Cybercriminal Infighting: ShinyHunters Breaches Clop Ransomware Gang’s Servers
In a rare case of cybercriminals targeting their own, the hacking group ShinyHunters successfully infiltrated the infrastructure of the notorious Clop ransomware gang, exposing sensitive data and potentially crippling its operations. The attack, confirmed by BleepingComputer, exploited a vulnerability in Grav, the content management system (CMS) used by Clop, allowing ShinyHunters to upload a file to the gang’s server without authentication. The message left behind "Maybe don’t try to threaten us next time" hinted at a retaliatory motive.
Within hours, Clop’s public-facing site was defaced, replaced with Noctali, ShinyHunters’ Pokémon mascot, alongside a Tor link to the group’s own site. While the initial breach was verified, ShinyHunters later claimed to have gained full server access, exfiltrating the code source, plugins, and /var/log directory a critical repository of logs containing authentication records, admin connections, and other operational details that ransomware groups typically keep hidden.
The most damaging revelation, however, was the alleged theft of Clop’s private onion service keys. If true, this would allow ShinyHunters to impersonate Clop’s Tor site, effectively hijacking its historical .onion address. Even if Clop rebuilds its infrastructure, the compromised keys would render its original Tor URL untrustworthy, forcing the gang to abandon a key asset in its extortion operations. The incident underscores the fragility of even sophisticated cybercriminal networks when internal conflicts escalate.
Grav TPRM report: https://www.rankiteo.com/company/grav
"id": "gra1790058238",
"linkid": "grav",
"type": "Vulnerability",
"date": "9/2026",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'industry': 'Cybercrime',
'name': 'Clop Ransomware Gang',
'type': 'Cybercriminal Organization'}],
'attack_vector': 'Exploited vulnerability in Grav CMS',
'data_breach': {'data_exfiltration': True,
'sensitivity_of_data': 'High',
'type_of_data_compromised': ['Source code',
'Plugins',
'Authentication logs',
'Admin connection records',
'Private onion service keys']},
'description': 'In a rare case of cybercriminals targeting their own, the '
'hacking group ShinyHunters successfully infiltrated the '
'infrastructure of the notorious Clop ransomware gang, '
'exposing sensitive data and potentially crippling its '
'operations. The attack exploited a vulnerability in Grav, the '
'content management system (CMS) used by Clop, allowing '
'ShinyHunters to upload a file to the gang’s server without '
'authentication. The message left behind hinted at a '
'retaliatory motive. Clop’s public-facing site was defaced, '
'and ShinyHunters claimed to have gained full server access, '
'exfiltrating source code, plugins, and critical logs. The '
'theft of Clop’s private onion service keys could allow '
'ShinyHunters to impersonate Clop’s Tor site, forcing the gang '
'to abandon a key asset in its extortion operations.',
'impact': {'brand_reputation_impact': 'Loss of credibility and trust in '
'Clop’s infrastructure',
'data_compromised': 'Source code, plugins, /var/log directory '
'(authentication records, admin connections), '
'private onion service keys',
'operational_impact': 'Potential crippling of Clop’s operations, '
'loss of trust in Clop’s Tor site, forced '
'abandonment of key infrastructure',
'systems_affected': 'Clop ransomware gang’s servers, Grav CMS, Tor '
'onion service'},
'initial_access_broker': {'entry_point': 'Grav CMS vulnerability',
'high_value_targets': 'Private onion service keys, '
'source code, logs'},
'lessons_learned': 'Cybercriminal organizations are vulnerable to internal '
'conflicts and targeted attacks, even sophisticated groups '
'can have critical infrastructure weaknesses, and private '
'keys for Tor services are high-value targets.',
'motivation': 'Retaliation, Cybercriminal Infighting',
'post_incident_analysis': {'root_causes': 'Unauthenticated file upload '
'vulnerability in Grav CMS, lack of '
'robust security measures in Clop’s '
'infrastructure, internal conflict '
'leading to retaliatory attack'},
'ransomware': {'data_exfiltration': True},
'recommendations': 'Cybercriminal groups should secure their infrastructure '
'with robust authentication, regularly audit their systems '
'for vulnerabilities, and avoid internal conflicts that '
'could lead to retaliatory attacks. Organizations should '
'monitor for signs of compromised infrastructure keys and '
'be prepared to migrate to new secure channels if '
'necessary.',
'references': [{'source': 'BleepingComputer'}],
'threat_actor': 'ShinyHunters',
'title': 'ShinyHunters Breaches Clop Ransomware Gang’s Servers',
'type': 'Data Breach, Defacement, Cybercriminal Infighting',
'vulnerability_exploited': 'Unauthenticated file upload vulnerability in Grav '
'CMS'}