Hacking the hackers: ShinyHunters breaches Clop ransomware site | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #ransomware


Cybercriminals do not only target companies and public institutions. They can also attack each other. Although some groups collaborate for their malicious activities and others emerge as small ‘offspring’ of larger collectives, it can also happen that two formations have their rivalry and even engage in relentless battles over victims, money, reputation, and other things.

This is what just happened between two of the most infamous bands in the ecosystem: ShinyHunters and Clop ransomware.

The first of them claims to have gained access to the server used by Clop for its leak site and manipulated it to place their own brand and a message directed at their rivals.

Among the displayed elements was an ASCII representation of the Pokémon Umbreon, associated with the identity of ShinyHunters, as well as a link to the group’s own Tor site.

Additionally, ShinyHunters also allegedly accessed various files and components of the ransomware group’s infrastructure.

“The data we stole includes source codes, GravCMS plugins, and other things. We are still downloading and reviewing them,” the collective commented to the cybersecurity information website BleepingComputer.

The threat actor also claims it is reviewing the obtained information and intends to use it to pressure Clop. Thus, they have given a 72-hour ultimatum. In this way, interestingly, they are following to the letter the modus operandi that ransomware bands usually carry out with their victims.

The ‘Pokémon hunters’ managed to exploit an unauthenticated file upload vulnerability in Grav CMS, the content management system used by the site. From there, they managed to introduce their own content and alter the page.

Furthermore, the attackers boast of having in their possession the private keys used by Clop’s Tor service. According to the hackers, possessing these keys would mean they could maintain control over the .onion address even if Clop tried to expel them from the server. The band claims they could use these keys to host the same service again under that address.

But why did this clash occur? ShinyHunters explained that this attack was carried out as retaliation for threats of violence and identification of their group members supposedly made by a Clop representative. These threats were made during a dispute over Clop’s Oracle E-Business Suite data theft campaign last year.

“During the Oracle EBS campaign they organized and from which I was stolen last year, someone from cl0p sent me a personal message that said, and I quote (translated from Russian): I have more money than you and all your people together, I will kill you soon,” the ShinyHunters spokesperson explained to the aforementioned page.

ShinyHunters is a cybercriminal group dedicated to mass data theft and extortion. Emerging around 2019, it is linked to the international criminal ecosystem and actors from countries like France, the U.S., or the U.K. It operates mainly through social engineering, credential theft, and attacks on cloud services. Among its victims are Ticketmaster, Santander, AT&T, Qantas, and Coinbase. Some investigations speak of very young members, aged 16 to 25, and even younger.

Clop (or Cl0p) is a ransomware gang linked to the Russian-speaking criminal ecosystem. Active since 2019, it combines system encryption with the theft and subsequent publication of information to pressure its victims. In recent years, it has become especially known for exploiting vulnerabilities in enterprise file transfer tools, as happened with MOVEit in 2023.

Other cybercriminal duels

It is not the first time that a conflict of this type occurs between black hat hackers. There are other recent and notable cases. For example, in March of last year, Dragon Force disrupted the leak page of its rivals BlackLock and Mamona, to publicly embarrass them.

This year, another incident of this kind occurred, although here there was not a single victim, but two. 0APT and KryBit attacked each other and leaked the rival’s operational data. As a result, both operations were severely affected.

Cybercriminals do not only target companies and public institutions. They can also attack each other. Although some groups collaborate for their malicious activities and others emerge as small ‘offspring’ of larger collectives, it can also happen that two formations have their rivalry and even engage in relentless battles over victims, money, reputation, and other things.

This is what just happened between two of the most infamous bands in the ecosystem: ShinyHunters and Clop ransomware.

The first of them claims to have gained access to the server used by Clop for its leak site and manipulated it to place their own brand and a message directed at their rivals.

Among the displayed elements was an ASCII representation of the Pokémon Umbreon, associated with the identity of ShinyHunters, as well as a link to the group’s own Tor site.

Additionally, ShinyHunters also allegedly accessed various files and components of the ransomware group’s infrastructure.

“The data we stole includes source codes, GravCMS plugins, and other things. We are still downloading and reviewing them,” the collective commented to the cybersecurity information website BleepingComputer.

The threat actor also claims it is reviewing the obtained information and intends to use it to pressure Clop. Thus, they have given a 72-hour ultimatum. In this way, interestingly, they are following to the letter the modus operandi that ransomware bands usually carry out with their victims.

The ‘Pokémon hunters’ managed to exploit an unauthenticated file upload vulnerability in Grav CMS, the content management system used by the site. From there, they managed to introduce their own content and alter the page.

Furthermore, the attackers boast of having in their possession the private keys used by Clop’s Tor service. According to the hackers, possessing these keys would mean they could maintain control over the .onion address even if Clop tried to expel them from the server. The band claims they could use these keys to host the same service again under that address.

But why did this clash occur? ShinyHunters explained that this attack was carried out as retaliation for threats of violence and identification of their group members supposedly made by a Clop representative. These threats were made during a dispute over Clop’s Oracle E-Business Suite data theft campaign last year.

“During the Oracle EBS campaign they organized and from which I was stolen last year, someone from cl0p sent me a personal message that said, and I quote (translated from Russian): I have more money than you and all your people together, I will kill you soon,” the ShinyHunters spokesperson explained to the aforementioned page.

ShinyHunters is a cybercriminal group dedicated to mass data theft and extortion. Emerging around 2019, it is linked to the international criminal ecosystem and actors from countries like France, the U.S., or the U.K. It operates mainly through social engineering, credential theft, and attacks on cloud services. Among its victims are Ticketmaster, Santander, AT&T, Qantas, and Coinbase. Some investigations speak of very young members, aged 16 to 25, and even younger.

Clop (or Cl0p) is a ransomware gang linked to the Russian-speaking criminal ecosystem. Active since 2019, it combines system encryption with the theft and subsequent publication of information to pressure its victims. In recent years, it has become especially known for exploiting vulnerabilities in enterprise file transfer tools, as happened with MOVEit in 2023.

Other cybercriminal duels

It is not the first time that a conflict of this type occurs between black hat hackers. There are other recent and notable cases. For example, in March of last year, Dragon Force disrupted the leak page of its rivals BlackLock and Mamona, to publicly embarrass them.

This year, another incident of this kind occurred, although here there was not a single victim, but two. 0APT and KryBit attacked each other and leaked the rival’s operational data. As a result, both operations were severely affected.


——————————————————–


Click Here For The Original Source.

.........................