Cl0p Til you Drop - 6 Years, 10 Campaigns, 8 Zero-Days

PART I

Operational Profile and Campaign Analysis

1. The MFT Targeting Pattern

Cl0p’s defining operational characteristic is a sustained and systematic focus on managed file transfer infrastructure. Across nine known campaigns, the group has targeted Accellion FTA, SolarWinds Serv-U, Fortra GoAnywhere MFT, PaperCut MF/NG, Progress MOVEit Transfer, SysAid ITSM, Cleo MFT (Harmony, VLTrader, LexiCom), Oracle E-Business Suite, and Gladinet Centrestack/TrioFox. With the partial exception of PaperCut (a print management server) and SysAid (an IT service management platform), every target shares a common architectural profile: an internet-facing application that processes, stores, or transfers files.

This targeting consistency is significant for two reasons. First, it indicates strategic specialization rather than opportunistic exploitation. The group has invested in developing or acquiring zero-day capabilities specifically for this product category, deploying novel exploits in seven of nine campaigns. Second, it defines a bounded, defensible attack surface. Organizations that operate MFT infrastructure can identify themselves as potential targets and implement category-specific protections — a defensive advantage that is uncommon against most ransomware groups.

Figure 1: Complete Cl0p campaign history, 2020–2025

2. Exploitation Timeline

The chronological record of Cl0p campaigns reveals a distinctive operational tempo characterized by extended dormancy periods punctuated by concentrated bursts of activity.

Figure 2: Campaign timeline with inter-campaign intervals

Several patterns merit attention. The group’s longest dormancy period — approximately 14 months between the SolarWinds Serv-U exploitation in late 2021 and the Fortra GoAnywhere campaign in January 2023 — was followed by its most active phase: four distinct campaigns across four separate technologies in ten months (January through October 2023). This burst-and-pause cadence suggests a development cycle in which the group acquires or develops exploits, executes campaigns in rapid succession, and then withdraws to prepare for the next cycle.

The inter-campaign intervals since 2023 have been notably consistent, ranging from 10 to 14 months between major operations. This periodicity, while not perfectly predictable, provides a rough forecasting baseline. As of mid-2026, the group’s last confirmed campaign (Centrestack, November 2025) was approximately eight months ago — suggesting the next operational cycle may be approaching.

3. Seasonal Clustering: The Q4 Pattern

Figure 3: Cl0p campaigns by quarter — Q4 exceeds all other quarters combined

When campaigns are mapped by calendar quarter, Q4 emerges as the dominant operational window. Five of nine confirmed campaigns were initiated during October through December — more than all other quarters combined. This clustering is operationally rational: Q4 coincides with major holidays in the United States and Europe (Thanksgiving, Christmas, New Year), periods when security operations centers are typically operating at reduced capacity and organizational response times are extended.

The Centrestack campaign provides the most explicit example. Initial compromises occurred on Thanksgiving Day 2025 (November 27), a date that maximized the gap between initial access and organizational detection. This seasonal preference should be treated as a high-confidence behavioral indicator for defensive planning purposes.

4. Pre-Attack Reconnaissance

One of the most strategically significant findings in this analysis is the extent to which Cl0p conducts advance reconnaissance against eventual targets. This behavior has been confirmed in at least two campaigns and is assessed as likely present but undetected in others.

4.1 MOVEit: Two Years of Pre-Attack Scanning

Following the MOVEit exploitation in May 2023, Kroll published research documenting reconnaissance activity against MOVEit infrastructure extending back approximately two years. IP address 45.129.137[.]232 conducted automated probing of MOVEit API endpoints in July 2021. A second IP, 92.118.36[.]233, performed similar scanning in April 2022. Both addresses were subsequently linked to active Cl0p operations.

Critically, the 45.129 address was simultaneously involved in the SolarWinds Serv-U campaign in 2021. This indicates that Cl0p was conducting offensive operations against one target while actively preparing for its next campaign — using overlapping infrastructure for both activities. The 92.118 subnet exhibited similar dual-use: it participated in the Fortra GoAnywhere attacks in February 2023, but had been conducting MOVEit reconnaissance ten months earlier.

Implication: Had defenders retroactively searched for Cl0p indicators from the GoAnywhere campaign (February 2023) in their MFT access logs, they could have identified MOVEit scanning activity from April 2022 — three months before the actual exploitation.

4.2 Oracle EBS: Recon-to-Extortion Timeline

The Oracle E-Business Suite campaign followed a similar pattern. In July 2025, Mandiant reported suspicious traffic targeting Oracle EBS from IP 200.107.207[.]26. Oracle released patches on July 15. Post-patch, exploit attempts were observed from a different IP (161.97.99[.]49). In August, the original 200.107 address returned with successful exploitation. Victim organizations reportedly did not detect the compromise until extortion emails arrived on September 29 from domains pubstorm.com and pubstorm.net.

This sequence — probing, dormancy through patch release, exploitation from alternate infrastructure, and delayed victim notification via extortion email — represents a mature operational workflow. The gap between successful exploitation (August) and victim awareness (late September) underscores the detection deficit that many organizations face with edge-device compromises.

