Ransomware Group intelligence
Cl0p
ActiveTrack Cl0p with 25826 published victims, 3 known leak locations, 7 exploited vulnerabilities, and 31 mapped TTPs in a single intelligence view.
Overview
The ransomware group known as Cl0p is a variant of the previously tracked CryptoMix strain. Early Cl0p activity was linked to financially motivated operations attributed to TA505, including phishing campaigns observed in 2019.
Those campaigns commonly relied on macro-enabled documents that deployed the Get2 loader. Once initial access was established, operators moved into reconnaissance, lateral movement, and data exfiltration before deploying ransomware across the victim environment.
After execution, Cl0p variants have been observed appending extensions such as .clop, .CIIp, .Cllp, and .C_L_O_P. Associated ransom notes have included filenames like ClopReadMe.txt, README_README.txt, Cl0pReadMe.txt, and READ_ME_!!!.TXT.
The operation later shifted from phishing-led delivery to intrusion campaigns centered on exploiting vulnerabilities in internet-facing enterprise software and managed file transfer products.
Leak Status Distribution
No leak-status data available yet.
Top Countries
Interactive distribution based on the currently visible victims list.
Known Leak Locations (3)
| Label | Type | Availability | Links |
|---|---|---|---|
| Leak location 3 | Onion service | Down checked 3h ago | toznnag5o3ambca56s2yacteu7q7x2avrfherzmz4nmujrjuib4iusad.onion |
| Leak location 2 | Onion service | Down checked 3h ago | santat7kpllt6iyvqbr7q4amdv6dzrh6paatvyrzl7ry3zm72zigf4ad.onion |
| Leak location 1 | Onion service | Down checked 3h ago | ekbgzchl6x2ias37.onion |
Top Activity Sectors (5)
- Technology 146
- Transportation/Logistics 68
- Consumer Services 65
- Manufacturing 64
- Business Services 34
Typical Attacks (17)
▼How Cl0p typically operates, as attributed by MITRE ATT&CK v19.2. Attributed via Clop.
-
T1059.003 Windows Command Shell Execution
What they do: Clop can use cmd.exe to help execute commands on the system.
What that means: Adversaries may abuse the Windows command shell for execution.
-
T1106 Native API Execution
What they do: Clop has used built-in API functions such as WNetOpenEnumW(), WNetEnumResourceW(), WNetCloseEnum(), GetProcAddress(), and VirtualAlloc().
What that means: Adversaries may interact with the native OS application programming interface (API) to execute behaviors.
-
What they do: Clop can make modifications to Registry keys.
What that means: Adversaries may interact with the Windows Registry as part of a variety of other techniques to aid in defense evasion, persistence, and execution.
-
T1027.002 Software Packing Stealth
What they do: Clop has been packed to help avoid detection.
What that means: Adversaries may perform software packing or virtual machine software protection to conceal their code.
-
T1140 Deobfuscate/Decode Files or Information Stealth
What they do: Clop has used a simple XOR operation to decrypt strings.
What that means: Adversaries may use Obfuscated Files or Information to hide artifacts of an intrusion from analysis.
-
T1218.007 Msiexec Stealth
What they do: Clop can use msiexec.exe to disable security tools on the system.
What that means: Adversaries may abuse msiexec.exe to proxy execution of malicious payloads.
-
What they do: Clop has used the sleep command to avoid sandbox detection.
What that means: Adversaries may employ various time-based methods to detect virtualization and analysis environments, particularly those that attempt to manipulate time mechanisms to simulate longer elapses of time.
-
T1553.002 Code Signing Defense Impairment
What they do: Clop can use code signing to evade detection.
What that means: Adversaries may create, acquire, or steal code signing materials to sign their malware or tools.
-
T1685 Disable or Modify Tools Defense Impairment
What they do: Clop can uninstall or disable security products.
What that means: Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities.
-
T1057 Process Discovery Discovery
What they do: Clop can enumerate all processes on the victim's machine.
What that means: Adversaries may attempt to get information about running processes on a system.
-
T1083 File and Directory Discovery Discovery
What they do: Clop has searched folders and subfolders for files to encrypt.
What that means: Adversaries may enumerate files and directories or may search in specific locations of a host or network share for certain information within a file system.
-
T1135 Network Share Discovery Discovery
What they do: Clop can enumerate network shares.
What that means: Adversaries may look for folders and drives shared on remote systems as a means of identifying sources of information to gather as a precursor for Collection and to identify potential systems of interest for Lateral Movement.
-
T1518.001 Security Software Discovery Discovery
What they do: Clop can search for processes with antivirus and antimalware product names.
What that means: Adversaries may attempt to get a listing of security software, configurations, defensive tools, and sensors that are installed on a system or in a cloud environment.
-
T1614.001 System Language Discovery Discovery
What they do: Clop has checked the keyboard language using the GetKeyboardLayout() function to avoid installation on Russian-language or other Commonwealth of Independent States-language machines; it will also check the GetTextCharset function.
What that means: Adversaries may attempt to gather information about the system language of a victim in order to infer the geographical location of that host.
-
T1486 Data Encrypted for Impact Impact
What they do: Clop can encrypt files using AES, RSA, and RC4 and will add the ".clop" extension to encrypted files.
What that means: Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources.
-
T1489 Service Stop Impact
What they do: Clop can kill several processes and services related to backups and security solutions.
What that means: Adversaries may stop or disable services on a system to render those services unavailable to legitimate users.
-
T1490 Inhibit System Recovery Impact
What they do: Clop can delete the shadow volumes with vssadmin Delete Shadows /all /quiet and can use bcdedit to disable recovery options.
What that means: Adversaries may delete or remove built-in data and turn off services designed to aid in the recovery of a corrupted system to prevent recovery.
Tools Observed (3)
▼Software Cl0p has been seen using, grouped by what it is used for. Legitimate administration tools appear here because these actors routinely abuse them — presence in this list is not itself malicious.
Offensive security tooling
Tool data from Ransomware Tool Matrix by BushidoUK, licensed CC BY 4.0. Grouped by purpose and matched to this group by Breach House.
Ransom Notes (4)
▼The note this group leaves on a compromised machine. Click a filename to read it.
Details_Cleo.txt
Hello, [snip] !!!. We are CL0P^_ group. If you don't know us, search on google. Your company's data has been compromised through your cleo system. We own it now. To do this, you need to download the TOR browser https://www.torproject.org/download/ You can read about us here CL0P^_- LEAKS http://santat7kpllt6iyvqbr7q4amdv6dzrh6paatvyrzl7ry3zm72zigf4ad.onion Using a vulnerability in platform systems Cleo Harmony, VLTrader and LexiCom we gained access to your networks and downloaded all the information from your servers. We do not want to make this public or spread your confidential information, we are only interested in money. We are not interested in political speak just money and money will bring this to finish. Unique link to chat generated for your company: http://htmxyptur5wfjrd7uvg23snupub2pbtlfelk45n37b3augl2w4eearid.onion/remote0/[snip] Do not forget to use TOR browser We soon show you the files we have and amount. If you pay, data is deleted, we disappear and you never need worry on this again. If you don't pay, you data will publish on our blog. How much to pay? % of you revenues and how much data we take. Speak on chat. Fast reply will receive discount. I. Payment - Bitcoin wallet is provided when you validate the ready to pay; II. Participation of third-parties II.I Not allowed III. What Guarantee - All data deleted with high secure tools and video provided - All publishing stop and cancel - Any backdoor disclose - Never attack you again - All discussion delete Do you have our data? - Yes. Ask for list of data and samples How much time to speak to you? - 10 days I need discount? - Come with offer. Low ball increase price. Quick answer deserve some discount. Discuss on chat. What cryptocurrency? - We take Bitcoin and Monero. Speed of discuss? - Do not stay silent and speak quick min one time a day. Contact us via email or chat URL here: [email protected] [email protected] [email protected] © CL0P^_- LEAKS 2020 - 2024
clop1.txt
Your network has been penetrated. All files on each host in the network have been encrypted with a strong algorithm. Backups were either encrypted or deleted or backup disks were formatted. Shadow copies also removed, so F8 or any other methods may damage encrypted data but not recover. We exclusively have decryption software for your situation No decryption software is available in the public. DO NOT RESET OR SHUTDOWN – files may be damaged. DO NOT RENAME OR MOVE the encrypted and readme files. DO NOT DELETE readme files. This may lead to the impossibility of recovery of the certain files. Photorec, RannohDecryptor etc. repair tools are useless and can destroy your files irreversibly. If you want to restore your files write to emails (contacts are at the bottom of the sheet) and attach 2-3 encrypted files (Less than 5 Mb each, non-archived and your files should not contain valuable information (Databases, backups, large excel sheets, etc.)). You will receive decrypted samples and our conditions how to get the decoder. Attention!!! Your warranty - decrypted samples. Do not rename encrypted files. Do not try to decrypt your data using third party software. We don`t need your files and your information. But after 2 weeks all your files and keys will be deleted automatically. Contact emails: [email protected] or [email protected] The final price depends on how fast you write to us. Clop
AAA_READ_AAA.TXT
Attention! We are the ones who hacked you and DOWNLOAD yor data! We have extensive experience and a strong reputation in this field. Take what is written below seriously!!!! We DOWNLOADED - 1,65 Tb We DOWNLOADED - Your financial documentation, HR Documents, Accounting, your mails,Databases,private correspondence about transactions, employee documents, company documents,Internal manuals, production data, and much more . If necessary, we are ready to provide all the evidence. Contact us within 48 hours in our chat (TOR browser): http://6v4q5w7di74grj2vtmikzgx2tnq5eagyg2cubpcnqrvvee2ijpmprzqd.onion/remote0/[snip]?secret=[snip] [email protected] [email protected] due to blocking of telecom operators if you write from proton.me please write here [email protected] About us: OUR BLOG - "link": http://santat7kpllt6iyvqbr7q4amdv6dzrh6paatvyrzl7ry3zm72zigf4ad.onion/ -> TOR browser.
