Cybercriminal Infighting: ShinyHunters Hijacks Clop’s Infrastructure in Escalating Rivalry
A feud between two prominent cybercrime groups has exposed vulnerabilities even within hacker operations. ShinyHunters, a notorious ransomware collective, claimed to have compromised the website and infrastructure of rival group Clop, taking its dark web site offline. The attack followed a reported threat from Clop, marking a rare instance of cybercriminals targeting each other’s systems.
According to Bleeping Computer, ShinyHunters exploited an unauthenticated file upload flaw in Grav CMS a content management system used by Clop to upload a warning message. The group later defaced Clop’s site with ASCII art and added its rivals to its own data leak list, demanding a ransom and an apology for the site’s return. A note left on the defaced page included a sarcastic apology for the "unprofessionalism."
Security experts weighed in on the incident, noting its irony. Steven Thomson of Barrier Networks called it a "funny twist" but cautioned that ShinyHunters may have staged the breach for publicity. Others, including Jamie Akhtar of CyberSmart, highlighted that cybercriminals are just as susceptible to the same security flaws they exploit in legitimate organizations. Clop’s alleged compromise reportedly extended beyond defacement, potentially exposing source code, operational logs, and Tor service keys critical components of its infrastructure.
Both groups have established reputations for high-profile attacks. ShinyHunters, active since at least 2020, has targeted major platforms, including a February vishing campaign flagged by Google and a breach of Salesforce’s Experience Cloud. Clop, meanwhile, has orchestrated widespread ransomware campaigns, notably exploiting vulnerabilities in MOVEit File Transfer and print management software.
The clash underscores the competitive nature of cybercrime, with experts like Javvad Malik of KnowBe4 noting that criminal enterprises operate like businesses complete with betrayals and power struggles. For defenders, the incident serves as a reminder that understanding threat actors’ motivations and behaviors is as critical as securing technical defenses.
Grav Web Solution Pvt. Ltd cybersecurity rating report: https://www.rankiteo.com/company/gravwebsolution
"id": "GRA1790072632",
"linkid": "gravwebsolution",
"type": "Vulnerability",
"date": "2/2026",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'industry': 'Cybercrime',
'name': 'Clop',
'type': 'Cybercrime Group'}],
'attack_vector': 'Unauthenticated file upload flaw in Grav CMS',
'data_breach': {'data_exfiltration': 'Potential data exfiltration',
'sensitivity_of_data': 'High',
'type_of_data_compromised': 'Source code, operational logs, '
'Tor service keys'},
'description': 'A feud between two prominent cybercrime groups, ShinyHunters '
"and Clop, led to ShinyHunters compromising Clop's website and "
'infrastructure. ShinyHunters exploited an unauthenticated '
"file upload flaw in Grav CMS to deface Clop's dark web site, "
'demand a ransom, and expose potential operational data.',
'impact': {'brand_reputation_impact': "Damage to Clop's reputation within "
'cybercriminal circles',
'data_compromised': 'Potential exposure of source code, '
'operational logs, and Tor service keys',
'downtime': "Clop's dark web site taken offline",
'operational_impact': "Disruption of Clop's operations, potential "
'exposure of critical infrastructure '
'components',
'systems_affected': "Clop's dark web site and infrastructure"},
'initial_access_broker': {'entry_point': 'Unauthenticated file upload flaw in '
'Grav CMS'},
'lessons_learned': 'Cybercriminals are susceptible to the same security flaws '
"they exploit. Understanding threat actors' motivations "
'and behaviors is critical for defenders.',
'motivation': 'Rivalry, Publicity, Extortion',
'post_incident_analysis': {'root_causes': 'Unauthenticated file upload flaw '
'in Grav CMS, lack of security '
'measures within cybercriminal '
'infrastructure'},
'ransomware': {'data_exfiltration': 'Potential data exfiltration',
'ransom_demanded': "Ransom and apology demanded for site's "
'return'},
'references': [{'source': 'Bleeping Computer'}],
'response': {'communication_strategy': "Defacement of Clop's site with ASCII "
'art and a sarcastic apology note'},
'threat_actor': 'ShinyHunters',
'title': 'ShinyHunters Hijacks Clop’s Infrastructure in Escalating Rivalry',
'type': 'Defacement, Data Breach, Ransomware',
'vulnerability_exploited': 'Unauthenticated file upload flaw in Grav CMS'}