5. Infrastructure Analysis

To quantify Cl0p’s infrastructure practices, all publicly reported indicators of compromise were mapped to their associated Autonomous System Numbers (ASNs) and correlated across campaigns. The resulting dataset encompasses 79 unique ASNs across nine campaigns.

5.1 Hosting Provider Preferences

Hostzealot, a Bulgarian-based hosting provider operating under multiple ASN names by country (e.g., HZ-US, HZ-BG), is the most frequently observed provider across Cl0p campaigns. It has been associated with infrastructure in the Accellion, GoAnywhere, MOVEit, and Cleo MFT campaigns — four of nine total. Hosting providers reused across three or more campaigns include Colocrossing, Datacampus, Datahome, DigitalOcean, Ghostnet (Ghost), and OVH. Some of these — DigitalOcean and OVH in particular — are large, widely used providers whose presence is partially attributable to their market prevalence. Others, such as Datacampus and Datahome, are more distinctive signals.

5.2 Diversification Assessment

The central finding of the infrastructure analysis is that Cl0p demonstrates a high degree of operational security through infrastructure diversification. Approximately two-thirds (53 of 79) of observed ASNs were used in only a single campaign. This means that IOC-based detection anchored exclusively to historical infrastructure will fail to detect the majority of new campaign activity.

However, the one-third reuse rate (26 of 79 ASNs) remains a non-trivial detection surface, particularly when combined with behavioral and temporal signals. A rolling blocklist of ASNs observed in Cl0p operations within the preceding 180 days represents a pragmatic, data-backed defensive layer — imperfect but meaningful.

5.3 OFAC Sanctions Intersection

The ASN associated with certain reconnaissance infrastructure (AS215929, Data Campus) is numerically proximate to AS215829, registered to Smart Digital Ideas DOO. This entity was identified as part of the AEZA hosting group and designated by the U.S. Treasury’s Office of Foreign Assets Control (OFAC) in November 2025. The intersection of Cl0p operational infrastructure with OFAC-sanctioned entities introduces compliance considerations for organizations engaged in incident response, ransom negotiation, or infrastructure procurement involving these networks.

6. Behavioral Profile: Operational Discipline

Cl0p’s operational behavior diverges markedly from the broader ransomware ecosystem. The group maintains no known public communication channels, does not engage in forum-based self-promotion, and has not been observed participating in inter-group disputes. When the Scattered Spider collective publicly disparaged Cl0p via Telegram, the group offered no response and continued operations without deviation.

This restraint extends to campaign tempo. Cl0p routinely maintains dormancy periods of 10 to 14 months between campaigns — a level of operational patience that is exceedingly rare among financially motivated threat actors. The combination of zero-day capability, targeting discipline, infrastructure diversification, and communication restraint produces an adversary profile that more closely resembles a state-sponsored operation than a conventional cybercriminal enterprise, though all available evidence indicates financially motivated operations.

PART II

Defensive Analysis and Countermeasures

7. Architectural Vulnerability Analysis

The persistent success of Cl0p’s campaigns is enabled by a recurring architectural flaw common to most managed file transfer deployments: the internet-facing web application component coexists with encryption key material and file storage within a single trust boundary. When the web application is compromised — regardless of the specific exploit used — the attacker inherits the application’s own ability to decrypt stored data.

The MOVEit compromise illustrates this clearly. The attack chain progressed from SQL injection to web shell deployment (LEMURLOOT), after which the web shell invoked MOVEit’s native GetBaseKeyProvider() function to decrypt files using the application’s own key management. AES-256 encryption at rest, the primary data protection control, was functionally irrelevant because the encryption and decryption capability resided on the same component that was compromised. This control protects against physical disk theft — a threat model that bears no relationship to Cl0p’s operations.

This is not a vulnerability in any single product. It is a design pattern replicated across the MFT product category. Cl0p has exploited it using SQL injection, deserialization attacks, configuration file access, and other techniques. The exploit varies; the architectural weakness does not.

8. WAF Default-Deny: Application-Layer Access Control

Organizations routinely implement default-deny at the network layer by closing all ports except those explicitly required. The same principle can and should be applied at the HTTP layer for high-risk MFT devices.

A typical managed file transfer application exposes approximately 15 legitimate URI paths. External users require access to the login page. Partner organizations may need specific API endpoints for file transfers, and these can be restricted to known IP ranges. All remaining paths — including those historically exploited by Cl0p — can be blocked at the web application firewall.

Applied to MOVEit CVE-2023-34362: the SQL injection targeted /moveitisapi/moveitisapi.dll — blocked at WAF. The LEMURLOOT web shell was planted as /human2.aspx — unreachable. All reconnaissance probes would generate 403 responses, producing a high-fidelity detection signal.

This approach yields a dual benefit. Offensively, it renders current and future zero-day exploits ineffective unless they target one of the small number of allowlisted paths. Defensively, every blocked request to a non-allowlisted path becomes a high-confidence indicator of reconnaissance or exploitation activity — a detection signal that is largely absent from default WAF configurations.

9. Operational Playbook: Immediate Priorities

The following actions are designed for immediate implementation and do not require architectural redesign.

