Clop ransomware booms in March as Fortra zero-day pays off for gang

Artur Marciniec – Fotolia

Backed by the threat actor tracked variously as Gold Tahoe and TA505, the Clop ransomware operation hit new ‘heights’ of activity last month, according to researchers

Alex Scroxton

By

Published: 06 Apr 2023 12:15

A total of 91 new victims were added to the Clop (aka Cl0p) ransomware leak site during March 2023, more than 65% of the total number of victims published between August 2020 and February 2023, as the threat group behind the ransomware, tracked by the Secureworks Counter Threat Unit (CTU) as Gold Tahoe embarked on a wide-ranging campaign of attacks.

The current surge in Clop activity is almost entirely down to the group’s successful exploitation of a zero-day vulnerability in the Fortra GoAnywhere managed file transfer (MFT) tool. Previous reports have claimed that the group has accessed and stolen data from 130 organisations via this method, which suggests that more are likely to be published. Currently known victims include energy sector giant Hitachi Energy, pharma giant Proctor & Gamble, security and storage firm Rubrik, and American department store Saks Fifth Avenue.

Many of the victims of the Fortra event are very high-profile organisations with revenues running into the billions, so despite ransom details being private, the CTU estimated that in many cases demands will run into the tens of millions.

However, Secureworks noted, the ransom demands may also be influenced by the perceived value of the data – in the Saks Fifth Avenue attack, for example, the supposed customer data the gang stole turned out to be mock customer data used to test internal systems, making it less likely the organisation will pay up.

Secureworks CTU intelligence director Mike McLellan said that unfortunately, wide-ranging supply chain attacks such as the Fortra incident are falling into a depressingly familiar pattern. “For an attacker, finding a vulnerability in popular third-party software can be like hitting the jackpot. Software often has privileged status to run on networks, it’s trusted. When that software is compromised, that system of trust is turned against customers.,” he said.

While different to the 3CX or Solarwinds [Sunburst] supply chain compromises, where attackers were able to compromise the software build process, the kind of indiscriminate exploitation activity that we’ve seen here can be just as damaging for individual organisations, if sensitive data is put at risk,” added McLellan.

Secureworks said that Gold Tahoe’s attacks had focused merely on data theft and extortion, and not encryption, which one would traditionally associate with a ransomware attack. Indeed, unlike previous Clop campaigns there is currently no evidence that any of the known Fortra incident victims have had their systems encrypted.

There is also something of a lack of clarity in regard to the value of the data that was stolen, with Gold Tahoe stating it only stole information stored on compromised GoAnywhere servers and claiming that it had the ability to move laterally and deploy ransomware, raising the question, why has it not done so?

McLellan said that Gold Tahoe may have decided not to actually deploy the Clop locker because it was trying to target as many victims as possible before Forta addressed the issue. Had it spent time identifying each victims’ ‘crown jewels’ it is possible it may have lost access to the wider victim base.

Who is Gold Tahoe?

Gold Tahoe is a longstanding, financially-motivated cyber criminal group that has been active in some form for over a decade. It has been known by many other names, perhaps most popularly Evil Corp – which it likely adopted itself in reference to the TV show Mr Robot – while threat researchers at Proofpoint know it as TA505, and other security organisations will have different designations.

The Russia-based operation was formerly an enthusiastic operator of the Dridex banking trojan and its predecessor Zeus, and many other malwares, and was one of the first groups to ramp up targeting of healthcare and pharmaceutical organisations at the onset of the Covid-19 pandemic.

Already notable in security circles having stolen over $100m in the course of its activity, the gang gained widespread public notoriety in 2019 when multiple members, including alleged leader Maksim Yakubets, and deputy Igor Turashev, were sanctioned by the US authorities.

Yakubets was notable for his lavish lifestyle, splurging the profits of the gang’s cyber attacks on an elaborate wedding, and a customised Lamborghini with vanity plates that spelled out the Russian word for thief. The deterioration of relations with Russia means that neither have ever faced justice.

However, it may not be the only actor involved in the current Clop campaign, claimed the Secureworks team. In one incident to which it responded last month, it found Clop being used by another actor, likely one it tracks as Gold Niagara (aka Carbon Spider or FIN7).

Gold Niagara historically targeted restaurants, retailers and hospitality organisations in order to access and steal money from their point-of-sale systems. However, there is some evidence that it pivoted to ransomware in 2021, with elements of the gang thought to be associated with the DarkSide operation.

