← Threat Actors & APT Groups

CL0P

Every article that identifies CL0P as responsible for or connected to reported activity.

RansomwareCybereason Blog·10 months ago

Addressing CL0P Extortion Campaign Targeting Oracle EBS CVE-2025-61882

The CL0P ransomware group has conducted a widespread extortion campaign targeting on-premises Oracle E-Business Suite deployments, exploiting CVE-2025-61882—a critical, unauthenticated remote code execution vulnerability—to gain unauthorized access and exfiltrate data between July and September 2025. Beginning in late September through early October, CL0P launched coordinated email extortion threats against affected organizations, with evidence suggesting threat actor activity dating back to at least August 9, 2025, and the group providing proof of stolen data to some targets during ongoing investigations.