ctipilot.ch

Cl0p

actor · actor:clop

Financially motivated data-theft extortion group with a multi-year pattern of exploiting a zero-day in a widely deployed enterprise application, exfiltrating at scale, and only then running a mass extortion wave — previously against Accellion FTA, GoAnywhere MFT, MOVEit Transfer, Cleo and Oracle E-Business Suite. Ransom-ISAC, eCrime.ch and DEFUSED attribute the 2026-07 PTC Windchill / FlexPLM extortion campaign to Cl0p affiliate activity; ReliaQuest, quoted by BleepingComputer on 2026-07-24, holds the actor unconfirmed and rests on tradecraft overlap with prior Cl0p campaigns.

Aliases: Clop, Graceful Spider, Chubby Scorpius, FIN11, Lace Tempest

Coverage timeline
7
first 2026-05-04 → last 2026-07-27
Peak priority
high
3 high · 4 notable
Sources cited
29
25 hosts
Sections touched
5
active-threats, trending-vulnerabilities, updates
Co-occurring entities
8
see Related entities below
ATT&CK techniques
9
pinned v19.1 · see below
2026-05-047 appearances2026-07-27

ATT&CK techniques

9 techniques observed across 5 entries — derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.1 · compare on the matrix · Navigator layer (JSON)

Resource Development TA0042

T1586.002Compromise Accounts: Email Accounts×1

Adversaries may compromise email accounts that can be used during targeting. Adversaries can use compromised email accounts to further their operations, such as leveraging them to conduct Phishing for Information, Phishing, or large-scale spam email campaigns. Utilizing an existing persona with a compromised email account may engender a level of trust in a potential victim if they have a relationship with, or knowledge of, the compromised persona. Compromised email accounts can also be used in the acquisition of infrastructure (ex: Domains).

Evidence: 2026-07-27/clop-windchill-flexplm-mass-extortion-wave-cve-2026-12569 · ATT&CK page ↗

Initial Access TA0001

T1190Exploit Public-Facing Application×3

Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.

Evidence: 2026-07-27/clop-windchill-flexplm-mass-extortion-wave-cve-2026-12569 · 2026-07-14/progress-sharefile-szc-active-exploitation-confirmed · 2026-07-11/moveit-transfer-certfr-cve-2026-10699-10698-11903 · ATT&CK page ↗

Execution TA0002

T1059.007Command and Scripting Interpreter: JavaScript×1

Adversaries may abuse various implementations of JavaScript for execution. JavaScript (JS) is a platform-independent scripting language (compiled just-in-time at runtime) commonly associated with scripts in webpages, though JS can be executed in runtime environments outside the browser.

Evidence: 2026-07-11/moveit-transfer-certfr-cve-2026-10699-10698-11903 · ATT&CK page ↗

Persistence TA0003

T1505.003Server Software Component: Web Shell×1

Adversaries may backdoor web servers with web shells to establish persistent access to systems. A Web shell is a Web script that is placed on an openly accessible Web server to allow an adversary to access the Web server as a gateway into a network. A Web shell may provide a set of functions to execute or a command-line interface on the system that hosts the Web server.

Evidence: 2026-07-27/clop-windchill-flexplm-mass-extortion-wave-cve-2026-12569 · ATT&CK page ↗

Privilege Escalation TA0004

T1068Exploitation for Privilege Escalation×2

Adversaries may exploit software vulnerabilities in an attempt to elevate privileges. Exploitation of a software vulnerability occurs when an adversary takes advantage of a programming error in a program, service, or within the operating system software or kernel itself to execute adversary-controlled code. Security constructs such as permission levels will often hinder access to information and use of certain techniques, so adversaries will likely need to perform privilege escalation to include use of software exploitation to circumvent those restrictions.

Evidence: 2026-07-23/solarwinds-serv-u-2026-3-critical-idor-priv-esc-root · 2026-05-12/ico-fines-south-staffordshire-water-963-900-water-sector-oes · ATT&CK page ↗

Discovery TA0007

T1083File and Directory Discovery×1

Adversaries may enumerate files and directories or may search in specific locations of a host or network share for certain information within a file system. Adversaries may use the information from File and Directory Discovery during automated discovery to shape follow-on behaviors, including whether or not the adversary fully infects the target and/or attempts specific actions.