Read more on Hackers and cybercrime prevention

Read More
Larisa Volkman

Latest

Brendan Sorsby’s football career may rightfully be put on ice after Browns appear uninterested

Bullet point summary by AI Brendan Sorsby's professional football career is in serious jeopardy after a major NFL team publicly distanced themselves from him. Cleveland Browns coach Todd Monken ruled out drafting the Texas Tech QB in the supplemental draft due to his college gambling violations. NFL teams are drawing a hard line on off-field

DeSean Jackson Calls Michael Vick’s Support a “Blessing” After Breakthrough HBCU Season

DeSean Jackson’s appointment as the head coach of the Delaware State Hornets caught college football unawares. But what was even more shocking was how he had a winning season with almost no coaching experience. As he talks about his mind-blowing debut season, Jackson mentions former teammate and current rival Michael Vick as a “blessing.” Watch

‘Don’t Think Anyone Wants To Be In Cleveland:’ Cam Heyward Reacts To Myles Garrett Trade

Cam Heyward’s never directly went up against Myles Garrett, which may be why he “could care less” that the former Cleveland Browns pass rusher is no longer in the division. On his Not Just Football podcast, Heyward reacted to the Browns trading Garrett to the Los Angeles Rams. “I think Aaron [Rodgers]’s definitely happy to

2027 NFL Draft Prospect Interview: Braedon Hellinger, LB, Aurora University

Meet Braedon Hellinger, a 2027 NFL Draft prospect. Discover his journey, passion for football, and personal insights. Name: Braedon Hellinger Position: LB College: Aurora University Height: 6’ 0” Weight: 215 lbs X: @23braedon23 Instagram: @2braedon2 What made you decide you wanted to be a football player? What made me decide to be a football player

Newsletter

Don't miss

Brendan Sorsby’s football career may rightfully be put on ice after Browns appear uninterested

Bullet point summary by AI Brendan Sorsby's professional football career is in serious jeopardy after a major NFL team publicly distanced themselves from him. Cleveland Browns coach Todd Monken ruled out drafting the Texas Tech QB in the supplemental draft due to his college gambling violations. NFL teams are drawing a hard line on off-field

DeSean Jackson Calls Michael Vick’s Support a “Blessing” After Breakthrough HBCU Season

DeSean Jackson’s appointment as the head coach of the Delaware State Hornets caught college football unawares. But what was even more shocking was how he had a winning season with almost no coaching experience. As he talks about his mind-blowing debut season, Jackson mentions former teammate and current rival Michael Vick as a “blessing.” Watch

‘Don’t Think Anyone Wants To Be In Cleveland:’ Cam Heyward Reacts To Myles Garrett Trade

Cam Heyward’s never directly went up against Myles Garrett, which may be why he “could care less” that the former Cleveland Browns pass rusher is no longer in the division. On his Not Just Football podcast, Heyward reacted to the Browns trading Garrett to the Los Angeles Rams. “I think Aaron [Rodgers]’s definitely happy to

2027 NFL Draft Prospect Interview: Braedon Hellinger, LB, Aurora University

Meet Braedon Hellinger, a 2027 NFL Draft prospect. Discover his journey, passion for football, and personal insights. Name: Braedon Hellinger Position: LB College: Aurora University Height: 6’ 0” Weight: 215 lbs X: @23braedon23 Instagram: @2braedon2 What made you decide you wanted to be a football player? What made me decide to be a football player

Badgers Beat Blue Bloods to Land Intriguing CB Prospect from California

Wisconsin football's first official visit weekend is the gift that keeps on giving. Just two days after the Badgers secured commitments from four-star wideout Jai Jones and three-star linebacker Nathan Jones, another high-priority target has pledged to Wisconsin after its first big recruiting weekend of the summer. Three-star cornerback Royalton Allen from Hesperia, California became

Jury acquits 2 business executives of bribing Navy admiral for government contract

A federal jury has acquitted two business executives of charges that they conspired to bribe a retired four-star U.S. Navy admiral, who is now serving a six-year prison sentence for his conviction on corruption charges By MICHAEL KUNZELMAN Associated Press WASHINGTON -- A federal jury has acquitted two business executives of charges that they conspired

US Business Leaders Optimistic About China Cooperation, Emphasize Importance of Chinese Market

© 2026 China Money Network. All Rights Reserved. Disclaimer: The views, opinions, forecasts, and statements made by our hosts and guests are the personal views of those respective individuals and may or may not be either endorsed or accepted by China Money Network Limited or the companies with which these individuals are employed.

Tesla’s Business Has Become Much More Diversified in Just the Past Five Years. Does That Make Its Stock a Better Buy Today?

Key Points Tesla's energy generation and storage segment generated 27% revenue growth last year. The company's non-automotive segments were able to help offset a double-digit decline in auto revenue in 2025. These 10 stocks could mint the next wave of millionaires › Tesla (NASDAQ: TSLA) is known for its electric vehicles (EVs), and while they