ShinyHunters Hacks and Defaces Clop’s Leak Site

ShinyHunters defacing the Clop ransomware Tor leak site and threatening to extort the gang

Extortion has suddenly turned against the extortionists themselves. ShinyHunters gained access to the Tor site of the Clop group and replaced its content with a page of its own. BleepingComputer confirmed that the attackers first uploaded a small file bearing a message to the server, and a few hours later completely altered the resource’s main page. The outlet detailed how ShinyHunters hacked the Clop leak site and threatened to extort the ransomware gang.

An Umbreon Defacement

In place of Clop’s site appeared ASCII art of the character Umbreon, which ShinyHunters uses as a symbol, a link to the group’s own platform, and a message about the hack. Such a result confirms at least the ability to write or change the files that the public Tor service serves. Deeper access to the server cannot yet be considered proven.

Claims of Full Server Access

ShinyHunters declared that it had obtained full access to the system and downloaded the source code, Grav CMS plugins, system logs, and other files. Separately, the group asserts that it took the contents of the /var/log directory. It could have contained records of server activity, authentication events, and the IP addresses of those who connected to Clop’s infrastructure.

The most sensitive claim appears to be the theft of the private keys of Clop’s onion service. In Tor, such a key confirms ownership of a specific .onion address. If ShinyHunters has indeed obtained working keys, removing the attackers from the current server would not fully solve the problem: the same address could be raised on another machine and passed off as Clop’s former resource.

What Has and Hasn’t Been Verified

There is as yet no independent proof of the theft of the logs, source code, and keys. BleepingComputer was able to verify only the placement of the file and the subsequent substitution of the site. Therefore, the confirmed part of the incident is limited to the compromise of a public resource, while the claims of full control over the server and access to internal data remain ShinyHunters’ version.

By ShinyHunters’ account, entry began with the ability to upload files without authorization in the Grav CMS that Clop’s site used. No public technical report with the CMS version, exploitation code, or confirmation from Grav’s developers has been published. The incident cannot yet be linked to a specific known vulnerability, nor can it be asserted that the problem affects ordinary Grav installations.

Extorting the Extortionists

After the hack, ShinyHunters decided to apply to Clop the very tool of pressure that cybercriminals usually wield against companies. The group announced its intention to extort money from Clop and demanded that it make contact within 72 hours. At the time of checking on September 21, no public confirmation of a deal, payment, or response from Clop had appeared in available sources.

A Feud Rooted in Oracle E-Business Suite

ShinyHunters names the events surrounding Oracle E-Business Suite as the cause of the conflict. In 2025, Clop conducted a mass campaign against corporate servers, and participants of Scattered Lapsus$ Hunters, linked to ShinyHunters, published working code matching the tool from the attacks. ShinyHunters claims the code originally belonged to the group, and that a Clop representative later threatened its participants. There is no independent confirmation of this version.

For both groups, the conflict touches more than reputation. ShinyHunters has weathered several blows to its associated infrastructure and continued attacks on corporate SaaS services, while Clop has for years built campaigns around the mass theft of data and pressure on victims. The loss of control over the leak platform strikes at the channel through which Clop publishes company names and stolen material.

The Broader Stakes

If the claims about the system logs and onion keys are confirmed, the consequences will prove wider than an ordinary page substitution. The logs could reveal the technical traces of the operators and visitors, while the keys would allow a dispute over the digital identity of the Tor service. For now, a narrower fact is confirmed: the infrastructure of a major extortion group proved vulnerable to the same class of attack that criminals usually threaten their own victims with.

Support Our Threat Intelligence

If you find our technology report and cybersecurity news helpful, consider supporting our work.

Crypto QR Code
USDT (TRC20):
TN8BdV8cp4T1Cd28gK9qTAnZknzzuwyUtm
USDT (ERC20):
0x3725e1a7d3bc5765499fa6aaafe307fabcd75bce

Leave a Reply