including shadow IT; apply default-deny WAF allowlisting (about 15 legitimate URI paths) so non-allowlisted requests become high-confidence reconnaissance indicators; retain MFT logs 12-24 months and retro-hunt on every MFT zero-day disclosure; baseline URIs and egress volumes per device; tighten outbound thresholds and review frequency October-January; watchlist Cl0p-associated ASNs on a rolling 180-day basis; and separate internet-facing components from key material and file storage. Attribution remains financially motivated; some Oracle EBS extortion attribution was publicly disputed.

## MITRE ATT&CK

- T1595 Active Scanning
- T1595.002 Active Scanning: Vulnerability Scanning
- T1583.003 Acquire Infrastructure: Virtual Private Server
- T1587.004 Develop Capabilities: Exploits
- T1190 Exploit Public-Facing Application
- T1505.003 Server Software Component: Web Shell
- T1552.001 Unsecured Credentials: Credentials In Files
- T1213 Data from Information Repositories
- T1657 Financial Theft

## Sources

- [Cl0p Til you Drop - 6 Years, 10 Campaigns, 8 Zero-Days (Team Cymru, Eli Woodward)](https://www.team-cymru.com/post/cl0p-ransomware-mft-attack-pattern-threat-intelligence)
- [CLOP targets Gladinet CentreStack servers in large-scale extortion campaign (Security Affairs)](https://securityaffairs.com/185875/cyber-crime/clop-targets-gladinet-centrestack-servers-in-large-scale-extortion-campaign.html)
- [Cl0p is back exploiting supply chains again (Vectra AI)](https://www.vectra.ai/blog/cl0p-is-back-exploiting-supply-chains-again)
- [Addressing CL0P Extortion Campaign Targeting Oracle EBS CVE-2025-61882 (Cybereason)](https://www.cybereason.com/blog/oracle-ebs-extortion-cl0p)
- [Cl0p ransomware surge 2025: operational patterns and key mitigations (HivePro)](https://hivepro.com/threat-advisory/cl0p-ransomware-surge-2025-operational-patterns-and-key-mitigations/)
- [Exploitation of CVE-2023-47246 (SecurityScorecard)](https://securityscorecard.com/resources/research/exploitation-of-cve-2023-47246/)
- [Ransomware Spotlight: Clop (Trend Micro)](https://trendmicro.com/vinfo/br/security/news/ransomware-spotlight/ransomware-spotlight-clop)
- [NVD - CVE-2023-34362 (MOVEit Transfer SQL injection)](https://nvd.nist.gov/vuln/detail/CVE-2023-34362)
- [NVD - CVE-2025-61882 (Oracle E-Business Suite)](https://nvd.nist.gov/vuln/detail/CVE-2025-61882)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-3070