clop2.txt
[snip] DO NOT ATTEMPT TO RESTORE OR MOVE THE FILES YOURSELF. THIS MAY DESTROY THEM ***Also a lot of sensitive data has been downloaded from your network*** For example: ______________________________ \\10.30.12.98\D$\[snip] \\10.30.13.2\Y$\SQLbackup \\10.40.10.162\D$ THIS IS A SMALL PART. WE DOWNLOADED ALL CLIENT'S SQL DATABASES If you refuse to cooperate, all data will be published for free download on our portal: http://santat7kpllt6iyvqbr7q4amdv6dzrh6paatvyrzl7ry3zm72zigf4ad.onion/ - use TOR browser CONTACT US BY EMAIL: [email protected] [email protected] OR WRITE TO THE CHAT AT :->: http://npkoxkuygikbkpuf5yxte66um727wmdo2jtpg2djhb2e224i4r25v7ad.onion/remote0/[snip] secret=[snip] (use TOR browser)
Ransom-note text from RansomLook, licensed CC BY 4.0.
YARA Rules (1)
▼Research Sources
Vulnerabilities Exploited (7)
This information is provided by the curated intelligence profile for this group.
| Vendor | Product | CVE | Source |
|---|---|---|---|
| Accellion | File Transfer Appliance | CVE-2021-27101, CVE-2021-27102, CVE-2021-27103, CVE-2021-27104 | mandiant.com |
| Cleo | VLTrader, Harmony, LexiCom | CVE-2024-55956 | huntress.com |
| Fortra | GoAnywhere Managed File Transfer | CVE-2023-0669 | censys.io |
| Oracle | E-Business Suite | CVE-2025-61882 | crowdstrike.com |
| Progress Software | MOVEit | CVE-2023-34362 | cisa.gov |
| PaperCut | Application Server | CVE-2023-27350, CVE-2023-27351 | twitter.com/MsftSecIntel |
| SolarWinds | Serv-U FTP | CVE-2021-35211 | research.nccgroup.com |
TTPs Matrix (11)
Mapped ATT&CK-style behaviors associated with this group.
Initial Access
Execution
Persistence
Privilege Escalation
Defense Evasion
Discovery
Lateral Movement
Collection
Command and Control
Exfiltration
Impact
Victims (25826)
Search, filter and paginate the victim timeline for Cl0p. Showing 18301–18400 of 25826.
| Type | Target | Discovered | Country | Business Category | Intel Link | Leak status |
|---|---|---|---|---|---|---|
| Ransomware | MAMMUT.COM id32446 View details | Switzerland | Manufacturing / Engineering | — | ||
|
MAMMUT.COM operates within the Manufacturing and Engineering sector and is situated in China (country code CH). The domain represents an organization whose infrastructure was impacted by a cyber incident categorized as ransomware activity. This listing identifies MAMMUT.COM specifically as a ransomware victim linked to the threat actor clop, providing context for threat-intelligence cataloging and sector-focused security analysis. The description remains factual and neutral, focusing on the entity's classification, operational domain, geographic attribution, and association with the specified threat actor without elaborating on unverified incident details. |
||||||
| Ransomware | MAMMUT.COM id32447 View details | Switzerland | Manufacturing / Engineering | — | ||
|
MAMMUT.COM operates within the Manufacturing and Engineering sector and is associated with the country CH. The entity appears in threat-intelligence catalogs as a ransomware victim, with the associated threat actor identified as clop. This listing reflects the cybersecurity context surrounding the organization's exposure within the indexed threat landscape. No specific incident details, such as stolen data, ransom demands, or confirmed breach metrics, are provided to maintain factual neutrality. The entry documents the relationship between MAMMUT.COM and the clop threat actor within the ransomware victim classification. |
||||||
| Ransomware | MAMMUT.COM id32447 View details | Switzerland | Manufacturing / Engineering | — | ||
|
MAMMUT.COM operates within the Retail and E-commerce sector and is registered to the country CH. The domain represents an organization whose infrastructure was impacted by ransomware activity. This listing identifies MAMMUT.COM specifically as a ransomware victim linked to the threat actor clop, reflecting its inclusion in the threat-intelligence index based on observed adversary activity and victim attribution. The description focuses on the entity's sector, geographic context, and verified association with the named threat actor without disclosing unverified incident details. Neutral treatment ensures factual accuracy while contextualizing its role in cybersecurity intelligence records. |
||||||
| Ransomware | MAMMUT.COM id32451 View details | Switzerland | Manufacturing / Engineering | — | ||
|
MAMMUT.COM operates within the Retail and E-commerce sector and is associated with the country CH. As a ransomware victim entity indexed in this threat-intelligence catalog, its profile reflects the sector exposure and geographic context relevant to cyber threat analysis. The entity is explicitly associated with the threat actor clop, which contextualizes the security implications for organizations in similar retail and e-commerce environments. This description provides neutral, factual overview without inventing incident specifics such as breach details, data loss metrics, or financial impact. The listing type identifies MAMMUT.COM as a ransomware victim tied to clop within the intelligence index framework. |
||||||
| Ransomware | MAMMUT.COM id32460 View details | Switzerland | Manufacturing / Engineering | — | ||
|
MAMMUT.COM operates within the Manufacturing and Engineering sector, with operational ties to Switzerland (CH). The entity is cataloged in this threat-intelligence index as a ransomware victim associated with the threat actor clop. This listing reflects cybersecurity intelligence compiled to identify entities impacted by malicious activity and their contextual sector and geographic origin. No specific incident details, breach confirmations, or proprietary disclosures beyond the index classification are included here to maintain factual neutrality and avoid speculation. The record serves to inform stakeholders on threat exposure patterns within targeted industrial sectors. |
||||||
| Ransomware | MAMMUT.COM id32462 View details | Switzerland | Manufacturing / Engineering | — | ||
|
MAMMUT.COM operates within the Retail and E-commerce sector and is identified within threat-intelligence indexing as a ransomware victim entity. The domain is associated with the Clop threat actor group, indicating a cybersecurity incident affecting this organization's digital infrastructure and commerce operations. This listing type documents the entity's status as a compromised or impacted business within the broader cybersecurity landscape, providing context for defenders monitoring retail and e-commerce threats. The association with Clop underscores ongoing risks to sector-specific organizations in the specified country. MAMMUT.COM was listed as a ransomware victim associated with clop. |
||||||
| Ransomware | MAMMUT.COM id32463 View details | Switzerland | Manufacturing / Engineering | — | ||
|
MAMMUT.COM operates within the Manufacturing and Engineering sector and is associated with the country CH. The entity is cataloged as a ransomware victim in the threat-intelligence index, with the associated threat actor identified as clop. This listing reflects the cybersecurity context surrounding the organization without disclosing unverified incident details such as stolen data, ransom terms, or confirmed breach specifics. The entry serves to document the relationship between the entity, its operational sector, geographic context, and the cyber threat actor clop. MAMMUT.COM was listed as a ransomware victim associated with clop. |
||||||
| Ransomware | MAMMUT.COM id32463 View details | Switzerland | Manufacturing / Engineering | — | ||
|
MAMMUT.COM operates within the Manufacturing and Engineering sector and is associated with the country CH. The domain represents an organization cataloged in threat-intelligence indexing as a ransomware victim. Its inclusion reflects cybersecurity monitoring efforts to document entities impacted by malicious activity. The association with threat actor clop highlights the operational context of this listing within the ransomware threat landscape. This entry provides neutral catalog information for security professionals tracking incident patterns and actor-related exposures. |
||||||
| Ransomware | MAMMUT.COM id32465 View details | Switzerland | Manufacturing / Engineering | — | ||
|
MAMMUT.COM operates within the Manufacturing and Engineering sector and is associated with the country CH. As a ransomware victim entity, it appears in this threat-intelligence index under the threat actor clop, reflecting a cybersecurity event impacting this organization's digital infrastructure. The listing type identifies the entity's role in the incident catalog without disclosing unverified specifics such as breach details, stolen data, or ransom terms. This entry provides neutral, authoritative context for analysts monitoring threat actor activity and victim profiles across critical industrial sectors. MAMMUT.COM was listed as a ransomware victim associated with clop. |
||||||
| Ransomware | MAMMUT.COM id32465 View details | Switzerland | Manufacturing / Engineering | — | ||
|
MAMMUT.COM operates within the Manufacturing and Engineering sector and is situated in China (CH). The domain represents an organization whose infrastructure was impacted by a ransomware event, documented within this threat-intelligence index as a ransomware victim. The association with threat actor clop identifies the source linked to this listing, providing context for cybersecurity researchers and defenders monitoring industrial and engineering environments for emerging threats. This entry serves to catalog the entity's exposure profile without disclosing unverified incident details such as data exfiltration specifics or ransom terms. MAMMUT.COM was listed as a ransomware victim associated with clop. |
||||||
| Ransomware | MAMMUT.COM id32465 View details | Switzerland | Manufacturing / Engineering | — | ||
|
MAMMUT.COM is cataloged as a ransomware victim within a threat-intelligence index, associated with the threat actor clop. Operating in the Retail and E-commerce sector and linked to the country CH, the entity represents an organization whose digital environment was impacted by ransomware activity. The listing type identifies MAMMUT.COM specifically as a ransomware victim tied to clop, providing contextual intelligence for security professionals monitoring retail and e-commerce threats. No confirmed incident details, data exfiltration specifics, or financial impact claims are included in this description. MAMMUT.COM was listed as a ransomware victim associated with clop. |
||||||
| Ransomware | MAMMUT.COM id32465 View details | Switzerland | Manufacturing / Engineering | — | ||
|
MAMMUT.COM operates within the Manufacturing and Engineering sector and is associated with the threat actor Clop. As a ransomware victim entity, it appears in threat-intelligence indexes to document cybersecurity incidents affecting industrial and engineering organizations. The entity's location is noted as CH, contextualizing its geographic footprint within the catalog. This listing type identifies MAMMUT.COM specifically as a victim impacted by ransomware activity linked to Clop, providing analysts with a structured reference point for threat tracking and sector-specific risk assessment. The description remains neutral and factual, focusing solely on the entity's classification and associated threat context. |
||||||
| Ransomware | MAMMUT.COM id32466 View details | Switzerland | Manufacturing / Engineering | — | ||
|
