ShinyHunters has broken into the dark web leak site operated by the Clop ransomware gang, turning a dispute between two major cybercrime groups into a direct attack on criminal infrastructure. The extortion group defaced Clop’s Tor website and is now threatening to use information allegedly stolen from the server against its rival.

 

 

The attack began on Friday when ShinyHunters claims it discovered an unauthenticated file upload vulnerability in the Grav content management system used by Clop’s website. The group initially demonstrated access by placing a small file on the server containing a warning directed at Clop and a link to ShinyHunters’ own leak site.

Several hours later, the compromise became much more visible. Clop’s normal leak site was replaced with ShinyHunters branding, confirming that the attackers had gained enough access to modify the website rather than simply upload an isolated file.

ShinyHunters claims its access went considerably further. The group says it obtained source code, website plugins, system logs, and other internal files stored on the compromised server, although the theft of this information has not been independently confirmed.

The attackers also claim to have obtained private keys associated with Clop’s Tor onion service. If genuine, possession of those keys could potentially allow another operator to recreate the onion identity on different infrastructure, creating additional problems for a cybercrime group that relies on its dark web address to communicate with victims and publish stolen information.

Server logs could be particularly sensitive for Clop because they may contain records connected to activity on the website. ShinyHunters has suggested that information taken from the server could expose details about Clop’s operations, but exactly what the allegedly stolen logs contain has not been publicly verified.

The attack appears to be connected to an existing dispute between the two groups. ShinyHunters says Clop previously threatened to reveal the identities of some of its members, while ShinyHunters has now threatened to expose information about Clop’s infrastructure and internal operations.

The disagreement reportedly intensified over a previous campaign involving vulnerabilities in Oracle E-Business Suite. ShinyHunters claims it originally discovered a vulnerability that was later used by Clop during attacks against numerous organizations, although the competing accounts from the cybercrime groups cannot be independently established in full.

Clop has become one of the most prominent data-extortion operations through campaigns targeting widely used enterprise software. Its 2023 exploitation of a vulnerability in MOVEit Transfer affected hundreds of organizations, while the group has continued using vulnerabilities in corporate software to steal information and pressure victims into paying.

ShinyHunters has followed a somewhat different model in many recent attacks, focusing heavily on stealing corporate data and credentials before using the information for financial extortion. Security researchers have observed a broader shift among cybercriminal groups toward data theft without necessarily encrypting victims’ computers.

Direct attacks between established cybercrime groups are less common than attacks against companies and government organizations. In this case, the same type of pressure normally directed at corporate victims is being turned against another extortion operation, with potentially sensitive information being used as leverage.

Clop’s leak site was unavailable when Reuters attempted to access it on Sunday, while ShinyHunters publicly claimed that it had gained extensive control over the rival group’s infrastructure. Clop has not publicly responded to the allegations, and the claimed theft of its internal files and Tor private keys remains unverified.

Leave a Reply