One of the world’s most notorious cybercrime groups has said it took over the dark web infrastructure of a rival gang, turning a long-running feud between the two operations into an unusually public showdown.
The hacking group ShinyHunters told Reuters on Sunday that it had broken into rival group cl0p’s site two days earlier after finding a vulnerability in the rival group’s software and using it to seize control of its systems. “We basically own them now,” ShinyHunters said in an online chat with Reuters.
Cl0p did not respond to repeated requests from Reuters for comment. Its dark web page was unreachable when Reuters tried to visit it on Sunday, though on Saturday it displayed the message “Domain Seized By ShinyHunters,” according to a screenshot kept by the cybercrime research platform eCrime.ch.
Two security experts told Reuters the dispute appeared authentic. Brandon Parsons, a threat intelligence manager at Minnesota-based Ascent Solutions, said clashes between criminal groups on the dark web are a genuine phenomenon. Joe Roosen, senior director of security research at Texas-based SpyCloud, said he had never seen one group confront another so openly. “This was a twist for sure,” he said. “It is rare I get to see these criminals fight each other.”
According to ShinyHunters, the two groups fell out over the alleged theft last year of an exploit targeting a then-unknown flaw in Oracle’s E-Business Suite. Such vulnerabilities, known as zero days because defenders have no time to patch them, are prized by attackers for the sweeping access they can provide. Cl0p, a Russian-speaking operation, used the flaw to steal data from what a Google analyst estimated was more than 100 companies, though ShinyHunters claims it found the vulnerability first.
The dispute escalated, with cl0p said to have threatened to expose the identities of several ShinyHunters members, prompting its rival to threaten releasing details of cl0p’s internal operations. Reuters could not immediately verify ShinyHunters’ account of the feud.
Both groups have built reputations for high-volume attacks. Cl0p exploited a flaw in MOVEit file transfer software in 2023 to steal data on tens of millions of people from more than 600 companies, and last month claimed to have taken large volumes of data from nearly 50 organisations worldwide, including Philips, Shell, Fiserv, and GE. ShinyHunters drew attention in April after claiming to have stolen millions of business records from Rockstar Games, and in May for an attack on the education tool Canvas that disrupted schools across the United States. This month, AI company Anthropic said it had caught hackers linked to ShinyHunters attempting to use its tools.
Click Here For The Original Source.
