LOADING

Type to search

ShinyHunters Claims Hack of Rival Cl0p Site as Cybercrime Feud Erupts

Cyber Threat News

ShinyHunters Claims Hack of Rival Cl0p Site as Cybercrime Feud Erupts

Share
ShinyHunters and cl0p cybercrime feud on the dark web

Cybercriminals don’t usually make a habit of attacking each other in public. That changed this week when ShinyHunters claimed it had breached the dark web operation of rival group cl0p and taken control of its website.

The alleged takeover happened on September 18. ShinyHunters told Reuters that it had found a vulnerability in cl0p’s software and used it to gain access to the group’s infrastructure.

“We basically own them now,” the group told Reuters in an online chat.

There was some evidence to support the claim. On September 19, cl0p’s dark web site displayed a message saying, “Domain Seized By ShinyHunters.” A screenshot of the page was preserved by eCrime.ch, a platform that tracks cybercrime activity.

By the following day, the site was no longer accessible when Reuters tried to visit it.

Cl0p did not respond to repeated requests for comment.

The incident has drawn attention because this isn’t a conventional cyberattack involving a company, government agency or individual. The alleged target is another cybercrime group, and both sides have been active in some of the world’s most significant data theft campaigns.

A fight over a zero-day

The roots of the dispute appear to go back to an Oracle vulnerability.

ShinyHunters said the two groups had been feuding over a previously unknown vulnerability in Oracle’s E-Business Suite, commonly known as EBS. The group claimed it had discovered the flaw first and accused cl0p of exploiting it.

A previously unknown vulnerability is known as a zero-day. These flaws are highly valuable to attackers because defenders may have no patch available when exploitation begins.

Cl0p used the Oracle vulnerability to steal data from more than 100 companies, according to an estimate from a Google analyst cited by Reuters.

But there is an important qualification here. ShinyHunters’ version of how the dispute began has not been independently verified by Reuters.

The disagreement apparently became more personal as the groups turned their attention toward each other. ShinyHunters claimed cl0p threatened to expose the identities of some of its members. It then threatened to reveal information about cl0p’s own operations.

That dispute appears to have culminated in the alleged takeover of cl0p’s dark web site.

Cybercrime groups rarely stay quiet forever

The two groups aren’t strangers to high-profile attacks.

Cl0p is a Russian-speaking cybercrime group with a long history of exploiting vulnerabilities in enterprise software. Its 2023 MOVEit campaign is one of its most significant operations.

The group exploited a vulnerability in MOVEit Transfer, a file-transfer platform used by organizations to exchange sensitive information. The campaign affected more than 600 organizations and exposed data belonging to tens of millions of people.

Cl0p has continued to claim large-scale data theft operations. Last month, it said it had stolen data from nearly 50 companies, including Philips, Shell, Fiserv and GE.

ShinyHunters has built its own reputation around large data breaches and extortion campaigns.

In April, the group claimed to have stolen millions of business records from Rockstar Games, the developer behind the Grand Theft Auto series.

The group was also linked to an attack involving Canvas, an education technology platform. The incident disrupted services across U.S. schools.

Earlier this month, Anthropic said it had detected hackers linked to ShinyHunters attempting to use its AI tools.

A cybercrime dispute in public view

Cybercrime groups compete for many of the same things legitimate security teams try to protect: software vulnerabilities, access credentials, stolen data and network access. They also compete with one another.

What makes this incident unusual is how openly that competition has played out.

Brandon Parsons, a threat intelligence manager at Ascent Solutions, told Reuters that disputes between criminal groups on the dark web aren’t unusual. Joe Roosen, senior director of security research at SpyCloud, said he had rarely seen rival cybercrime groups confront each other this openly.

The alleged takeover gives security researchers an unusual look at the tensions inside the cybercrime ecosystem. It also shows how valuable an unpatched vulnerability can become. A flaw that can provide access to a victim’s systems can be just as useful when the target happens to be another criminal operation.

For now, though, parts of the story remain difficult to verify.

Reuters observed that cl0p’s site displayed the seizure message and later found the site inaccessible. But the broader claims made by ShinyHunters about how it gained access, its control over cl0p’s infrastructure, and the history of their dispute have not been independently established.

That distinction matters. In cybercrime reporting, a claim appearing on a dark web forum isn’t automatically proof of a successful attack.

In this case, one thing is clear: a feud that had been playing out within the cybercrime underground has now surfaced in public, with one notorious group claiming that it has turned the tools of the cybercriminal trade against another.

 

Source: Cybercrime feud erupts on dark web as notorious group claims hijack of rival’s website | Reuters

Author

  • New Project 18

    Maya Pillai is a technology writer with over 20 years of experience. She specializes in cybersecurity, focusing on ransomware, endpoint protection, and online threats, making complex issues easy to understand for businesses and individuals.

    View all posts
Tags:
Maya Pillai

Maya Pillai is a technology writer with over 20 years of experience. She specializes in cybersecurity, focusing on ransomware, endpoint protection, and online threats, making complex issues easy to understand for businesses and individuals.

  • 1