Evidence: 2026-07-27/clop-windchill-flexplm-mass-extortion-wave-cve-2026-12569 · ATT&CK page ↗

Collection TA0009

T1074Data Staged×1

Adversaries may stage collected data in a central location or directory prior to Exfiltration. Data may be kept in separate files or combined into one file through techniques such as Archive Collected Data. Interactive command shells may be used, and common functionality within cmd and bash may be used to copy data into a staging location.

Evidence: 2026-07-27/clop-windchill-flexplm-mass-extortion-wave-cve-2026-12569 · ATT&CK page ↗

Impact TA0040

T1499.004Endpoint Denial of Service: Application or System Exploitation×1

Adversaries may exploit software vulnerabilities that can cause an application or system to crash and deny availability to users. Some systems may automatically restart critical applications and services when crashes occur, but they can likely be re-exploited to cause a persistent denial of service (DoS) condition.

Evidence: 2026-07-11/moveit-transfer-certfr-cve-2026-10699-10698-11903 · ATT&CK page ↗

T1657Financial Theft×1

Adversaries may steal monetary resources from targets through extortion, social engineering, technical theft, or other methods aimed at their own financial gain at the expense of the availability of these resources for victims. Financial theft is the ultimate objective of several popular campaign types including extortion by ransomware, business email compromise (BEC) and fraud, "pig butchering," bank hacking, and exploiting cryptocurrency networks.

Evidence: 2026-07-27/clop-windchill-flexplm-mass-extortion-wave-cve-2026-12569 · ATT&CK page ↗

Story timeline

  1. 2026-07-27Cl0p-affiliated actors move the PTC Windchill / FlexPLM intrusions (CVE-2026-12569) into a mass extortion-email phase, with no victims named yet
    updatesWindchill exploitation turns to extortion: staff-wide emails name the PLM breach vector, victim listings still pending
  2. 2026-07-23SolarWinds Serv-U 2026.3 — 15 critical IDOR flaws let authenticated users escalate to root RCE on the file-transfer server (CVSS 9.1)
    trending-vulnerabilitiesSolarWinds patches 15 critical IDOR-to-root flaws in the internet-facing Serv-U managed-file-transfer server
  3. 2026-07-14Progress ShareFile Storage Zone Controller — Shadowserver confirms active exploitation of CVE-2026-2699; exposed instances collapse ~30,000 to ~1,000
    updatesHoneypots record in-the-wild exploitation of the ShareFile Storage Zone Controller auth bypass the same day Progress ordered shutdowns
  4. 2026-07-11Progress MOVEit Transfer: pre-auth SFTP DoS (CVE-2026-10699), admin table-scope bypass (CVE-2026-10698) and stored XSS (CVE-2026-11903), patched 2026.0.2
    trending-vulnerabilitiesCERT-FR flags three new MOVEit Transfer CVEs — a pre-auth SFTP memory-leak DoS is reachable on any exposed instance (no exploitation yet)
  5. 2026-05-12ICO fines South Staffordshire Water £963,900 — water-sector OES with partial SIEM coverage; Cl0p attribution and ZeroLogon kill-chain detail sourced to The Record
    active-threatsICO fines South Staffordshire Water £963,900 — water-sector OES with partial SIEM coverage; Cl0p attribution and ZeroLogon kill-chain detail sourced to The
  6. 2026-05-11South Staffordshire Water — ICO £963,900 fine
    weekly-incidents-recap
  7. 2026-05-04Looking ahead — 2026-W19
    weekly-looking-ahead

Relationships explore in graph

Typed, source-stated connections from the entity registry — each edge cites the entry whose reporting establishes it.

attributed activity

Where this entity is cited

  • trending-vulnerabilities2
  • updates2
  • weekly-looking-ahead1
  • weekly-incidents-recap1
  • active-threats1

Source distribution

  • cve.threatint.eu3 (10%)
  • security-hub.ncsc.admin.ch2 (7%)
  • theregister.com2 (7%)
  • attack.mitre.org1 (3%)
  • bankinfosecurity.com1 (3%)
  • bishopfox.com1 (3%)
  • bleepingcomputer.com1 (3%)
  • cert.ssi.gouv.fr1 (3%)
  • other17 (59%)

Co-occurring entities

Derived — referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.

