Clop ransomware has returned after the recent arrests of gang members and has started reporting new victims on its data leak site.
Last week, Ukrainian police authorities, along with the Korean National Police Service and the US, arrested members of the Clop gang.
Learn more: Ukraine arrests members of Clop ransomware gang

A video shared by Ukrainian police shows authorities searching homes and seizing 500 million Ukrainian hryvnias (about $180,000), computer equipment, documents, and expensive cars (Tesla, Mercedes, etc.).
In a press release, Ukrainian police described the arrests as a significant blow against the operations of the Clop ransomware gang.
“Law enforcement authorities have managed to shut down the infrastructure from which the virus is spreading and block channels for the legalization of illegally obtained cryptocurrencies,” he said.
Clop ransomware returns
However, it appears that the Clop ransomware gang has taken action again, after publishing stolen data from two new victims on the data leak site it operates.
Cybersecurity firm Intel 471 said the gang continues operations despite the arrests of some members because the arrests mainly targeted the money laundering division of the business, while the key members of the group were likely not arrested.
“We do not believe that any key members of the CLOP ransomware group have been arrested and we believe they are likely living in Russia“.
See also: Bombardier: Clop ransomware group leaked company data!

Since this particular group has caught the attention of the authorities, it is possible that it will disappear for a while and reappear under a different name.
The Clop group seems to have made a quick comeback, but law enforcement has managed to crack down on several ransomware gangs this year, targeting partners and infrastructure.
Earlier this year, Bulgarian police seized servers belonging to the gang behind the Netwalker ransomware, and Ukrainian police arrested members of the Egregor ransomware group.
The FBI also arrested the developer of the TrickBot trojan, who was helping to develop a new ransomware operation.
A few words about the team
The Clop ransomware gang has been operating since March 2019. It began targeting businesses with a variant of the CryptoMix ransomware.
Typically, hackers gain access to a corporate computer and then slowly spread throughout the network, stealing data and documents. After collecting all the valuable data, they deploy ransomware on the network to encrypt its devices.
See also: Mysterious ransomware payment detected on RubRatings site
The Clop ransomware gang has been linked to attacks on Maastricht University, Software AG IT, ExecuPharm, and Indiabulls.
Ukrainian police estimate total losses related to Clop ransomware at $500 million.
Source: Bleeping Computer
