Saltar al contenido
Ransomware Response · Respuesta a incidentes de ransomware

Actor de amenazas

clop

12 víctimas en México
Perfil del grupoInteligencia
url
https://www.ransomware.live/group/clop
name
clop
description
The ransomware group known as Cl0p is a variant of a previously known strain dubbed CryptoMix. It is worth noting that this variant was delivered as the final payload in a phishing campaign in 2019 and was exclusively financially motivated, with attacks carried out by the threat actors TA505.<br> <br> At that time, malicious actors sent phishing emails that led to a macro-enabled document that would drop a loader called 'Get2.' After gaining an initial foothold in the system or infrastructure, the actors began using reconnaissance, lateral movement, and exfiltration techniques to prepare for the deployment of the ransomware.<br> <br> After the execution of the ransomware, Cl0p appends the extension '.clop' to the end of files, or other types of extensions such as '.CIIp, .Cllp, and .C_L_O_P,' as well as different versions of the ransom note that were also observed after encryption. Depending on the variant, any of the ransom text files were created with names like 'ClopReadMe.txt, README_README.txt, Cl0pReadMe.txt, and READ_ME_!!!.TXT.'<br> <br> The Clop operation has shifted from delivering its final payload via phishing and has begun initiating attacks using vulnerabilities that resulted in the exploitation and infection of victims' infrastructures.<BR>Source: https://github.com/crocodyli/ThreatActors-TTPs
Víctimas recientesMás recientes primero
FechaVíctimaGrupoSectorFuente
21 de noviembre de 2025GRUPOBIMBO.COMclopAgriculture and Food Productionn/d
27 de febrero de 2025ENTERATEK.MXclopTechnologyn/d
27 de febrero de 2025VIDAGROUP.COMclopBusiness Servicesn/d
27 de febrero de 2025LOSCABOSMEXICANFOODS.COMclopHospitality and Tourismn/d
27 de febrero de 2025IUSA.MXclopManufacturingn/d
27 de febrero de 2025INNOVADOR.COM.MXclopTechnologyn/d
27 de febrero de 2025INTERFACTURA.COMclopTechnologyn/d
27 de febrero de 2025HOMEDEPOT.COM.MXclopConsumer Servicesn/d
10 de febrero de 2025BARCOMADE.COMclopn/dn/d
11 de enero de 2025EKOMERCIO.COMclopBusiness Servicesn/d
24 de marzo de 2023CAJASANRAFAEL.COM.MXclopFinancial Servicesn/d
22 de diciembre de 2022ORDEREXPRESS.COM.MXclopBusiness Servicesn/d