All cited sources (29)

Entries about Cl0p (7)

2026-07-27 · view entry permalink →

HIGHCVE-2026-12569exploitedupdateNATOB2

Cl0p-affiliated actors move the PTC Windchill / FlexPLM intrusions (CVE-2026-12569) into a mass extortion-email phase, with no victims named yet

UPDATE · originally covered PTC Windchill CVE-2026-12569 now confirmed exploited in the wild with JSP web shells (2026-06-27)

The PTC Windchill / FlexPLM deserialization RCE this pipeline covered when CISA confirmed exploitation has moved from quiet data theft into open extortion. From 20 July a joint advisory by Ransom-ISAC, eCrime.ch and DEFUSED records that it "began observing an alleged Cl0p ransomware (aka Graceful Spider, Chubby Scorpius, FIN11, Lace Tempest) data extortion campaign sending emails with a subject line, “Windchill PDMLink module serious data leak” to an unknown number of affected organizations" (Ransom-ISAC / eCrime.ch / DEFUSED, 2026-07-22). The delivery pattern is the operationally useful part: the messages are sent from randomly compromised accounts and go to hundreds of recipients inside the victim organisation at once, carrying the attacker's current contact addresses — an approach the same advisory notes is consistent with the Oracle E-Business Suite campaign of last year apart from the new addresses (same advisory).

Two facts bound the response window. First, no victim has been named: "As of 22 July, Cl0p ransomware has not begun listing victims of this latest campaign on their dark web data leak site or has publicly claimed credit for this latest campaign" (same advisory), so an affected organisation's first and possibly only warning is the staff-wide email, not a leak-site entry. Second, attribution is unsettled and the two reporting streams disagree in a way worth carrying: the joint advisory treats this as Cl0p affiliate activity, while ReliaQuest, quoted by BleepingComputer, states that "The actor behind these attacks remains unconfirmed. however, the observed tradecraft shares characteristics with previous Cl0p campaigns targeting enterprise applications and high-value data repositories" (BleepingComputer, 2026-07-24). The underlying access route is unchanged from the June coverage — a pre-authentication information disclosure in the FlexPLM WSDL endpoint chained with the Windchill login-servlet flaw, followed by JSP web shells and staged data theft (Ransom-ISAC / eCrime.ch / DEFUSED, 2026-07-22).

One correction to how this pipeline previously framed remediation, because it changes who is still exposed: there is no version floor above which an installation is safe. PTC ships a patch per version, and its own change log records the older Windchill lines being patched between 18 and 19 June — 13.0.2 on 18 June, and 11.0 M030 alongside 13.1.1 on 19 June — while the SUPs for 13.1.2 and 13.1.3, and the first release naming FlexPLM as well as Windchill, only arrived on 14 July 2026 (PTC, 2026-07-14). 11.0 M030 appears in that patch list as a version that receives a fix, not as a boundary below which systems are safe, and there is no lower bound at all: NVD states the flaw "also impacts Windchill and FlexPLM releases prior to 11.0 M030", and above that it enumerates discrete affected releases rather than a continuous range, topping out at Windchill 13.1.3 and FlexPLM 13.0.3. The practical consequence is narrower than a version number suggests but sharper for those it catches: an estate on 13.1.2 or 13.1.3 had no patch available between CISA's KEV confirmation on 25 June and the SUP release on 14 July, whereas a 13.1.1 estate could have patched from 19 June. Neither a high version number nor a version above 11.0 M030 is therefore evidence of remediation, and only the per-version list in PTC's eSupport article CS473270 answers the question.

Triage: the extortion email is itself a detectable event with a clean discriminator. A legitimate internal security notice originates from a known internal sender and the organisation's own mail infrastructure; this pattern is a large recipient set inside one organisation receiving mail from a compromised account with no prior relationship to it, referencing a specific internal application by name. Mail-flow telemetry showing that fan-out to a wide internal distribution list from a previously-unseen sender — rather than the message content — is the signal, and it should route to incident response rather than to the phishing-report queue.

