Skip to content
Tech News
← Back to articles

ShinyHunters hacks Clop leak site, threatens to extort ransomware gang

read original more articles
Why This Matters

This incident is notable because it shows even cybercriminal infrastructure is vulnerable to rival hackers, undermining the perceived operational security of ransomware gangs like Clop. It highlights ongoing turf wars within the cybercrime ecosystem, which could disrupt extortion operations and expose sensitive victim data to further misuse.

Key Takeaways

The ShinyHunters extortion gang breached the Clop (aka Cl0p) ransomware operation's data leak site, defacing the Tor site and allegedly stealing server data and the private keys for its onion service.

The attack began Friday night when ShinyHunters exploited what they claim is an unauthenticated file upload vulnerability in Grav CMS, which they used to upload a small text file to Clop's site.

File downloaded from Clop's data leak site

Source: BleepingComputer

The small text file contained a message from the threat actors to the Clop ransomware gang, warning not to threaten them and including a link to ShinyHunter's own data leak site.

"THIS SITE HAS BEEN PWN3D BY SHINYHUNTERES #Skids10p - Maybe don't try to threaten us next time," read the uploaded file.

File uploaded to Clop's data leak site

Source: BleepingComputer

The file also contained a link to the ShinyHunters data leak site.

BleepingComputer confirmed that the file had been uploaded to Clop's server and could be downloaded directly from the ransomware gang's Tor site.

... continue reading