ShinyHunters Breaches Clop Ransomware Leak Site via Unpatched Grav CMS Flaw

Clop moves to new Tor address after defacement; both groups dispute extent of data stolen

By LineZotpaper
Published
Read Time2 min
The Clop ransomware gang has relocated its data leak site to a new Tor address after confirming that its previous server was compromised and defaced by the ShinyHunters extortion group through an unauthenticated path traversal vulnerability in an unpatched Grav CMS installation.

The Clop ransomware gang has moved its data leak site to a new Tor address after confirming its previous server was compromised through an unupdated Grav CMS plugin. The breach, earlier this month, was carried out by the ShinyHunters extortion group, which initially uploaded a small text file and later replaced the site with a full-page defacement displaying its Umbreon Pokémon logo and a link to its own data leak site.

ShinyHunters subsequently claimed on its own leak site that it stole source code, Grav CMS plugins, server logs, and the private keys used by Clop's Tor onion service, and issued a ransom demand threatening to leak the files if Clop did not pay. Clop has denied any relationship or ongoing negotiations with ShinyHunters, stating, "We do not know them, we have never worked with them, and at the moment we are not in contact with them."

When asked how the breach occurred, Clop confirmed that its Grav installation had not been fully updated. However, the Russian ransomware gang disputes ShinyHunters' claims that valuable operational or financial data was taken, asserting that the compromised server contained only content, with no data or financial activity.

Grav CMS has confirmed that the vulnerability and exploitation details shared by ShinyHunters are accurate. ShinyHunters told BleepingComputer the compromised server was running Grav 1.7.43 and that they exploited an unauthenticated file upload flaw in Grav's form upload handling. The vulnerability involved directory traversal via the __unique_form_id__ POST parameter, allowing creation of upload paths outside the intended temporary directory.

Although Clop says it is not communicating with the other threat actors, Clop has since been quietly removed from ShinyHunters' data leak site, a development that commonly occurs when negotiations are under way. ShinyHunters declined to answer further questions about the removal.

§

Analysis

Why This Matters

  • The incident demonstrates that even ransomware gangs themselves can fall victim to operational security failures, showing the vulnerability of threat actors' own infrastructure.
  • The confirmed compromise of private keys for a Tor onion service could have broader implications for the anonymity of Clop's operations.
  • The dispute over stolen data value highlights the ongoing trust issues within cybercriminal ecosystems.

Background

Clop is a well-known Russian ransomware group that has been active for years, targeting large organizations with data extortion schemes. ShinyHunters gained notoriety for breaches of companies such as Microsoft and AT&T. The clash between two prominent cybercriminal groups is unusual, as such groups typically avoid directly attacking one another to prevent drawing law enforcement attention.

Key Perspectives

Clop: The gang denies any collaboration or payment to ShinyHunters, downplays the value of stolen material, and has moved its leak site to a new address. It blames the breach on a failure to update a Grav CMS plugin. ShinyHunters: The group claims it stole significant operational data, including private keys and source code, and issued a ransom demand. It has since removed Clop from its leak site, which may indicate negotiations. Security Observers: The incident highlights that cybercriminal groups are not immune to the same vulnerabilities they exploit, and that unpatched software remains a risk even among sophisticated threat actors.

What to Watch

  • Whether Clop's new Tor site remains stable or suffers further attacks.
  • Any public release of allegedly stolen data by ShinyHunters if negotiations fail.
  • Law enforcement response or increased scrutiny of both groups following the public breach.

Sources

Zotpaper

Written by software from the reporting listed above, scored by an automated standards desk, and published without a person reading it first. If something here is wrong, tell the editor and it will be put right.