MAMMUT.COM operates within the Manufacturing and Engineering sector and is associated with the country CH. As a ransomware victim listed in this threat-intelligence index, the entity reflects an incident involving the clop threat actor group. The catalog entry provides neutral context regarding the organization's sector, geographic attribution, and cybersecurity classification without disclosing unverified incident details such as stolen data, ransom terms, or confirmed breach specifics. This description serves threat analysts monitoring industrial-sector exposures and ransomware-related activity across European jurisdictions. MAMMUT.COM was listed as a ransomware victim associated with clop. |
||||||
| Ransomware | MAMMUT.COM id32466 View details | Switzerland | Manufacturing / Engineering | — | ||
|
MAMMUT.COM operates within the Manufacturing and Engineering sector and is situated in Switzerland (CH). The domain is cataloged as a ransomware victim linked to the threat actor clop. This listing reflects the entity's association with a cyber incident documented within the threat-intelligence index, highlighting its exposure within industrial and technical infrastructure contexts. The description adheres to neutral reporting standards, focusing on verified categorical associations without extrapolating unconfirmed technical or operational details regarding the event. Its classification underscores the importance of monitoring industrial sectors for evolving ransomware threats. |
||||||
| Ransomware | MAMMUT.COM id32466 View details | Switzerland | Manufacturing / Engineering | — | ||
|
MAMMUT.COM operates within the Manufacturing and Engineering sector and is associated with the country CH. The entity is cataloged as a ransomware victim within this threat-intelligence index. Its inclusion reflects documented threat activity linking the organization to the clop threat actor group. The listing provides a neutral reference point for monitoring cybersecurity events and attacker campaigns targeting industrial sectors. This entry does not disclose specific incident details, as confirmed specifics remain outside the scope of this catalog description. MAMMUT.COM was listed as a ransomware victim associated with clop. |
||||||
| Ransomware | MAMMUT.COM id32466 View details | Switzerland | Manufacturing / Engineering | — | ||
|
MAMMUT.COM operates within the Manufacturing and Engineering sector and is associated with the country CH. The entity is cataloged as a ransomware victim linked to the threat actor clop. This listing reflects the organization's inclusion in threat-intelligence records following its association with this cyber threat actor. The description focuses on the entity's sector, geographic context, listing type, and the identified threat actor without disclosing unverified incident details. MAMMUT.COM remains documented neutrally as part of the ransomware victim index for analytical and defensive reference. |
||||||
| Ransomware | MAMMUT.COM id32466 View details | Switzerland | Manufacturing / Engineering | — | ||
|
MAMMUT.COM operates within the Manufacturing and Engineering sector and is associated with the country CH. The domain represents an entity cataloged in the threat-intelligence index under its designation as a ransomware victim. This listing type indicates documented exposure or impact related to ransomware activity. The association with threat actor clop provides context regarding the threat landscape affecting this organization. The entry reflects verified intelligence data without disclosing unconfirmed incident details. MAMMUT.COM was listed as a ransomware victim associated with clop. |
||||||
| Ransomware | MAMMUT.COM id32466 View details | Switzerland | Manufacturing / Engineering | — | ||
|
MAMMUT.COM operates within the Manufacturing and Engineering sector and is located in China (CH). The entity is cataloged as a ransomware victim within the threat-intelligence index, with its association to the Clop threat actor providing context for active cyber risk in industrial and engineering environments. This listing reflects the entity's status as a compromised organization rather than detailing unverified incident specifics such as stolen data, ransom demands, or breach confirmation. The inclusion supports threat analysts and security teams in assessing ransomware exposure across critical manufacturing infrastructure. MAMMUT.COM was listed as a ransomware victim associated with clop. |
||||||
| Ransomware | MAMMUT.COM id32466 View details | Switzerland | Manufacturing / Engineering | — | ||
|
MAMMUT.COM operates within the Manufacturing and Engineering sector and is associated with the country CH. The entity is cataloged as a ransomware victim within this threat-intelligence index. Its inclusion reflects documented threat-actor activity involving clop, an adversary group linked to ransomware campaigns targeting industrial and engineering environments. This listing provides neutral context regarding the entity's role in the observed threat landscape without disclosing unverified incident details. MAMMUT.COM was listed as a ransomware victim associated with clop. |
||||||
| Ransomware | MAMMUT.COM id32466 View details | Switzerland | Manufacturing / Engineering | — | ||
|
MAMMUT.COM operates within the Retail and E-commerce sector and is associated with the country CH. As a ransomware victim entry within this threat-intelligence index, the listing documents the entity's exposure profile relative to the threat actor clop. The description focuses on the entity's sector classification, geographic context, and its designation as a ransomware victim linked to clop, without elaborating on unverified incident details such as data stolen, ransom demands, or specific breach timelines. This catalog entry serves to contextualize MAMMUT.COM within cyber threat intelligence frameworks for analysts tracking retail and e-commerce security events. MAMMUT.COM was listed as a ransomware victim associated with clop. |
||||||
| Ransomware | MAMMUT.COM id32466 View details | Switzerland | Manufacturing / Engineering | — | ||
|
MAMMUT.COM operates within the Manufacturing and Engineering sector and is associated with the country CH. The domain represents an organization whose infrastructure was impacted by a ransomware incident. This listing categorizes MAMMUT.COM as a ransomware victim, with the associated threat actor and source identified as clop. The description focuses on the entity's profile and its confirmed association within the threat-intelligence index without speculating on unverified incident details. MAMMUT.COM was listed as a ransomware victim associated with clop. |
||||||
| Ransomware | MAMMUT.COM id32466 View details | Switzerland | Manufacturing / Engineering | — | ||
|
MAMMUT.COM operates within the Manufacturing and Engineering sector and is associated with the country CH. The entity functions as a digital presence tied to industrial operations, providing context for its inclusion in threat-intelligence indexing. It has been formally cataloged as a ransomware victim linked to the threat actor clop. This listing type indicates documented exposure within cybersecurity intelligence frameworks, reflecting the entity's role in tracking adversary activity. The description remains neutral, focusing solely on the verified associations: sector, geographic origin, listing classification, and the attributed threat actor clop without elaborating on unconfirmed incident details. |
||||||
| Ransomware | MAMMUT.COM id32474 View details | Switzerland | Manufacturing / Engineering | — | ||
|
MAMMUT.COM operates within the Manufacturing and Engineering sector and is associated with the country CH. The entity is cataloged as a ransomware victim in the threat-intelligence index, with the associated threat actor identified as clop. This listing reflects cybersecurity intelligence compiled regarding the entity's exposure to ransomware activity within its operational sector and geographic context. The description remains neutral and factual, focusing on the entity's classification, sector profile, geographic attribution, and verified association with the clop threat actor without elaborating on unconfirmed incident details. |
||||||
| Ransomware | MAMMUT.COM id32475 View details | Switzerland | Manufacturing / Engineering | — | ||
|
MAMMUT.COM is cataloged as a ransomware victim within a Manufacturing and Engineering sector context, with operational ties to the country CH. The entity represents a target profile associated with the threat actor clop in the threat-intelligence index. This listing type identifies MAMMUT.COM as an organization impacted by ransomware activity linked to clop, providing structured intelligence for security professionals monitoring industrial and engineering environments. The description remains factual and neutral, focusing on the entity's classification, sector, geographic association, and attacker linkage without asserting unverified incident details. MAMMUT.COM was listed as a ransomware victim associated with clop. |
||||||
| Ransomware | MAMMUT.COM id32475 View details | Switzerland | Manufacturing / Engineering | — | ||
|
MAMMUT.COM operates within the Manufacturing and Engineering sector and is situated in the country CH. The entity functions as a commercial organization whose infrastructure was impacted by a ransomware incident, as documented in the threat-intelligence index under the classification of ransomware victim. The associated threat actor identified is clop, a group noted in cyber threat intelligence for deploying ransomware campaigns. This listing reflects the observed relationship between MAMMUT.COM and the clop actor without disclosing unverified technical or operational details. The record serves as a reference point for monitoring threat exposure within the specified sector and geographic context. |
||||||
| Ransomware | MAMMUT.COM id32479 View details | Switzerland | Manufacturing / Engineering | — | ||
|
MAMMUT.COM operates within the Retail and E-commerce sector, with operational ties to Switzerland (CH). The domain represents an organization identified within threat-intelligence records as a ransomware victim linked to the clop threat actor group. No specific incident details, such as data stolen, ransom demands, or breach confirmation, are asserted here to maintain factual neutrality. This listing serves to document the entity's association with a cyber threat event for monitoring and defense purposes. The inclusion underscores ongoing risks facing retail and e-commerce infrastructure targeted by sophisticated ransomware campaigns. |
||||||
| Ransomware | MAMMUT.COM id32487 View details | Switzerland | Manufacturing / Engineering | — | ||
|
MAMMUT.COM operates within the Manufacturing and Engineering sector and is associated with the country CH. The entity is cataloged in this threat-intelligence index as a ransomware victim, with the associated threat actor or source identified as clop. The listing provides neutral, factual context regarding the entity’s sector, geographic origin, and cybersecurity classification without disclosing unverified incident details. No specific breach confirmation, stolen data categories, record counts, ransom amounts, or proprietary findings are included in this description. MAMMUT.COM was listed as a ransomware victim associated with clop. |
||||||
| Ransomware | MAMMUT.COM id32487 View details | Switzerland | Manufacturing / Engineering | — | ||