On 20 July, Ransom-ISAC began observing an alleged Cl0p ransomware (aka Graceful Spider, Chubby Scorpius, FIN11, Lace Tempest) data extortion campaign sending emails with a subject line, “Windchill PDMLink module serious data leak” to an unknown number of affected organizations

As of 22 July, Cl0p ransomware has not begun listing victims of this latest campaign on their dark web data leak site or has publicly claimed credit for this latest campaign.

Ransom-ISAC / eCrime.ch / DEFUSED 2026-07-22

The actor behind these attacks remains unconfirmed. however, the observed tradecraft shares characteristics with previous Cl0p campaigns targeting enterprise applications and high-value data repositories.

BleepingComputer, quoting ReliaQuest
threat27 Jul 04:33Zmulti-sourceOpen finding ↗

2026-07-23 · view entry permalink →

NOTABLECVE-2026-28304 +15NATOA1

SolarWinds Serv-U 2026.3 — 15 critical IDOR flaws let authenticated users escalate to root RCE on the file-transfer server (CVSS 9.1)

Serv-U 2026.3, released 2026-07-21, fixes 16 vulnerabilities — 15 of them critical at CVSS 9.1 — that are insecure-direct-object-reference (IDOR, CWE-639) and broken-access-control flaws in the managed-file-transfer web console rather than memory-safety bugs (SolarWinds, 2026-07-21). The consequential path is authorization: an authenticated user — in several cases needing only group- or domain-administrator scope, not full system administrator — can escalate to system administrator and achieve remote code execution as root on the underlying host, with reduced impact on Windows deployments (SolarWinds PSIRT, 2026-07-21; NCSC Switzerland, 2026-07-22). Individual flaws cover privilege escalation via configuration-path modification, arbitrary system-administrator account creation, arbitrary file read/write, account takeover through IDOR, and domain-user-group elevation to an admin group; one medium issue (CVE-2026-28315, CVSS 6.2) is a stored XSS in the admin UI usable for session hijacking. All were reported through SolarWinds' Intigriti bug-bounty program and NCSC-CH records exploitation status as unknown; heise notes Serv-U's history as a target for the Cl0p affiliate in prior MOVEit-class campaigns purely as context for why file-transfer software patch-lag is a recurring high-value target class (heise online, 2026-07-22).

SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to privilege escalation and remote code execution as root.

SolarWinds 2026-07-21

Successful exploitation allows authenticated attackers to escalate privileges to system administrator and execute arbitrary code with root privileges via network access.

NCSC Switzerland 2026-07-22
vulnerability23 Jul 04:34Zmulti-sourceOpen finding ↗

2026-07-14 · view entry permalink →

HIGHCVE-2026-2699exploitedupdateNATOB1

Progress ShareFile Storage Zone Controller — Shadowserver confirms active exploitation of CVE-2026-2699; exposed instances collapse ~30,000 to ~1,000

UPDATE · originally covered Progress orders ShareFile Storage Zone Controller shutdown over a 'credible external threat' — day three, no patch or root cause disclosed (2026-07-13)

Two developments harden the picture around Progress's emergency ShareFile Storage Zone Controller (SZC) shutdown order. First, the shutdown was not precautionary in the abstract: the alert "arrived the same day that independent honeypots began detecting active, in-the-wild attempts to exploit" the pre-auth authentication-bypass flaw CVE-2026-2699, with Shadowserver Foundation honeypots first recording those attempts on Friday 2026-07-10 (BankInfoSecurity, 2026-07-13). This moves the flaw's status from PoC-public to actively exploited. Second, defenders responded at scale — the number of internet-exposed Storage Zone Controllers fell from watchTowr's April count of about 30,000 to roughly 1,000 by 2026-07-13, evidence of widespread emergency power-downs (BankInfoSecurity, 2026-07-13). Progress restored ShareFile cloud-service access for SZC customers but continues to require the on-prem controllers themselves stay powered off pending its investigation, and still reports no evidence of unauthorized access to customer data (The Register, 2026-07-13; Progress ShareFile status, 2026-07-13).

