MITRE ATT&CK G0088
Aliases: TA505, FIN11, Lace Tempest
Official Attribution Source: CISA Advisory AA23-158A (MOVEit Campaign)

Key Facts

Jurisdiction
Russian Federation
Geographic origin
Cases
0
Prosecution matters
Defendants
0
Indicted individuals
Sanctions
0
OFAC designations
  • Attributed Country: Russian Federation.
  • ATT&CK Group Reference: G0088 (CL0P).
  • Linked to 0 primary court prosecution records.
  • Identified 0 individually charged operatives.

Prosecution Cases Attributed to This Actor

OPERATIONAL DEFENSE

Targeted Defensive Hardening for CL0P

Run Stack Audit →

Primary Initial Access Defense

Enforce hardware FIDO2 multi-factor authentication across all perimeter VPN, Citrix, and cloud data portals. Prohibit SMS or push-based MFA that can be bypassed via vishing or SIM swapping.

Lateral Movement Interception

Restrict internal SMB (port 445) and RPC traversal between workstation subnets. Implement tiered Active Directory administration so domain administrator credentials are never cached on endpoints.