ShinyHunters hacks rival extortion gang and takes over its dark web site
ShinyHunters claims it hacked rival extortion gang Clop's leak site via a Grav CMS flaw and seized its onion domain.
ShinyHunters reportedly breached the Clop ransomware gang's dark web leak site by exploiting a claimed unauthenticated file-upload vulnerability in Grav CMS, defacing it with an extortion note demanding money and a public apology. The group claims to control the onion service private keys and threatens to disclose which companies paid Clop and to what Bitcoin addresses, including during the Oracle EBS campaign. ShinyHunters, active since 2019, previously claimed stealing 3.65 TB of data on about 9,000 academic institutions from Instructure, while Clop's PTC Windchill campaign named over 40 victims including Shell and Philips.