Attack Overview
VICTIM
DP World
INDUSTRY
Transportation
LOCATION
United Arab Emirates
ATTACKER
Clop
FIRST REPORTED
March 23, 2023

The Cl0p Ransomware Gang's Attack on DP World

The Cl0p ransomware gang has attacked DP World. DP World is a multinational logistics organization headquartered in Dubai, UAE. It employs more than 100,000 people and was founded in 2005. Cl0p posted DP World to its data leak site on March 24th but did not provide any further information.

Understanding Cl0p's Threat

Cl0p is a major Ransomware-as-service (RaaS) platform first observed in 2019. Cl0p is a dangerous ransomware family because it has advanced anti-analysis capabilities and anti-virtual machine analysis to prevent investigations in an emulated environment like those commonly used by security tools. Cl0p is one of just a handful of threat actors that have developed a Linux version.

While Linux has a tiny footprint in desktop computing, it runs ~80% of web servers and a substantial portion of embedded devices used in the healthcare field – and this means that Cl0p is likely actively recruiting new talent to help improve their platform and expand the scope of what and whom they can attack.

Cl0p's Expanding Threat

Cl0p also exfiltrates data to be leveraged in double extortion schemes and has recently claimed responsibility for attacks against over 130 organizations – some outside the healthcare sector - using a zero-day vulnerability in secure file transfer software GoAnywhere MFT.

Disclaimer

The Halcyon Attacks Lookout Database is compiled using publicly available information based on the hosting choices of real-world threat actors and data from a variety of trackers. This information is provided in accordance with principles of fair use. Halcyon has made reasonable efforts to sanitize and verify the data; however, we do not guarantee the accuracy, completeness, or reliability of the information provided. Updates to the database are made as new source data becomes available from reputable sources.  By accessing, viewing, or using the information within the Halcyon Attacks Lookout Database, you acknowledge and agree to do so entirely at your own risk. No reliance should be placed upon the information for decision-making, and Halcyon disclaims all liability for any inaccuracies or omissions in the data.

See Halcyon in action

Interested in getting a demo?
Fill out the form to meet with a Halcyon Anti-Ransomware Expert!

1
2
3
Let's get started
1
1
2
3
1
1
2
2
3
Back
Next
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.