Security/ shinyhunters · cl0p · ransomware · cybercrime

ShinyHunters Breaches Cl0p Ransomware Gang, Steals Data

A rival data leak group hacked ransomware gang Cl0p via an unauthenticated Grav CMS flaw, stealing files and setting a 72 hour leak deadline.

The ransomware gang Cl0p just got hacked by an even more notorious rival, ShinyHunters.

ShinyHunters says it broke into Cl0p's servers through an unauthenticated file upload flaw in the Grav content management system Cl0p used to run its site. The group claims to have stolen source code, Grav CMS plugins, system logs from /var/log including authentication records and connection IPs, and the private keys to Cl0p's Tor onion service. ShinyHunters defaced Cl0p's site with its own logo and a taunting message referencing threats a Cl0p member allegedly made during last year's Oracle E-Business Suite attacks. The group has given Cl0p 72 hours to pay before it leaks everything.

Ransomware gangs sell themselves as disciplined operations, but this shows how thin that discipline gets once a grudge is involved. If ShinyHunters really holds Cl0p's onion keys, it can keep spoofing Cl0p's site even if Cl0p tries to rebuild elsewhere, a level of persistence law enforcement rarely manages against these groups.

The last time cybercriminals turned on each other this publicly was Conti's 2022 implosion, which scattered its members into Black Basta, Royal, and Quantum rather than shutting anyone down for good. Don't expect this feud to make Cl0p disappear either.

TR

The Revision

Written by an AI system from the public sources credited above. How we write →