How A Ransomware Gang Hijacked A Rival Gang’s Website – And Is Now Extorting Them For “2.333% Of Their Net Worth | #ransomware | #cybercrime


Ransomware groups shaking down ordinary companies barely raises an eyebrow anymore. Extortionists extorting extortionists, on the other hand, is a delightfully rare spectacle, and exactly why Cl0p’s recent public embarrassment deserves a front-row seat.

This week, rival syndicate ShinyHunters hijacked Cl0p’s Tor leak site, the very dark web portal used to publish stolen files and pressure victims into paying up. BleepingComputer confirmed the file was posted to Cl0p’s server, proving that even cyber-extortionists can fall victim to an unwanted surprise upload.

What followed was a gloriously petty dark web takeover. The site was plastered with ShinyHunters imagery, featuring ASCII art of the Pokémon Umbreon alongside a broadcast that the domain had been hijacked outright.

By 20 September, reports confirmed the original portal was gone, replaced by a header reading “Domain Seized By ShinyHunters”. Cybersecurity analysts verified the breach was legitimate. ShinyHunters then repurposed Cl0p’s own platform into an extortion tool aimed at its original creator, demanding an eight-figure payout pegged to 2.333% of Cl0p’s estimated net worth.

 

What’s Confirmed, And What’s Only A Claim

 

Untangling this feud means separating confirmed compromise from creative dark web theatrics.

The visible takeover and defacement of Cl0p’s leak portal are solid, verified facts. What’s unverified is ShinyHunters’ claim that it raided Cl0p’s backend servers, swiped source code, stole Grav CMS plugins, scraped logs and looted the private keys for Cl0p’s Tor onion service.

Seizing those keys would allow ShinyHunters to mirror Cl0p’s official dark web address on its own servers. Security researchers verified the file upload and public defacement, but left the deeper server theft claims unconfirmed.

That boundary puts the rest of the feud into perspective. What we know for sure is a confirmed portal hijack paired with bold, unverified claims of total server control. The shakedown turned increasingly hostile either way.

ShinyHunters warned that the eight-figure price tag would climb every 24 hours Cl0p dragged its feet, adding demands for a public apology alongside interest on profits Cl0p generated from its Oracle E-Business Suite campaign. The group further threatened to publish a directory of companies that paid ransoms, listing exact settlement figures and Bitcoin wallet addresses.

Cl0p eventually surfaced with a short note asking for direct contact due to broken communication channels, a white flag ShinyHunters ignored as they kept up the heat.

 

What Sparked This Ransomware Feud?

 

The bad blood traces back to Cl0p’s 2025 spree against Oracle E-Business Suite.

Public tracking documented Cl0p using that loophole to plunder data from over 100 organisations, but ShinyHunters claims it found the vulnerability first and that Cl0p basically stole its homework.

Security researchers noted ShinyHunters dropped a proof-of-concept exploit around the same timeframe, which Oracle later acknowledged matched the precise mechanism Cl0p used. ShinyHunters insists things turned hostile when a Cl0p rep threatened to dox its members, though those specific allegations are unverified.

It all paints a far more complex picture than standard criminal squabbling. The drama blends an intellectual property dispute over stolen exploit code, revenge for personal threats, sheer commercial competition and a public reputation clash, hosted right on the servers usually meant for extortion.

 

Where Does The 2.333% Figure Come From?

 

The exact decimal percentage serves performative ends as much as financial ones.

It applies a gloss of corporate auditing to an unverified sum, with no evidence confirming Cl0p’s real net worth. Intelligence reports indicated that an eight-figure demand suggests an assumed financial position in the hundreds of millions, though no independent party can verify those figures.

The demand structure replicates corporate extortion tactics: a calculated figure, an assessment of financial capacity, a firm deadline, escalating penalties and threats to release sensitive data. While the irony is apparent, the execution is quite routine.

ShinyHunters essentially handed Cl0p’s business model back to them: capture the site, threaten public damage, enforce a timeline and demand a payout. Showing that in the dark web space, intellectual property is shared, customer support is non-existent and honour among extortionists has a very specific price tag.





Click Here For The Original Source.

——————————————————–

..........

.

.