The US government is offering $10 million for tips about the Cl0p ransomware

TechSpot is celebrating its 25th anniversary. TechSpot means tech analysis and advice you can trust .

Why it matters: The US Department of State sent a new reward notice in its "Rewards for Justice" plan, asking for any information related to a dangerous malware that has been targeted federal and private organizations. People in the know, or even competing cyber-criminals, have a chance to win easy money - or be targeted by government investigators as well.

The $10 million reward promoted by the US government is for information useful to identify or locate any person involved in cyber-criminal activities while working for a foreign government. The Department of State says that such cyber-criminals have recently targeted US critical infrastructures in violation of the Computer Fraud and Abuse Act, and they are mostly involved in the Clop ransomware operation.

In the past few months, the Clop (or CL0P) malware has targeted systems that used the Moveit file transfer application , exploiting a previously unknown SQL injection vulnerability tracked as CVE-2023-34362. The FBI and Cybersecurity and Infrastructure Security Agency (CISA) have published a joint security advisory, providing affected organizations with recommended actions and mitigations to protect themselves against the 0-day flaw and the malware.

The Clop cyber-gang started to abuse the Moveit vulnerability on May 27th, just in time for the US Memorial Day holiday, seemingly stealing files from hundreds of private companies. According to CNN , the Clop ransomware was later used to breach several US federal agencies as well.

Advisory from @CISAgov , @FBI : https://t.co/jenKUZRZwt

Do you have info linking CL0P Ransomware Gang or any other malicious cyber actors targeting U.S. critical infrastructure to a foreign government?

Send us a tip. You could be eligible for a reward. #StopRansomware pic.twitter.com/fAAeBXgcWA

– Rewards for Justice (@RFJ_USA) June 16, 2023

As the government is now offering $10 million for any help to identify or catch the cyber-criminals, the attack was likely successful in compromising the Department of Energy and other federal agencies dealing with critical matters and infrastructures. Washington can get tips through secure chatting apps (Signal, WhatsApp, Telegram), or even via an encrypted link hosted inside Tor's darknet.

According to Bleeping Computer, the Clop cyber-gang has now begun the extortion phase for its latest wave of ransomware attacks by listing the compromised companies on a Tor data leak site. If the affected organizations won't pay the ransom, the note says, the stolen files will be leaked online.

The Clop cyber-criminals say they are not interested in politics, as they seemingly are only motivated by financial reasons. When their ransomware net catches some government data from exposed or unprotected systems, the unknown criminals state , they do the "polite thing" by deleting all the stolen files.

Like any other modern cyber-crime or ransomware operation, there is absolutely no reason to trust anything the Clop actors are saying. The US government is therefore acting on the assumption that the criminals have stolen sensible files, and that they need to identify them in order to effectively neutralize the threat.

Tech Jobs: Find the next step in your career

Related Stories

Featured on TechSpot