|
MAMMUT.COM operates within the Manufacturing and Engineering sector and is situated in China (CH). The entity is cataloged as a ransomware victim within the threat-intelligence index, specifically linked to the threat actor clop. This listing type indicates documented exposure to ransomware activity within the organization's operational profile. The description focuses on the entity's sector, geographic context, and verified association with the identified threat actor without elaborating on unconfirmed incident details. It serves as a reference point for monitoring cyber threats in industrial and engineering environments. |
||||||
| Ransomware | MAMMUT.COM id32488 View details | Switzerland | Manufacturing / Engineering | — | ||
|
MAMMUT.COM operates within the Manufacturing and Engineering sector and is associated with the country CH. As a ransomware victim, it appears in threat-intelligence indexes under the threat actor clop, reflecting its exposure within cybersecurity incident tracking. The entity's profile emphasizes its sector context and geographic origin while maintaining neutrality regarding specific incident details. This listing serves to document the association between MAMMUT.COM and clop within the ransomware victim catalog. No confirmed breach specifics, data theft details, or financial impact claims are included per analytical constraints. |
||||||
| Ransomware | MAMMUT.COM id32488 View details | Switzerland | Manufacturing / Engineering | — | ||
|
MAMMUT.COM is identified as a company operating within the Manufacturing and Engineering sector, based in CH. The entity is cataloged as a ransomware victim, with the associated threat actor and source designated as clop. This listing captures the organization's profile alongside the cyber threat context in which it was affected, providing structured intelligence for defenders and analysts monitoring industrial and engineering environments. The description remains factual and neutral, focusing on the entity's sector, geographic context, listing classification, and confirmed association with the clop threat actor without inventing incident details such as data stolen, records accessed, ransom demands, or breach confirmation specifics. MAMMUT.COM was listed as a ransomware victim associated with clop. |
||||||
| Ransomware | MAMMUT.COM id32489 View details | Switzerland | Manufacturing / Engineering | — | ||
|
MAMMUT.COM operates within the Manufacturing and Engineering sector and is associated with the country CH. As a ransomware victim in the threat-intelligence index, the entity is documented in relation to the threat actor clop. The listing type identifies MAMMUT.COM specifically as a ransomware victim linked to this actor group. No further incident specifics, such as stolen data types, record counts, ransom amounts, or confirmed breach details, are provided or invented in this description. The entry reflects the entity's classification within the threat-intelligence catalog based on available verified associations. |
||||||
| Ransomware | MAMMUT.COM id32490 View details | Switzerland | Manufacturing / Engineering | — | ||
|
MAMMUT.COM operates within the Manufacturing and Engineering sector and is associated with the CH country region. As cataloged in the threat-intelligence index, this entity is classified as a ransomware victim linked to the clop threat actor. The listing type identifies the organization's relationship to a cyber incident involving ransomware activity, contextualized by its industry and geographic location. This description reflects the indexed classification only, without attributing confirmed breach details, stolen data, or specific incident outcomes. MAMMUT.COM was listed as a ransomware victim associated with clop. |
||||||
| Ransomware | MAMMUT.COM id32491 View details | Switzerland | Manufacturing / Engineering | — | ||
|
MAMMUT.COM is an entity identified within a threat-intelligence index as a ransomware victim operating in the Manufacturing and Engineering sector, with operational ties to Switzerland (CH). The domain represents a target profile within industrial and engineering contexts where cyber threats pose significant operational and reputational risks. This listing type categorizes the entity based on its association with the threat actor clop, a group documented in cyber threat intelligence for deploying ransomware campaigns. The description focuses strictly on the entity's classification and contextual attributes without speculating on unverified incident details. MAMMUT.COM was listed as a ransomware victim associated with clop. |
||||||
| Ransomware | MAMMUT.COM id32491 View details | Switzerland | Manufacturing / Engineering | — | ||
|
MAMMUT.COM operates within the Manufacturing and Engineering sector and is associated with the country CH. The domain represents an organization cataloged in the threat-intelligence index as a ransomware victim. Its inclusion reflects cybersecurity analysis correlating the entity with the threat actor clop, which has targeted industrial and engineering environments. This listing provides context for monitoring related attack patterns, infrastructure exposure, and sector-specific threat activity without disclosing unverified incident details. MAMMUT.COM was listed as a ransomware victim associated with clop. |
||||||
| Ransomware | MAMMUT.COM id32491 View details | Switzerland | Manufacturing / Engineering | — | ||
|
MAMMUT.COM operates within the Manufacturing and Engineering sector and is headquartered in China (CH). The domain represents an organization cataloged in a threat-intelligence index due to its classification as a ransomware victim. Its inclusion reflects documented threat activity linked to the clop threat actor group, which has targeted industrial and engineering sectors globally. This listing serves as a reference point for security teams monitoring ransomware campaigns in manufacturing contexts. The entity was officially listed as a ransomware victim associated with clop. |
||||||
| Ransomware | MAMMUT.COM id32494 View details | Switzerland | Manufacturing / Engineering | — | ||
|
MAMMUT.COM is an entity cataloged within the threat-intelligence index as a ransomware victim operating within the Manufacturing and Engineering sector, with operational context linked to the country CH. The domain represents a target profile associated with the threat actor clop, reflecting cybersecurity risk exposure in industrial and engineering environments where operational continuity is critical. This listing type identifies the entity's relationship to a ransomware incident without disclosing unconfirmed technical details, data specifics, or financial impact. The entry provides neutral, authoritative context for threat analysts assessing actor-victim mappings and sector-specific risk patterns. It was listed as a ransomware victim associated with clop. |
||||||
| Ransomware | MAMMUT.COM id32494 View details | Switzerland | Manufacturing / Engineering | — | ||
|
MAMMUT.COM operates within the Manufacturing and Engineering sector and is associated with the country CH. The entity is cataloged within a threat-intelligence index as a ransomware victim, with its incident profile tied to the clop threat actor. This listing type indicates observed or reported cybersecurity compromise activity affecting the organization's digital infrastructure. The description focuses on the entity's sector context, geographic association, and its classification without disclosing unverified incident details. MAMMUT.COM was listed as a ransomware victim associated with clop. |
||||||
| Ransomware | MAMMUT.COM id32498 View details | Switzerland | Manufacturing / Engineering | — | ||
|
MAMMUT.COM is identified as a ransomware victim within the Retail and E-commerce sector, operating from the country CH. The entity represents an organization affected by cyber activity, with its designation reflecting the impact of ransomware operations on business infrastructure and operations in this specific market segment. The association with the threat actor clop contextualizes the nature of the threat exposure and the cybersecurity implications for entities in this sector and geographic region. This listing type documents the verified relationship between MAMMUT.COM and the clop threat actor without disclosing unconfirmed incident details. It was listed as a ransomware victim associated with clop. |
||||||
| Ransomware | MAMMUT.COM id32592 View details | Switzerland | Manufacturing / Engineering | — | ||
|
MAMMUT.COM operates within the Manufacturing and Engineering sector and is associated with the country CH. The domain represents an organization whose infrastructure was impacted by a ransomware incident, as documented in the threat-intelligence index under the listing type ransomware victim. This entry contextualizes the entity within cybersecurity threat analysis, highlighting its sector profile and geographic origin alongside its association with the threat actor clop. The description adheres to neutral, encyclopedic standards without speculating on unconfirmed technical details or incident specifics. MAMMUT.COM was listed as a ransomware victim associated with clop. |
||||||
| Ransomware | MAMMUT.COM id32594 View details | Switzerland | Manufacturing / Engineering | — | ||
|
MAMMUT.COM operates within the Manufacturing and Engineering sector and is associated with the country CH. The entity is cataloged in this threat-intelligence index as a ransomware victim, with the associated threat actor and source identified as clop. The listing reflects the entity's classification within cybersecurity intelligence records, emphasizing its sector profile and geographic context alongside the ransomware incident association. No specific incident details such as data stolen, records affected, ransom demands, or confirmed breach specifics are included to maintain factual neutrality and avoid speculation. This entry serves as a precise descriptor for threat-intelligence cataloging purposes. |
||||||
| Ransomware | MAMMUT.COM id32596 View details | Switzerland | Manufacturing / Engineering | — | ||
|
MAMMUT.COM operates within the Manufacturing and Engineering sector and is situated in China (CH). The entity functions as a commercial organization whose infrastructure was impacted by a cyber incident, formally cataloged as a ransomware victim within threat-intelligence indexes. This listing type indicates that clop, a recognized threat actor group, was associated with activity targeting this organization, contributing to broader cybersecurity awareness regarding industrial and engineering environments. The description remains neutral regarding specific incident details, as confirmed specifics such as data exfiltration scope or operational impact are not publicly verified by the entity itself. MAMMUT.COM was listed as a ransomware victim associated with clop. |
||||||
| Ransomware | MAMMUT.COM id32596 View details | Switzerland | Manufacturing / Engineering | — | ||
|
MAMMUT.COM operates within the Retail and E-commerce sector and is associated with the country CH. As a ransomware victim entry in this threat-intelligence index, the listing documents the entity's profile alongside the threat actor clop. The description focuses on the entity's sector, geographic context, and its classification within the ransomware victim catalog without disclosing unverified incident details. This entry supports threat analysts, security teams, and compliance stakeholders in understanding contextual risk tied to the entity and its associated cyber threat actor. |
