Grav CMS: Clop Ransomware Group changes Server and vows Not to Pay ShinyHunters

Grav CMS: Clop Ransomware Group changes Server and vows Not to Pay ShinyHunters

Clop Ransomware Group Relocates Leak Site After Alleged ShinyHunters Breach

The ongoing rivalry between ransomware gangs escalated this month after the Clop ransomware operation reportedly moved its data-leak website to a new server following an alleged attack by the ShinyHunters cybercrime group. Nearly 10 days prior, ShinyHunters claimed to have compromised Clop’s infrastructure, including its Tor-based leak forum, which is used to publish stolen data and extort victims.

The breach was reportedly executed by exploiting a vulnerability in Grav CMS, a file-based content management system, demonstrating how even sophisticated cybercriminal groups can be exposed through unpatched software. While the initial attack appeared to disrupt Clop’s operations, the group responded by relocating its infrastructure rather than engaging with ShinyHunters’ ransom demands.

According to BleepingComputer, Clop has shown no interest in paying the attackers and is instead considering retaliatory measures. This incident underscores the competitive and hostile nature of the cybercrime ecosystem, where threat actors increasingly target one another rather than just traditional victims.

While details of the breach remain unverified, Clop’s decision to migrate its leak site suggests the group views the previous server as compromised. If retaliation occurs, the conflict could escalate further, highlighting how vulnerabilities in underground infrastructure can fuel ongoing cybercriminal disputes. The full extent of the compromise including whether any data was stolen remains unclear.

Source: https://www.cybersecurity-insiders.com/clop-ransomware-group-changes-server-and-vows-not-to-pay-shinyhunters/

BleepingComputer cybersecurity rating report: https://www.rankiteo.com/company/bleepingcomputer

"id": "BLE1790670404",
"linkid": "bleepingcomputer",
"type": "Vulnerability",
"date": "9/2026",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'industry': 'Cybercrime',
                        'name': 'Clop Ransomware Group',
                        'type': 'Cybercriminal organization'}],
 'attack_vector': 'Exploitation of unpatched software (Grav CMS vulnerability)',
 'data_breach': {'sensitivity_of_data': 'High (stolen data from Clop’s '
                                        'victims)',
                 'type_of_data_compromised': 'Potential leak forum data '
                                             '(unverified)'},
 'description': 'The Clop ransomware operation moved its data-leak website to '
                'a new server following an alleged attack by the ShinyHunters '
                'cybercrime group. ShinyHunters claimed to have compromised '
                'Clop’s infrastructure, including its Tor-based leak forum, by '
                'exploiting a vulnerability in Grav CMS. Clop responded by '
                'relocating its infrastructure and is considering retaliatory '
                'measures.',
 'impact': {'brand_reputation_impact': 'Potential reputational damage within '
                                       'cybercriminal ecosystem',
            'data_compromised': 'Potential compromise of Clop’s leak forum '
                                'data (unverified)',
            'downtime': 'Disruption of Clop’s operations (temporary)',
            'operational_impact': 'Relocation of infrastructure, potential '
                                  'retaliatory actions',
            'systems_affected': 'Tor-based leak forum, Clop’s infrastructure'},
 'initial_access_broker': {'entry_point': 'Grav CMS vulnerability',
                           'high_value_targets': 'Clop’s Tor-based leak forum'},
 'investigation_status': 'Ongoing (details unverified)',
 'lessons_learned': 'Even sophisticated cybercriminal groups are vulnerable to '
                    'unpatched software. The cybercrime ecosystem is '
                    'increasingly competitive and hostile, with threat actors '
                    'targeting one another.',
 'motivation': 'Cybercriminal rivalry, disruption of operations, potential '
               'retaliation',
 'post_incident_analysis': {'corrective_actions': 'Relocation of '
                                                  'infrastructure, potential '
                                                  'retaliation',
                            'root_causes': 'Exploitation of unpatched Grav CMS '
                                           'vulnerability'},
 'ransomware': {'ransomware_strain': 'Clop'},
 'recommendations': 'Regularly patch and update software, even for underground '
                    'infrastructure. Monitor for signs of compromise and have '
                    'contingency plans for infrastructure relocation.',
 'references': [{'source': 'BleepingComputer'}],
 'response': {'containment_measures': 'Migration to new server',
              'incident_response_plan_activated': 'Relocation of '
                                                  'infrastructure'},
 'threat_actor': ['Clop Ransomware Group', 'ShinyHunters'],
 'title': 'Clop Ransomware Group Relocates Leak Site After Alleged '
          'ShinyHunters Breach',
 'type': 'Ransomware Attack',
 'vulnerability_exploited': 'Grav CMS vulnerability'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.