9.1 Asset Identification

Enumerate all internet-facing managed file transfer applications across the organization, including both formally provisioned services and shadow IT. Organizations of 1,500 employees or more should assume at least one undocumented file transfer service exists within their environment. Discovery should encompass both SaaS and on-premises deployments.

9.2 Log Retention Verification

Confirm that access logs for all identified MFT assets are retained for a minimum of 12 months, with 24 months preferred. Given Cl0p’s demonstrated willingness to conduct reconnaissance up to two years in advance of exploitation, short retention windows (days or weeks) eliminate the possibility of effective retro-hunting.

9.3 Traffic Baselining

Establish baseline URI access patterns for each MFT device to enable anomaly detection. Define what constitutes normal inbound URI patterns so that novel or non-standard paths — potential indicators of vulnerability scanning — generate alerts. Additionally, baseline outbound data transfer volumes at the device level. Determine normal hourly and daily transfer volumes and configure alerts for anomalous egress, particularly during Q4.

9.4 Watchlist Updates

Incorporate known Cl0p-associated ASNs into network monitoring and blocking rules on a rolling 180-day basis. While two-thirds of the group’s infrastructure is single-use, the one-third reuse rate justifies ongoing monitoring of previously observed hosting providers and autonomous systems.

10. The Zero-Day Protocol: Retro-Hunt First

When the next MFT zero-day is disclosed, do not limit the response to patching. The first action after patch deployment should be retroactive log analysis for evidence of pre-exploitation reconnaissance.

Cl0p has demonstrated a consistent pattern of scanning target infrastructure weeks to years before deploying exploits. A newly disclosed MFT vulnerability should trigger immediate retro-hunting for anomalous URI patterns targeting the affected application, traffic from ASNs historically associated with Cl0p operations, and probe attempts from IPs appearing in Cl0p campaigns within the preceding 180 days. Log review should extend as far back as retention allows. Patching addresses the vulnerability. Retro-hunting determines whether the vulnerability was already exploited.

11. Case Study: Gladinet Centrestack (November–December 2025)

The most recent confirmed Cl0p campaign provides a real-time illustration of the operational patterns documented in this report.

11.1 Initial Detection

On December 18, 2025, the Curated Intelligence community published an advisory via LinkedIn reporting active Cl0p targeting of Centrestack file servers. Team Cymru’s review of global traffic data corroborated this reporting: a significant surge in scanning activity targeting Centrestack devices was observed beginning November 27, 2025 — Thanksgiving Day in the United States.

11.2 Exploitation Sequence

Huntress subsequently published analysis confirming that initial compromises occurred on November 27. The exploitation targeted the web.config file, with attack traffic originating from IP address 147.124[.]x.x. Huntress’s log analysis documented a progression from failed exploitation attempts to a successful compromise, indicating iterative refinement by the attacker. Gladinet released a critical security update on Saturday, November 29 — two days after the initial compromises.

11.3 Post-Exploitation Infrastructure

In early January 2026, one of the attacker IPs was observed hosting a Centrestack instance for approximately three days. The most plausible explanation is exploit development or testing — standing up a target application to refine attack techniques. This behavior is consistent with the group’s demonstrated pattern of methodical preparation.

12. Conclusions and Strategic Recommendations

Cl0p has provided the defender community with an unusually rich operational dataset. Over six years, the group has demonstrated consistent targeting preferences, predictable seasonal patterns, identifiable infrastructure reuse, and a recurring exploitation of the same fundamental architectural weakness. This consistency represents a strategic advantage for defenders — provided the intelligence is operationalized.

Strategic Priorities

Elevate MFT security to a distinct program. Managed file transfer devices warrant dedicated security controls, monitoring, and incident response procedures separate from general endpoint or server security programs. Any critical vulnerability disclosed in an MFT product should trigger zero-day protocol response regardless of whether Cl0p attribution is established.

Implement seasonal heightened monitoring. Q4 should be treated as a high-risk period for MFT infrastructure. Organizations should consider tightening outbound data transfer thresholds, increasing log review frequency, and staffing security operations accordingly during October through January.

Deploy WAF allowlisting on MFT devices. Default-deny at the HTTP layer for file transfer applications is the single highest-impact defensive measure available. It mitigates current exploits, reduces the effectiveness of future zero-days, and generates high-fidelity detection signals.

Institutionalize retro-hunting. Every new MFT vulnerability disclosure should trigger retroactive log analysis extending as far back as retention allows. The cost of retro-hunting is low; the cost of missing a pre-existing compromise is not.

Address the architectural root cause. Long-term risk reduction requires separating internet-facing web components from decryption key material and file storage. Until this separation is achieved, encryption-at-rest controls on MFT devices provide a false sense of security against application-layer attacks.

Cl0p operates with the discipline of a business, executing a visible and repeatable playbook over a multi-year time horizon. The corollary is that a visible, repeatable playbook is also a defendable one — if the intelligence it provides is translated into operational controls.

Interactive infrastructure visualization: eliwoodward.github.io/clop-campaigns

This report is based on research presented at FIRSTCON Denver 2026.