ShinyHunters hack rival Clop ransomware gang and leak site on the Dark Web

The financially motivated extortion group ShinyHunters has breached and defaced the Tor-based data leak site operated by the Clop ransomware gang, escalating a simmering feud into an outright attack on rival criminal infrastructure.[1][7][9] Multiple outlets report that the attackers say they gained access by abusing an unauthenticated file upload vulnerability in the Grav content management system that powers Clop’s leak portal.[1][5][7]

Reporting indicates the intrusion began around the night of September 18–19, 2026, when ShinyHunters first placed a taunting text file on the hidden service before fully replacing the homepage with an Umbreon-themed defacement referencing the group’s persona.[2][6][8] BleepingComputer and other observers verified that Clop’s leak site was taken over and its usual victim listing content replaced by the ShinyHunters message, confirming at least the visible compromise of the gang’s Tor infrastructure.[2][9][11]

In messages shared with journalists and detailed in subsequent coverage, ShinyHunters claims it obtained “full access” to Clop’s server, including leak site source code, Grav CMS plugins, system logs, database contents, and the cryptographic private keys for the operation’s onion service.[3][5][10] If accurate, possession of those keys would allow the attackers to impersonate Clop’s dark-web address or permanently deny them control of the existing service, turning the traditional ransomware extortion model back on its operators.[3][4][7] However, several reports note that while the defacement is independently confirmed, the alleged theft of server data and Tor private keys has not yet been verified by a second source, and remains an unproven claim at the time of writing.[2][6][8]

ShinyHunters itself is profiled as a long-running, financially driven cybercrime collective active since at least 2019, known for large-scale data exfiltration and extortion campaigns against enterprise platforms and cloud services.[12][13] Threat intelligence firms say the brand now operates within a broader Scattered LAPSUS$ Hunters alliance alongside actors such as Scattered Spider and LAPSUS$, coordinating overlapping intrusion campaigns.[14] Clop, meanwhile, is a well-established ransomware and data-theft operation whose leak site has been central to naming victims and pressuring organizations into paying, making the takedown of this infrastructure a symbolic blow inside the criminal ecosystem.[7][9][15]

Technically, the incident underscores ongoing risks around Grav CMS deployments and similar flat-file content management systems when file upload functionality is exposed without strong authentication or validation controls.[1][5][7] Public reporting so far has described the flaw only as an “unauthenticated arbitrary file upload” issue, and has not tied it to a specific CVE identifier, NVD entry, or vendor advisory, suggesting the bug may be a zero-day or a misconfiguration rather than a widely tracked vulnerability.[1][2][8] In the absence of a documented CVSS score or patch bulletin, defenders running Grav-backed sites must treat the attack as a warning that any unauthenticated upload surface on their infrastructure could be leveraged for remote code execution or full system compromise.[5][7][10]

For organizations, the fact that cybercriminals are now weaponizing web application flaws against one another should be viewed less as schadenfreude and more as proof that these same weaknesses are actively exploitable in production environments.[3][7][9] Security teams operating Grav or comparable CMS platforms should inventory all upload endpoints, enforce strict authentication and content-type validation, isolate CMS instances from critical data stores, and monitor for anomalous file writes and process execution on web servers, hardening their environments before the techniques showcased in this intra-criminal feud are reused against legitimate targets.[5][7][14]

References

  1. ShinyHunters hacks Clop ransomware gang and threatens to extort it
  2. ShinyHunters Defaces Clop Leak Site, Tor Key Theft Unproven
  3. ShinyHunters hacks Clop leak site, threatens to extort…
  4. ShinyHunters says it hijacked Cl0p’s dark web leak site – TNW
  5. ShinyHunters Hacks Clop Ransomware Leak Site in Dark …
  6. ShinyHunters Defaces Clop Leak Site: Cybercrime Feud Goes Public | DeafNews
  7. ShinyHunters Rooted Clop’s Leak Site Through Grav CMS, and …
  8. ShinyHunters Defaces Clop Leak Site and Claims Theft of Onion …
  9. ShinyHunters Hacks Clop Leak Site, Threatens to Extort Rival Ransomware Gang
  10. ShinyHunters Hacks Clop Ransomware Leak Site and Blackmails the Gang – Hitechub
  11. Dark Web Search: ShinyHunters Targets Clop Leak Site
  12. ShinyHunters: Threat Actor Profile | BreachNews
  13. ShinyHunters Threat Actor Profile: TTPs, IoCs & Attacks
  14. Are You Exposed to ShinyHunters?
  15. Latest Clop news – Bleeping Computer

Comments

No comments yet. Why don’t you start the discussion?

Leave a Reply