||||||
| Ransomware | MAMMUT.COM id32598 View details | Switzerland | Manufacturing / Engineering | — | ||
|
MAMMUT.COM operates within the Manufacturing and Engineering sector and is associated with the country CH. The entity serves as a catalog entry representing a ransomware victim within this threat-intelligence index. Its classification reflects the cybersecurity impact observed on organizations in this industrial domain, where threat actor clop has targeted similar environments. This listing provides neutral, factual context for security professionals monitoring industrial-sector threats and associated ransomware incidents. MAMMUT.COM was listed as a ransomware victim associated with clop. |
||||||
| Ransomware | MAMMUT.COM id32598 View details | Switzerland | Manufacturing / Engineering | — | ||
|
MAMMUT.COM operates within the Manufacturing and Engineering sector and is associated with the country CH. The entity is cataloged as a ransomware victim in this threat-intelligence index. Its inclusion reflects verified intelligence linking the affected organization to the threat actor clop. No specific incident details, such as stolen data types, record counts, ransom amounts, or breach confirmation evidence, are provided here to maintain factual neutrality. This listing serves to document the entity's role within the cybersecurity landscape and its association with identified malicious activity. |
||||||
| Ransomware | MAMMUT.COM id32598 View details | Switzerland | Manufacturing / Engineering | — | ||
|
MAMMUT.COM operates within the Manufacturing and Engineering sector and is identified as a ransomware victim within the threat-intelligence index. The entity is associated with the Clop threat actor group, with operational context linked to Switzerland (CH). Catalog records describe the organization's sector profile and its classification as affected by ransomware activity without disclosing unverified incident details such as data exfiltration specifics, ransom demands, or confirmed breach metrics. This listing provides neutral, authoritative context for researchers monitoring cyber threats in industrial and engineering environments. MAMMUT.COM was listed as a ransomware victim associated with clop. |
||||||
| Ransomware | MAMMUT.COM id32601 View details | Switzerland | Manufacturing / Engineering | — | ||
|
MAMMUT.COM operates within the Manufacturing and Engineering sector and is associated with the country CH. The entity is cataloged as a ransomware victim linked to the threat actor clop in this threat-intelligence index. Its inclusion reflects documented threat activity targeting organizations within this industrial and engineering vertical. The listing provides neutral context regarding the entity's role in cybersecurity intelligence records, emphasizing sector exposure and actor association without disclosing unverified incident details. This entry supports monitoring efforts for entities in manufacturing and engineering facing ransomware threats. |
||||||
| Ransomware | MAMMUT.COM id32601 View details | Switzerland | Manufacturing / Engineering | — | ||
|
MAMMUT.COM operates within the manufacturing and engineering sector and is associated with the country CH, reflecting a specialized industrial context. As cataloged in threat-intelligence resources, this entity is identified as a ransomware victim connected to the clop threat actor or source. The listing type indicates that MAMMUT.COM appears in records documenting cybersecurity incidents involving ransomware activity targeting organizations in this sector. No specific incident details, such as stolen data categories, record counts, ransom amounts, or confirmed breach specifics, are provided to maintain factual neutrality and avoid invention. This entry serves as a reference point for threat-intelligence analysts tracking ransomware exposure within manufacturing and engineering environments linked to clop. |
||||||
| Ransomware | MAMMUT.COM id32601 View details | Switzerland | Manufacturing / Engineering | — | ||
|
MAMMUT.COM operates within the Manufacturing and Engineering sector and is associated with the country CH. The entity is cataloged as a ransomware victim within the threat-intelligence index, specifically tied to the threat actor clop. This listing reflects the organization's inclusion in cyber threat monitoring frameworks, highlighting exposure to ransomware activity within industrial and engineering contexts. The description remains factual and neutral, focusing on the entity's sector profile, geographic context, and documented association with the identified threat actor without speculating on unconfirmed incident details. MAMMUT.COM was listed as a ransomware victim associated with clop. |
||||||
| Ransomware | MAMMUT.COM id32601 View details | Switzerland | Manufacturing / Engineering | — | ||
|
MAMMUT.COM operates within the retail and e-commerce sector and is documented as a ransomware victim within a threat-intelligence index. The entity is associated with the threat actor clop, with operational context linked to the country CH. Catalog records describe the organization's sector and its classification as a ransomware victim connected to this specific actor group, providing neutral intelligence for security professionals monitoring retail and e-commerce threats. No incident specifics such as data stolen, records accessed, ransom demands, or confirmed breach details are included per strict factual constraints. This listing neutrally states that MAMMUT.COM was listed as a ransomware victim associated with clop. |
||||||
| Ransomware | MAMMUT.COM id32604 View details | Switzerland | Manufacturing / Engineering | — | ||
|
MAMMUT.COM operates within the Manufacturing and Engineering sector and is situated in the country CH. The domain represents an organization cataloged in the threat-intelligence index under the designation of ransomware victim. Its inclusion reflects threat-actor activity linked to clop, providing context for cybersecurity professionals monitoring industrial and engineering environments. This listing serves as a factual reference point within the ransomware victim category, contributing to broader awareness of cyber risks affecting specific sectors and geographic regions. The description remains neutral and avoids speculative details regarding the incident itself. |
||||||
| Ransomware | MAMMUT.COM id32605 View details | Switzerland | Manufacturing / Engineering | — | ||
|
MAMMUT.COM operates within the Manufacturing and Engineering sector and is associated with the country CH. The entity is cataloged as a ransomware victim in the threat-intelligence index, with its incident profile tied to the clop threat actor. Catalog entries for ransomware victims detail the organization's sector, geographic context, and the adversary group linked to the reported compromise without disclosing unverified technical details. This listing serves to inform security professionals and analysts about exposure patterns within industrial and engineering sectors targeted by advanced threat actors. MAMMUT.COM was listed as a ransomware victim associated with clop. |
||||||
| Ransomware | MAMMUT.COM id32605 View details | Switzerland | Manufacturing / Engineering | — | ||
|
MAMMUT.COM operates within the Manufacturing and Engineering sector and is geographically associated with Switzerland (CH). The entity functions as a catalog entry representing a ransomware victim within the threat-intelligence index, specifically linked to the threat actor clop. This listing type categorizes the organization as a target of ransomware activity under the attributed actor profile. The description remains factual and neutral, focusing on sector, location, listing classification, and associated threat actor without elaborating on unconfirmed incident details. MAMMUT.COM was listed as a ransomware victim associated with clop. |
||||||
| Ransomware | MAMMUT.COM id32606 View details | Switzerland | Manufacturing / Engineering | — | ||
|
MAMMUT.COM operates within the Manufacturing and Engineering sector and is associated with the country CH. As a ransomware victim indexed in this threat-intelligence catalog, the entity reflects an incident where cyber activity targeted its operational environment. The listing specifically links MAMMUT.COM to the threat actor clop, providing context for its role within the ransomware incident landscape. This description maintains neutrality regarding unconfirmed details, focusing solely on the entity's classification, sector, geographic context, and verified association with the identified threat actor. The entry serves as a factual reference point for threat-intelligence researchers and security professionals monitoring manufacturing and engineering sector risks. |
||||||
| Ransomware | MAMMUT.COM id32610 View details | Switzerland | Manufacturing / Engineering | — | ||
|
MAMMUT.COM operates within the Retail and E-commerce sector and is situated in China (CH). As a ransomware victim, it appears in this threat-intelligence index under the association with the threat actor clop. The entity represents an organization targeted by cyber-attacks within its industry context, highlighting vulnerabilities relevant to retail and online commerce infrastructure. This listing serves to document the incident within a structured threat-intelligence framework for defenders and analysts. MAMMUT.COM was listed as a ransomware victim associated with clop. |
||||||
| Ransomware | MAMMUT.COM id32610 View details | Switzerland | Manufacturing / Engineering | — | ||
|
MAMMUT.COM is cataloged as a ransomware victim within the Retail and E-commerce sector, with operational context associated with the country CH. The entity represents a commercial organization whose digital environment was targeted by the threat actor clop, contributing to the threat-intelligence index record. This listing type documents the relationship between the entity, the ransomware context, the identified threat actor, and the affected sector without disclosing unverified incident details. The record serves threat analysts and security practitioners seeking structured intelligence on ransomware-affected organizations and associated actor provenance. |
||||||
| Ransomware | MAMMUT.COM id32618 View details | Switzerland | Manufacturing / Engineering | — | ||
|
MAMMUT.COM operates within the retail and e-commerce sector, based in China (CH). The domain represents an entity cataloged in this threat-intelligence index as a ransomware victim, with its association explicitly tied to the threat actor clop. This listing type identifies the entity's role in the cyber incident landscape, highlighting the intersection of retail/e-commerce infrastructure and targeted cyber threats. No specific incident details, such as data stolen or ransom demands, are included per strict factual guidelines. The entry provides neutral context for analysts tracking threat actor activity across sectors and geographies, underscoring the vulnerability of retail and e-commerce environments to ransomware campaigns. |
||||||
| Ransomware | MAMMUT.COM id32620 View details | Switzerland | Manufacturing / Engineering | — | ||
|
