Cyber overview
Cyber threat actor

Cl0p

Russian-speaking extortion enterprise · active since 2019

Extortion group specializing in mass exploitation of managed file-transfer products, including the MOVEit campaign that affected hundreds of US companies and government agencies at once.

Aliases
Lace TempestTA505FIN11
Primary targets
Managed file-transfer users Federal and state agencies Financial services Education

MITRE ATT&CK techniques

0 techniques mapped · click any technique ID to open the MITRE ATT&CK entry, any CVE to view its NVD record, or any citation for source reporting.

No MITRE ATT&CK mapping available yet for Cl0p.
Live feed mentions
  1. Tue, 21 Oct 2025 14:00:00 GMT · SecurityWeek
    SecurityWeek: Oracle E-Business Suite flaw exploited across dozens of customer environments
  2. Thu, 09 Oct 2025 13:00:00 GMT · Google Threat Intelligence Group / Mandiant
    Google Threat Intelligence Group and Mandiant document Oracle E-Business Suite zero-day extortion