White Paper
THREAT PROFILE: Clop Ransomware
Clop is a ransomware-as-a-service (RaaS) group first identified in 2019 that has evolved from traditional ransomware operations into a data-focused extortion enterprise. While initially known for double-extortion attacks involving both file encryption and data theft, the group shifted its strategy around 2020 toward large-scale data extortion campaigns, often exploiting software vulnerabilities and supply chain weaknesses to steal sensitive information from multiple organizations simultaneously. Clop primarily targets manufacturing and industrial organizations, with many victims based in North America. The threat profile examines the group’s targeted industries, geographic reach, data leak operations, exploited vulnerabilities, known tools, and affiliations with other threat actors. It als