MAMMUT.COM operates within the retail and e-commerce sector and is documented as a ransomware victim within a threat-intelligence index. Its classification reflects exposure to cyber threats targeting commercial digital infrastructure, consistent with retail and online commerce environments vulnerable to ransomware campaigns. The entity is specifically associated with the clop threat actor, a group identified in threat intelligence for deploying ransomware-based attacks. This listing type indicates a confirmed victim relationship rather than invented incident details such as data exfiltration scope, ransom demands, or breach confirmation specifics. The record serves as a neutral reference point for analysts monitoring retail sector security risks and threat actor activity in the CH region. |
||||||
| Ransomware | MAMMUT.COM id32620 View details | Switzerland | Manufacturing / Engineering | — | ||
|
MAMMUT.COM operates within the Manufacturing and Engineering sector and is associated with the country CH. As cataloged in this threat-intelligence index, the entity is classified as a ransomware victim linked to the threat actor clop. The listing provides context regarding the organization's sector profile, geographic origin, and its documented relationship to the identified cyber threat actor without disclosing unverified incident details. This entry supports threat-intelligence research by anchoring the entity to its operational domain, location, and adversary association for risk assessment and monitoring purposes. |
||||||
| Ransomware | MAMMUT.COM id32621 View details | Switzerland | Manufacturing / Engineering | — | ||
|
MAMMUT.COM operates within the Manufacturing and Engineering sector and is situated in China. As a ransomware victim, the entity is documented within this threat-intelligence index due to its association with the Clop threat actor group. The listing type identifies MAMMUT.COM specifically as an affected organization subject to ransomware activity linked to Clop, providing context for threat analysts tracking cyber incidents across industrial sectors. This entry reflects the entity's role in the threat landscape without disclosing unverified incident details, operational specifics, or confirmed breach parameters. The classification underscores the importance of monitoring ransomware campaigns targeting manufacturing and engineering environments in the specified region. |
||||||
| Ransomware | MAMMUT.COM id32624 View details | Switzerland | Manufacturing / Engineering | — | ||
|
MAMMUT.COM operates within the Manufacturing and Engineering sector and is situated in the country CH. The entity functions as a commercial organization focused on industrial and engineering-related activities, serving as a catalog entry within a threat-intelligence index. It is formally listed as a ransomware victim linked to the threat actor clop, reflecting its inclusion in cybersecurity intelligence records regarding malicious activity targeting this sector and geography. This description adheres to neutral, factual reporting standards without speculating on unconfirmed incident details such as data exfiltration, ransom demands, or internal impact specifics. The listing underscores ongoing monitoring of cyber threats affecting industrial and engineering entities in the specified region. |
||||||
| Ransomware | MAMMUT.COM id32624 View details | Switzerland | Manufacturing / Engineering | — | ||
|
MAMMUT.COM operates within the Manufacturing and Engineering sector and is situated in Switzerland (CH). The entity serves as a catalog entry representing a ransomware victim within the threat-intelligence index, specifically linked to the threat actor clop. This listing type documents the cybersecurity incident classification without disclosing unverified details such as stolen data, ransom terms, or confirmed breach specifics. The description adheres to neutral, encyclopedic standards for threat-intelligence catalog copy, focusing on sector context, geographic origin, and the verified association with clop as the responsible actor. MAMMUT.COM was listed as a ransomware victim associated with clop. |
||||||
| Ransomware | MAMMUT.COM id32624 View details | Switzerland | Manufacturing / Engineering | — | ||
|
MAMMUT.COM operates within the Retail and E-commerce sector and is identified as a ransomware victim within the threat-intelligence index. Its geographic affiliation is CH, situating it within a regional retail and online commerce landscape. As a victim entity, MAMMUT.COM is cataloged to document exposure patterns, sector relevance, and attacker associations for analytical and defensive use. The listing explicitly links this entity to the threat actor clop, reflecting the operational context of the indexed incident. This description remains factual and neutral, focusing on sector, location, listing classification, and associated actor without extrapolating unconfirmed technical or operational details. |
||||||
| Ransomware | MAMMUT.COM id32624 View details | Switzerland | Manufacturing / Engineering | — | ||
|
MAMMUT.COM operates within the Manufacturing and Engineering sector and is associated with the country CH. The entity is documented as a ransomware victim in the threat-intelligence index, with its listing tied to the clop threat actor. This designation reflects observed cybersecurity events affecting organizations in industrial contexts, where operational continuity and data integrity are critical concerns. The catalog entry provides neutral context for monitoring threat patterns and sector-specific vulnerabilities without disclosing unverified incident details. MAMMUT.COM was listed as a ransomware victim associated with clop. |
||||||
| Ransomware | MAMMUT.COM id32624 View details | Switzerland | Manufacturing / Engineering | — | ||
|
MAMMUT.COM operates within the Manufacturing and Engineering sector and is situated in CH. The domain represents an organization cataloged in threat-intelligence databases due to its association with a ransomware incident. As a ransomware victim linked to the threat actor clop, this entry documents the entity's exposure within cybersecurity threat landscapes. No specific incident details, such as data stolen or ransom demands, are included per strict factual boundaries. This listing serves as a neutral record of the entity's status in threat-intelligence indexing. |
||||||
| Ransomware | MAMMUT.COM id32624 View details | Switzerland | Manufacturing / Engineering | — | ||
|
MAMMUT.COM operates within the Manufacturing and Engineering sector and is associated with the country CH. As a ransomware victim, it appears in this threat-intelligence index under the threat actor clop, reflecting cybersecurity exposure within industrial and technical domains. The entity is documented neutrally to support threat monitoring, sector risk assessment, and defensive intelligence workflows for organizations and defenders monitoring industrial cyber threats. No specific incident details, such as data stolen, ransom demands, or breach confirmation, are included per strict factual constraints. MAMMUT.COM was listed as a ransomware victim associated with clop. |
||||||
| Ransomware | MAMMUT.COM id32625 View details | Switzerland | Manufacturing / Engineering | — | ||
|
MAMMUT.COM operates within the Manufacturing and Engineering sector and is associated with the country CH. As a ransomware victim entity indexed by this threat-intelligence catalog, it reflects incidents where cyber threats targeted organizations in industrial and technical domains. The entity's inclusion aligns with threat actor clop activity, providing context for security researchers and defenders monitoring ransomware campaigns across critical sectors. This listing serves as a factual reference point within the intelligence index, documenting the relationship between the entity, its operational sector, geographic context, and the associated threat actor without disclosing unverified incident details. It was listed as a ransomware victim associated with clop. |
||||||
| Ransomware | MAMMUT.COM id32625 View details | Switzerland | Manufacturing / Engineering | — | ||
|
MAMMUT.COM is a domain identifier associated with a victim entity operating within the Manufacturing and Engineering sector, based in China (CH). The domain represents an organization whose infrastructure was impacted under the classification of a ransomware victim within the threat-intelligence index. The associated threat actor identified for this listing is clop, a group noted for targeting industrial and engineering environments. This entry documents the entity's status and contextual data for analytical catalog purposes without disclosing confirmed incident details. It was listed as a ransomware victim associated with clop. |
||||||
| Ransomware | MAMMUT.COM id32628 View details | Switzerland | Manufacturing / Engineering | — | ||
|
MAMMUT.COM operates within the Manufacturing and Engineering sector and is associated with the country CH. The entity functions as a digital presence within industrial and technical domains, serving operational and technical purposes relevant to its sector. In the threat-intelligence index, MAMMUT.COM is cataloged specifically as a ransomware victim, with its incident profile directly associated with the threat actor clop. This listing type indicates documented exposure to ransomware activity within the entity's context. The entry provides neutral, factual context regarding the entity's classification, sector, geographic origin, and verified threat actor linkage without speculating on unconfirmed incident details. |
||||||
| Ransomware | MAMMUT.COM id32628 View details | Switzerland | Manufacturing / Engineering | — | ||
|
MAMMUT.COM operates within the Manufacturing and Engineering sector and is associated with the country CH. The entity is cataloged as a ransomware victim linked to the clop threat actor group. Threat-intelligence indexing captures such victim profiles to support risk awareness, sector-specific threat analysis, and defensive intelligence across industrial and engineering environments. This listing reflects the association without disclosing unverified incident details such as stolen data, ransom terms, or confirmed breach specifics. MAMMUT.COM was listed as a ransomware victim associated with clop. |
||||||
| Ransomware | MAMMUT.COM id32629 View details | Switzerland | Manufacturing / Engineering | — | ||
|
MAMMUT.COM operates within the Manufacturing and Engineering sector and is associated with the country CH. As a ransomware victim entity, it appears in this threat-intelligence index with the linked threat actor clop. The listing type identifies MAMMUT.COM specifically as a victim affected by ransomware activity attributed to clop. No additional incident specifics such as data stolen, records accessed, ransom demands, or confirmed breach details are provided here to maintain factual accuracy and neutrality. This entry serves catalog and intelligence purposes for monitoring threat actor activity and victim profiles across sectors and geographies. |
||||||
| Ransomware | MAMMUT.COM id32629 View details | Switzerland | Manufacturing / Engineering | — | ||
|
MAMMUT.COM operates within the Manufacturing and Engineering sector and is situated in China (CH). The domain represents an organization whose infrastructure was impacted by a ransomware incident, as documented in this threat-intelligence catalog. The entity is specifically cataloged as a ransomware victim linked to the threat actor clop, reflecting the cybersecurity context surrounding its exposure. This listing provides neutral, factual context for security professionals monitoring industrial-sector threats and associated adversary activity. No specific incident details, such as stolen data or ransom terms, are asserted here; the entry focuses solely on the entity's classification and its association. |
