Cl0p Is Back, Exploiting Supply Chains Again. by Lucie Cardiet
ID: a8f8a4e2-6321-5d10-8279-2e3cf2a3d53b
STIX ID: report--a8f8a4e2-6321-5d10-8279-2e3cf2a3d53b
Feed Name: Vectra AI Blog
- This report chronicles the resurgence and evolution of the Cl0p ransomware group from 2019–2025, documenting multiple large-scale supply-chain and MFT exploit campaigns (Accellion, SolarWinds Serv-U, GoAnywhere, MOVEit, Cleo, Oracle EBS), widespread data theft and extortion (CISA-estimated ~3,000 U.S. and ~8,000 global MOVEit victims), a shift toward encryption-less data-only extortion, observed TTPs (web shells, encrypted exfiltration, credential misuse), and practical detection and mitigation recommendations for defenders.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
