New Delhi. The alleged cyber conflict between ransomware group Clop and cybercrime group ShinyHunters has taken a new turn. Following claims that ShinyHunters breached infrastructure linked to Clop’s ransomware operations and gained control of its data leak website, Clop has reportedly changed the server and related infrastructure supporting its leak site. According to information that has emerged, Clop is not interested in paying a ransom to ShinyHunters over the alleged attack. Instead, the group is reportedly considering possible retaliation against those responsible.
Around 10 days ago, ShinyHunters claimed that it had breached infrastructure associated with Clop’s ransomware operation. The group allegedly gained access to Clop’s data leak website and altered its appearance. The website was accessible through the Tor network and operated as a hidden service. However, the claim does not establish how much access the attackers obtained to Clop’s wider network or other critical systems.
FCRF Launches CP-FRM to Build India’s Next Generation of Fraud Risk Professionals
Data leak sites play an important role in ransomware operations. Through these websites, ransomware groups threaten to publish stolen information in order to pressure victim companies and institutions into paying a ransom. As a result, an alleged takeover of such a site can affect a ransomware group’s operations and its ability to pressure victims. In Clop’s case, the reported decision to abandon the old infrastructure and move to a new server appears to be a significant response to the alleged breach.
According to available information, Clop’s new data leak site has been moved to a new server and a new address. The alleged compromise of the previous server has been linked to the exploitation of a vulnerability in Grav CMS. Grav is a file-based content management system used to build and operate websites. However, the presence of this vulnerability alone does not establish the extent of access obtained during the incident or determine exactly what data may have been affected.
What makes the incident notable is the alleged identity of the target. Instead of a conventional company, government agency or business organization, the claimed target was the infrastructure of another ransomware group. Groups such as Clop typically infiltrate the networks of organizations, steal data and then threaten to release it unless a ransom is paid. In this case, another cybercrime group allegedly targeted infrastructure used for a similar purpose.
Reports suggest that Clop members are not interested in paying a ransom to ShinyHunters following the alleged attack. Instead, the group is reportedly considering possible retaliation. It remains unclear what form such an action could take or whether it will actually be carried out. Any discussion of a retaliatory attack should therefore, for now, be treated as a claim or reported possibility rather than a confirmed development.
The incident also highlights the possibility of conflict between criminal groups operating in the cyber underground. Different groups can target each other’s websites, servers and online services in an attempt to demonstrate their capabilities or disrupt rival operations. Such confrontations can make the cybercrime ecosystem even more unstable and unpredictable.
The episode also highlights an important aspect of cybersecurity. Internet-facing servers, websites and software can expose operators to risks when vulnerabilities remain unpatched. Whether a system is being used by a legitimate organization or a criminal group, weaknesses in publicly available software can provide attackers with a potential entry point. Regular software updates, vulnerability management and strict access controls are therefore important elements of server security.
However, information about the alleged ShinyHunters attack and its access to Clop’s infrastructure is currently based largely on claims associated with cybercrime groups and reports emerging from the cybersecurity community. The full scope of the alleged intrusion has not been independently established. It is also unclear whether attackers obtained specific data from the old server or whether any sensitive information was actually stolen.
Clop’s reported decision to move its leak site to a new server indicates that the group no longer considers the old infrastructure secure. By shifting to new infrastructure, it appears to be attempting to maintain its operations while reducing the risk associated with the allegedly compromised server. At the same time, reports of a refusal to pay ransom and possible retaliation make the incident different from a conventional ransomware attack.
If reports concerning potential retaliation are subsequently confirmed, the alleged confrontation between Clop and ShinyHunters could enter a more serious phase. For now, the incident illustrates how cybercriminal groups themselves can become targets of attacks involving data theft, infrastructure compromise and attempts to disrupt online operations.
Follow for daily updates on cybercrime, corporate fraud, DFIR, hacking, investigations, and digital forensics