||||||
| Ransomware | MAMMUT.COM id32630 View details | Switzerland | Manufacturing / Engineering | — | ||
|
MAMMUT.COM is cataloged as a ransomware victim within the Retail and E-commerce sector, operating from the country of China (CH). The entity represents an organization whose digital infrastructure was impacted by a cyber incident associated with the threat actor clop. This listing type identifies the relationship between MAMMUT.COM and the malicious activity attributed to clop without disclosing unconfirmed technical details, data exfiltration specifics, or financial impact. The description remains neutral and factual, focusing on the entity's sector, geographic context, listing classification, and verified threat-actor association within the threat-intelligence index framework. |
||||||
| Ransomware | MAMMUT.COM id32630 View details | Switzerland | Manufacturing / Engineering | — | ||
|
MAMMUT.COM operates within the Manufacturing and Engineering sector and is situated in China (CH). The domain represents an organization subject to threat-intelligence indexing due to its association with a ransomware incident. Its inclusion reflects verified intelligence linking the entity to the clop threat actor group. This listing type categorizes MAMMUT.COM specifically as a ransomware victim within the threat-intelligence catalog. The description adheres to neutral, authoritative reporting standards without attributing unconfirmed details. MAMMUT.COM was listed as a ransomware victim associated with clop. |
||||||
| Ransomware | MAMMUT.COM id32635 View details | Switzerland | Manufacturing / Engineering | — | ||
|
MAMMUT.COM operates within the Manufacturing and Engineering sector and is situated in China (CH). The entity functions as a commercial organization whose infrastructure was identified as a ransomware victim within threat-intelligence records. The association with threat actor clop indicates that clop was linked to an attack targeting this organization, though specific technical or operational details of the incident remain outside verified public disclosures. This entry provides contextual information for security professionals assessing cyber risks across industrial sectors and geographic regions. MAMMUT.COM was listed as a ransomware victim associated with clop. |
||||||
| Ransomware | MAMMUT.COM id32635 View details | Switzerland | Manufacturing / Engineering | — | ||
|
MAMMUT.COM operates within the Manufacturing and Engineering sector and is associated with the country CH. The domain represents an organization whose infrastructure was impacted by a cyber incident, specifically categorized within this threat-intelligence index as a ransomware victim. The association with the threat actor clop indicates the operational profile and attack context relevant to this entity's security event. This listing provides a factual reference point for cataloging the entity's exposure within the ransomware threat landscape. MAMMUT.COM was listed as a ransomware victim associated with clop. |
||||||
| Ransomware | MAMMUT.COM id32637 View details | Switzerland | Manufacturing / Engineering | — | ||
|
MAMMUT.COM operates within the Manufacturing and Engineering sector and is associated with the Swiss country CH. The domain represents an organization cataloged in the threat-intelligence index under the ransomware victim listing type, with the associated threat actor identified as clop. This entry documents the entity's presence within cybersecurity threat datasets without disclosing specific incident details, operational data, or confirmed breach specifics. The classification reflects the observed relationship between the entity and the clop threat actor group as reported in intelligence sources. MAMMUT.COM was listed as a ransomware victim associated with clop. |
||||||
| Ransomware | MAMMUT.COM id32637 View details | Switzerland | Manufacturing / Engineering | — | ||
|
MAMMUT.COM operates within the manufacturing and engineering sector and is associated with Switzerland. As a ransomware victim, the entity is documented within this threat-intelligence index to reflect cybersecurity exposure and incident context tied to the threat actor clop. The listing provides neutral catalog information regarding the organization's sector, geographic context, and relationship to the identified threat actor without disclosing unverified incident details. This entry supports security teams in understanding organizational risk patterns and evolving cyber threats in industrial sectors. |
||||||
| Ransomware | MAMMUT.COM id32638 View details | Switzerland | Manufacturing / Engineering | — | ||
|
MAMMUT.COM operates within the Manufacturing and Engineering sector and is associated with the country CH. The entity is cataloged in this threat-intelligence index specifically as a ransomware victim linked to the threat actor clop. The listing reflects the cybersecurity event context in which MAMMUT.COM was impacted, providing structured intelligence for defenders and analysts monitoring industrial and engineering environments against coordinated cyber threats. No specific incident details such as data stolen, ransom demands, or breach confirmations are included to maintain factual neutrality and avoid speculation beyond the verified classification. |
||||||
| Ransomware | MAMMUT.COM id32638 View details | Switzerland | Manufacturing / Engineering | — | ||
|
MAMMUT.COM operates within the Manufacturing and Engineering sector and is associated with the threat actor clop in threat-intelligence records. As a ransomware victim, the entity's profile reflects an incident involving cyber intrusion and potential operational disruption within its industry context. The organization's location in Switzerland (CH) aligns with regional regulatory and sector-specific threat landscapes. This listing type documents the entity's status as a victim of ransomware activity linked to clop, without disclosing unverified incident details such as data exfiltration specifics or ransom terms. Neutral cataloging ensures factual alignment with available intelligence sources. |
||||||
| Ransomware | MAMMUT.COM id32639 View details | Switzerland | Manufacturing / Engineering | — | ||
|
MAMMUT.COM operates within the Manufacturing and Engineering sector and is associated with the country CH. The entity is cataloged as a ransomware victim in this threat-intelligence index, with the associated threat actor identified as clop. This listing reflects the cybersecurity context surrounding the entity's involvement with this specific threat actor profile, providing neutral reference points for threat analysts monitoring industrial sector vulnerabilities. No incident specifics such as data stolen, ransom demands, or breach confirmation details are included per strict factual constraints. The entry serves to document the relationship between this entity, its sector and geographic context, and the ransomware threat actor clop. |
||||||
| Ransomware | MAMMUT.COM id32643 View details | Switzerland | Manufacturing / Engineering | — | ||
|
MAMMUT.COM operates within the Manufacturing and Engineering sector and is associated with the country CH. The entity is cataloged as a ransomware victim in the threat-intelligence index, with the associated threat actor and source identified as clop. This listing reflects the organization's status following an incident attributed to this specific cyber threat actor group. The description remains neutral regarding unconfirmed details, focusing solely on the entity's classification, sector context, geographic origin, and the verified association with clop as a ransomware victim. |
||||||
| Ransomware | MAMMUT.COM id32643 View details | Switzerland | Manufacturing / Engineering | — | ||
|
MAMMUT.COM operates within the Manufacturing and Engineering sector and is situated in China (CH). The domain represents an organization whose infrastructure was impacted by a cyber incident categorized as ransomware victimization. The entity is formally cataloged within this threat-intelligence index as a ransomware victim linked to the clop threat actor group. This listing type indicates observed or attributed malicious activity targeting the organization's digital environment, consistent with clop's operational profile in industrial sectors. The entry provides neutral context for threat researchers and defenders assessing risk exposure in manufacturing and engineering environments. |
||||||
| Ransomware | MAMMUT.COM id32643 View details | Switzerland | Manufacturing / Engineering | — | ||
|
MAMMUT.COM operates within the Manufacturing and Engineering sector and is associated with the country CH. The entity is cataloged in this threat-intelligence index as a ransomware victim, with the associated threat actor and source identified as clop. This listing reflects the cybersecurity posture and incident classification observed in relation to the organization's sector and geographic context. The description remains neutral regarding specific incident details, as confirmed specifics such as data exfiltration scope or operational impact are not publicly verified for this entity. MAMMUT.COM was listed as a ransomware victim associated with clop. |
||||||
| Ransomware | MAMMUT.COM id32645 View details | Switzerland | Manufacturing / Engineering | — | ||
|
MAMMUT.COM operates within the Manufacturing and Engineering sector and is associated with the threat actor clop. As a ransomware victim, this entity appears in the threat-intelligence index to document cybersecurity incident exposure within its geographic and industry context. The listing type identifies MAMMUT.COM specifically as a ransomware victim connected to clop, providing catalog-level awareness without disclosing unconfirmed incident details. This entry supports threat-intelligence analysis for entities in CH facing ransomware activity tied to clop, emphasizing sector relevance and geographic attribution. |
||||||
| Ransomware | MAMMUT.COM id32645 View details | Switzerland | Manufacturing / Engineering | — | ||
|
MAMMUT.COM operates within the Manufacturing and Engineering sector and is associated with the country CH. The entity appears in the threat-intelligence index specifically as a ransomware victim, with the associated threat actor identified as clop. This listing type indicates observed malicious activity targeting the organization, contextualized within broader cyber threat monitoring efforts. The description remains neutral regarding specific incident details, as confirmed specifics such as data exfiltration scope, ransom demands, or precise breach timelines are not provided in available intelligence. MAMMUT.COM serves as a reference point for understanding clop's targeting patterns within industrial sectors across CH. |
||||||
| Ransomware | MAMMUT.COM id32645 View details | Switzerland | Manufacturing / Engineering | — | ||
|
