R
Ransomwhere.org
Live MapLatest VictimsGroups
PaymentsTTPsIdentifyNewsDataAPI
LIVE
Ransomwhere.org

Real-time ransomware intelligence platform. Tracking threat actors, victims, and payments to raise awareness and help defend against ransomware attacks worldwide.

Platform

  • Live Map
  • Latest Victims
  • Groups
  • Payments
  • Identify
  • News

Resources

  • Data & Methodology
  • API Docs
  • NoMoreRansom
  • Ransomware.live
  • CISA Advisories

Data sourced from Ransomware.live API. For informational purposes only.

© 2026 Ransomwhere.org

Groups/clop

clop

Active

The ransomware group known as Cl0p is a variant of a previously known strain dubbed CryptoMix. It is worth noting that this variant was delivered as the final payload in a phishing campaign in 2019 and was exclusively financially motivated, with attacks carried out by the threat actors TA505.<br> <br> At that time, malicious actors sent phishing emails that led to a macro-enabled document that would drop a loader called 'Get2.' After gaining an initial foothold in the system or infrastructure, the actors began using reconnaissance, lateral movement, and exfiltration techniques to prepare for the deployment of the ransomware.<br> <br> After the execution of the ransomware, Cl0p appends the extension '.clop' to the end of files, or other types of extensions such as '.CIIp, .Cllp, and .C_L_O_P,' as well as different versions of the ransom note that were also observed after encryption. Depending on the variant, any of the ransom text files were created with names like 'ClopReadMe.txt, README_README.txt, Cl0pReadMe.txt, and READ_ME_!!!.TXT.'<br> <br> The Clop operation has shifted from delivering its final payload via phishing and has begun initiating attacks using vulnerabilities that resulted in the exploitation and infection of victims' infrastructures.<BR>Source: https://github.com/crocodyli/ThreatActors-TTPs

1251
Victims
3
Sites

Known Leak Sites

ekbgzchl6x2ias37.onionDLS
santat7kpllt6iyvqbr7q4amdv6dzrh6paatvyrzl7ry3zm72zigf4ad.onionDLS
toznnag5o3ambca56s2yacteu7q7x2avrfherzmz4nmujrjuib4iusad.onionDLS

Victims (1251)

Live
DAD.CO.TH
clopTH
THEMORTGAGEFIRM.COM
clopUS
FISHWINDOWCLEANING.COM
clopUS
SOLUTIONSINSAFETY.COM
clop
BOYDEN.COM
clopUS
CFDT.FR
clopFR
SPOHNASSOCIATES.COM
clopUS
GARNERGROUP.NET
clop
THEPERPETUAL.COM
clopUS
AIGBUSINESS.COM
clop
HYDEPARKUMC.ORG
clopUS
GIACARE.COM
clopUS
GIASPACE.COM
clopUS
ONESUPPORT.COM
clopUS
HUDSONSUSTAINABLE.COM
clopUS
GOKALLIT.COM
clop
CHEHARDY.COM
clopUS
RBDCONSTRUCTION.COM
clopUS
BROADREACHRETAIL.COM
clopUS
BE09.FR
clopFR
SMITHIPSERVICES.COM
clop
PROACTIVEMEDICAL.COM
clopUS
ITARCHITECHS.COM
clopUS
HUDSONEXECUTIVE.COM
clopUS
ANSTECHINC.COM
clopUS

Top Targeted Countries

Unknown530
United States423
Canada53
United Kingdom26
Australia24

Activity

Total victims1251
Countries affected54
Last seen