Recorded Future analyst Allan Liska publicly assessed that the pattern "smells like CL0P ransomware group activity," pointing to Clop's long record of mass-exploiting secure file-transfer software (Accellion FTA, GoAnywhere, MOVEit, Cleo Harmony, and Oracle E-Business Suite) (BankInfoSecurity, 2026-07-13). This is a named researcher's hypothesis, not an attribution: Progress has identified no actor and disclosed no root cause.

Defender takeaway. The one-day earlier guidance — treat any exposed SZC as untrusted and keep it powered off rather than patched — is now backed by confirmed in-the-wild exploitation, so it should carry more weight, not less, for any organisation that has not yet acted. Exposure concentrates in the US and Germany, keeping this directly relevant to European on-prem file-exchange operators. The recommended state remains a full power-off of on-prem Storage Zone Controllers until Progress publishes scope; the original entry's shutdown and bounded-compromise-check actions still stand unchanged.

The alert arrived the same day that independent honeypots began detecting active, in-the-wild attempts to exploit a critical authentication bypass vulnerability the vendor patched earlier this year in its ShareFile Storage Zone Controller software.

Honeypots run by nonprofit cybersecurity organization Shadowserver Foundation first recorded active, in-the-wild attacks attempting to exploit CVE-2026-2699 on Friday.

This smells like CL0P ransomware group activity. If you use ShareFile, be like C-3PO and 'shut them all down.'

BankInfoSecurity (ISMG) 2026-07-13
incident14 Jul 12:50Zmulti-sourceOpen finding ↗

Earlier coverage (4)

2026-07-11NOTABLENATOA2Progress MOVEit Transfer: pre-auth SFTP DoS (CVE-2026-10699), admin table-scope bypass (CVE-2026-10698) and stored XSS (CVE-2026-11903), patched 2026.0.2France's CERT-FR/ANSSI advisory CERTFR-2026-AVI-0856 (2026-07-10) covers three newly-patched flaws in Progress MOVEit Transfer, the managed file-transfer product with a history of mass exploitation (Cl0p, 2023): CVE-2026-10699 (CVSS 7.5) is an unauthenticated SFTP-service memory leak an attacker can drive to denial of service; CVE-2026-10698 (CVSS 7.2) lets an admin-level user bypass Custom Reports table-scope restrictions to read or manipulate data outside scope; CVE-2026-11903 (CVSS 8.0) is a low-privilege stored XSS in the Ad Hoc module. No exploitation or public PoC is reported. Fixed in 2026.0.2 (and the 2025.0.8 / 2025.1.4 branch releases); Swiss/EU public-sector and finance operators running internet-facing MOVEit should prioritise the upgrade given the product's exposure profile and exploitation history.2026-05-12HIGHICO fines South Staffordshire Water £963,900 — water-sector OES with partial SIEM coverage; Cl0p attribution and ZeroLogon kill-chain detail sourced to The RecordICO fines South Staffordshire Water £963,900 for the 2020–2022 Cl0p intrusion. Regulator-side findings call out inadequate vulnerability management, unpatched critical systems, obsolete unsupported software (Windows Server 2003) and partial SIEM coverage; 633,887 individuals' data was published on the dark web from a total holding of about 1.85 million customer records (ICO notice, 2026-05-11). Reporting by The Record adds the ZeroLogon / two-DC kill-chain detail2026-05-11NOTABLESouth Staffordshire Water — ICO £963,900 fineICO fines South Staffordshire Water £963,900 over the 2022 Cl0p ZeroLogon kill-chain intrusion (daily 2026-05-12). The water-sector OES finding with the partial SIEM coverage detail (5% host-inventory coverage) is the operational lesson for any utility / critical-infrastructure operator with patchy telemetry.2026-05-04NOTABLELooking ahead — 2026-W19Canvas / Instructure extortion deadline — Tuesday 2026-05-12 (two days out). Second-intrusion claim against Instructure made 2026-05-08 despite the May 8 patches; seven Dutch universities disconnected; Dutch DPA and ICO engaged.