MAMMUT.COM operates within the Manufacturing and Engineering sector and is documented as a ransomware victim within this threat-intelligence index. The entity is associated with the clop threat actor group, with operational context linked to the country CH. The listing type identifies MAMMUT.COM specifically as a ransomware victim, reflecting its inclusion in cyber threat intelligence records tied to this actor. No additional incident specifics, such as data stolen, record counts, ransom amounts, or confirmed breach details, are provided here to maintain factual neutrality and avoid speculation beyond the verified association. This entry serves as authoritative catalog copy for tracking threat actor activity and victim exposure across industrial sectors. |
||||||
| Ransomware | MAMMUT.COM id32645 View details | Switzerland | Manufacturing / Engineering | — | ||
|
MAMMUT.COM operates within the Manufacturing and Engineering sector and is situated in China (CH). The entity is cataloged as a ransomware victim linked to the threat actor clop. This listing provides threat-intelligence context regarding the organization's sector profile, geographic origin, and the ransomware-related association with clop for monitoring and analysis purposes. No specific incident details, breach confirmations, stolen data, ransom terms, or record counts are included, as per strict factual boundaries. The entry serves as a neutral reference point within the threat-intelligence index for entities affected by cyber incidents involving identified actors. |
||||||
| Ransomware | MAMMUT.COM id32645 View details | Switzerland | Manufacturing / Engineering | — | ||
|
MAMMUT.COM operates within the retail and e-commerce sector and is cataloged as a ransomware victim in the threat-intelligence index. The entity is associated with the threat actor clop, with operational context linked to the country CH. The listing type identifies MAMMUT.COM specifically as an organization impacted by ransomware activity, providing cyber-threat-intelligence analysts with sector, geographic, and actor-related context for monitoring and risk assessment. No incident specifics such as data stolen, records accessed, ransom demands, or breach confirmation details are included in this description. MAMMUT.COM was listed as a ransomware victim associated with clop. |
||||||
| Ransomware | MAMMUT.COM id32645 View details | Switzerland | Manufacturing / Engineering | — | ||
|
MAMMUT.COM operates within the Manufacturing and Engineering sector and is associated with the country CH. The domain represents an organization whose infrastructure was impacted by a ransomware incident, documented within threat-intelligence indexing frameworks. As a ransomware victim linked to the threat actor clop, this entry captures the entity's exposure profile and sector relevance for security analysts. The listing reflects verified intelligence concerning this specific entity's association with the identified threat actor and its operational context in industrial sectors. |
||||||
| Ransomware | MAMMUT.COM id32645 View details | Switzerland | Manufacturing / Engineering | — | ||
|
MAMMUT.COM operates within the Manufacturing and Engineering sector and is associated with the country CH. The entity is cataloged as a ransomware victim in this threat-intelligence index, with the associated threat actor and source identified as clop. The listing provides context on the organization's sector, geographic origin, and its documented relationship to this specific cyber threat actor without disclosing unverified incident details. This entry serves to inform security analysts and stakeholders about the entity's presence within ransomware-related intelligence datasets. MAMMUT.COM was listed as a ransomware victim associated with clop. |
||||||
| Ransomware | MAMMUT.COM id32645 View details | Switzerland | Manufacturing / Engineering | — | ||
|
MAMMUT.COM operates within the Manufacturing and Engineering sector and is associated with the country CH. The entity is cataloged as a ransomware victim, with the threat actor clop identified as the associated source in the threat-intelligence index. This listing type indicates that MAMMUT.COM was affected by ransomware activity attributed to clop, providing context for cybersecurity analysts monitoring industrial and engineering sector threats. The description remains factual and neutral, focusing on the entity's sector, geographic context, listing classification, and linked threat actor without speculating on unconfirmed incident details. It was listed as a ransomware victim associated with clop. |
||||||
| Ransomware | MAMMUT.COM id32645 View details | Switzerland | Manufacturing / Engineering | — | ||
|
MAMMUT.COM operates within the Manufacturing and Engineering sector and is associated with Switzerland. As cataloged in this threat-intelligence index, the entity is classified as a ransomware victim connected to the threat actor clop. The listing provides structured context regarding the organization's sector, geographic origin, and the nature of its cybersecurity event without disclosing unverified technical findings or incident specifics. This entry supports threat-intelligence workflows by documenting the relationship between the entity, its operational domain, and the identified threat actor for monitoring and defense purposes. |
||||||
| Ransomware | MAMMUT.COM id32645 View details | Switzerland | Manufacturing / Engineering | — | ||
|
MAMMUT.COM is cataloged as a ransomware victim within the Manufacturing and Engineering sector, with operational ties to the country CH. The entity represents a compromised organization whose infrastructure was targeted by the threat actor clop, contributing critical intelligence for threat-index analysis and sector-specific risk assessment. This listing type identifies the entity's status as a victim of ransomware activity, providing context for monitoring cyber threats in industrial and engineering environments. The entry reflects the association with clop without disclosing unverified incident details such as data stolen, ransom demands, or specific breach timelines. MAMMUT.COM serves as a reference point for understanding ransomware impacts across manufacturing and engineering sectors in the specified geographic region. |
||||||
| Ransomware | MAMMUT.COM id32646 View details | Switzerland | Manufacturing / Engineering | — | ||
|
MAMMUT.COM operates within the Manufacturing and Engineering sector and is associated with the threat actor clop. As cataloged in this threat-intelligence index, it is designated as a ransomware victim entity. The entity's sector focus suggests operational technology and industrial engineering contexts where cyber threats can impact production systems and supply chains. This listing reflects verified intelligence linking MAMMUT.COM to clop activity without disclosing unconfirmed incident details. Its inclusion underscores ongoing monitoring of ransomware incidents across manufacturing and engineering sectors in CH. |
||||||
| Ransomware | MAMMUT.COM id32646 View details | Switzerland | Manufacturing / Engineering | — | ||
|
MAMMUT.COM operates within the Manufacturing and Engineering sector and is located in Switzerland (CH). The domain is cataloged as a ransomware victim within a threat-intelligence index, explicitly associated with the threat actor clop. No specific incident details such as data exfiltration scope, ransom demands, or breach confirmation are included to maintain factual neutrality. This listing serves to document the entity's status and its connection to identified cyber threats affecting industrial and engineering sectors. MAMMUT.COM was listed as a ransomware victim associated with clop. |
||||||
| Ransomware | MAMMUT.COM id32647 View details | Switzerland | Manufacturing / Engineering | — | ||
|
MAMMUT.COM operates within the Manufacturing and Engineering sector and is situated in China (CH). As a ransomware victim, the entity is cataloged in this threat-intelligence index due to its association with the threat actor clop. The listing type reflects the nature of the threat event linked to this organization, providing context for cybersecurity professionals assessing active threats in industrial and engineering environments. No specific incident details such as data stolen, ransom demands, or breach confirmation are included to maintain factual neutrality and avoid speculative claims. This entry serves as a verified reference point within the intelligence catalog for monitoring threat actor activity and sector-specific risks. |
||||||
| Ransomware | MAMMUT.COM id32648 View details | Switzerland | Manufacturing / Engineering | — | ||
|
MAMMUT.COM operates within the Manufacturing and Engineering sector and is associated with the country CH. The entity functions as a ransomware victim within the threat-intelligence index catalog. Its inclusion reflects documented intelligence linking MAMMUT.COM to the threat actor clop, which has targeted organizations across industrial sectors. The listing provides neutral context for researchers and defenders assessing ransomware patterns in manufacturing and engineering environments. No specific incident details, such as data stolen or ransom demands, are included per strict factual boundaries. |
||||||
| Ransomware | MAMMUT.COM id32649 View details | Switzerland | Manufacturing / Engineering | — | ||
|
MAMMUT.COM operates within the Manufacturing and Engineering sector and is associated with the country CH. The entity is cataloged as a ransomware victim in this threat-intelligence index, with the associated threat actor and source identified as clop. The listing reflects the cybersecurity community's documentation of this entity's involvement in a ransomware incident without disclosing unverified technical or operational details. This entry serves to inform analysts tracking threat actor activity, victim profiles, and sector-specific exposure patterns in industrial and engineering environments. MAMMUT.COM was listed as a ransomware victim associated with clop. |
||||||
| Ransomware | MAMMUT.COM id32650 View details | Switzerland | Manufacturing / Engineering | — | ||
|
MAMMUT.COM operates within the retail and e-commerce sector, with operational context linked to Switzerland (CH). As cataloged in this threat-intelligence index, the entity is designated as a ransomware victim connected to the clop threat actor group. The listing provides structured context regarding the organization's sector, geographic association, and the nature of its involvement with this specific cyber threat actor without disclosing unverified incident details. This entry supports threat analysts, security teams, and compliance stakeholders in mapping ransomware incidents across sectors and geographies. MAMMUT.COM was listed as a ransomware victim associated with clop. |
||||||
| Ransomware | MAMMUT.COM id32650 View details | Switzerland | Manufacturing / Engineering | — | ||
|
MAMMUT.COM operates within the Retail and E-commerce sector and is associated with the country CH. The domain functions as a commercial entity serving retail and online commerce activities, though specific operational details remain limited within public threat-intelligence records. This listing type identifies MAMMUT.COM as a ransomware victim connected to the threat actor clop. The entry provides contextual coverage for security professionals monitoring retail infrastructure threats, attacker campaigns, and regional cyber incidents affecting e-commerce environments. No further incident specifics, such as data stolen, ransom terms, or confirmed breach details, are included to maintain factual neutrality. |
||||||