started · updated
ShinyHunters hijacks Clop ransomware gang's dark web leak site
The cybercrime group ShinyHunters has reportedly hijacked the dark web leak site of the Clop ransomware gang, marking a rare and public confrontation between major criminal organizations.
ShinyHunters claims to have gained wide-ranging control over Clop’s infrastructure by exploiting an unauthenticated file upload vulnerability in Grav CMS. The attackers defaced Clop’s Tor site with ASCII art and messages stating, “Domain Seized By ShinyHunters.” Beyond defacement, ShinyHunters claims to have stolen sensitive data, including source code, Grav CMS plugins, system logs, and the private cryptographic keys for Clop’s Tor onion service.
The conflict appears to stem from a long-standing dispute regarding a zero-day exploit used in Clop’s previous campaigns targeting Oracle E-Business Suite. ShinyHunters alleges they discovered the vulnerability first and is now attempting to extort Clop, demanding an eight-figure payment and a public apology. The group has threatened to leak Clop’s files and identify companies that previously paid ransoms to the gang if their demands are not met.
Entities
Clop · E-Business Suite · Grav CMS · Oracle · ShinyHunters