ShinyHunters apparently breached rival ransomware gang Clop last week, and the incident could pose additional risks to victim organizations caught in the middle.
ShinyHunters is a financially motivated cybercrime group known primarily for data theft and extortion attacks. The group's identity has become increasingly fluid, with researchers observing ties to and collaboration with cybercriminals associated with the Scattered Spider and Lapsus$ collectives.
Clop, meanwhile, is a notorious ransomware gang best known for large-scale data extortion campaigns, particularly involving zero-day vulnerabilities. Clop actors were behind the massive 2023 campaign that exploited a zero-day in Progress Software's MOVEit file transfer software, as well as a similar campaign that targeted a Fortra GoAnywwhere flaw that same year.
Over the weekend, ShinyHunters defaced Clop's Dark Web data leak site with a message: "DOMAIN SEIZED BY SHINYHUNTERS." As first reported by BleepingComputer, ShinyHunters claimed the attack began on Friday night when it exploited an unauthenticated file upload vulnerability in the Grav CMS used by Clop's leak site.
Related:Cybercriminals Are Hiding New Malware in Torrents for Popular Films
ShinyHunters vs. Clop: Cybercrime Feud
ShinyHunters claimed it obtained full access to Clop's leak site server and stole source code, Grav CMS plug-ins, system logs, private keys for its Onion service, and other data. Those data-theft claims have not been independently verified.
The attackers continued to leave messages on Clop's site taunting the ransomware group and attempting to extort it. On Sept. 19, a message attributed to ShinyHunters demanded an unspecified eight-figure payment in Bitcoin and directed Clop to contact an Onionmail address.
On Sept. 20, the attackers wrote on Clop's page, "I want all the money you made off the EBS campaign plus more AND WITH INTEREST, before I start releasing information regarding the companies that paid you, how much, and to what Bitcoin address."
The reference to "EBS" likely references Clop's extortion campaign targeting customers affected by the critical Oracle E-Business Suite (EBS) zero-day vulnerability CVE-2025-61882 last fall. Public feuds and attacks between cybercriminal groups aren't uncommon; earlier this year, two emerging ransomware groups, 0APT and KryBit, hacked one another and leaked internal data.
... continue reading