ShinyHunters Hacks Rival Ransomware Gang Cl0p, Defaces Website and Demands Ransom
ShinyHunters has reportedly hacked rival gang Cl0p, stolen data and Tor keys, defaced its site and demanded a 72-hour ransom, TechRadar reports.
ShinyHunters added Cl0p to its data leak site and gave the gang 72 hours to pay a ransom or see all its files published, according to Cybernews. The files allegedly taken include source code, Grav CMS plugins, system logs and other information. The amount demanded was not known.
"We are still downloading and reviewing them," ShinyHunters allegedly told BleepingComputer, referring to the stolen data. The group said the haul included source codes, Grav CMS plugins and other material.
ShinyHunters also said it stole everything in the server's /var/log directory, including system activity records, authentication logs and IP addresses associated with connections to the server. TechRadar noted that such data is unlikely to identify Cl0p members, who are believed to be Russian and largely free to operate, though doxxing could help defenders disrupt the group's infrastructure.
The attackers claimed to have obtained the private keys for Cl0p's Tor onion service. "We have their onion keys. So if they kick us out it wouldn't matter at all because we control the private keys to host the same exact onion URL," the group allegedly told BleepingComputer.
ShinyHunters defaced Cl0p's website after allegedly finding an unauthenticated file upload flaw in the Grav CMS installation Cl0p was using, according to the report. Cybernews confirmed the site had been defaced. It now displays an ASCII image of ShinyHunters' logo, a link to its Tor site and a message: "THIS SITE HAS BEEN PWN3D BY SHINYHUNTERES #Skids10p - Maybe don't try to threaten us next time." The page also says "rooting your systems since '19 ;)".
The taunt appeared to refer to an earlier threat from a Cl0p member, TechRadar reported. ShinyHunters told BleepingComputer that during Cl0p's 2025 Oracle E-Business Suite campaign, someone from Cl0p messaged the group and said, translated from Russian: "I have more money than you and all of your people combined, I'll kill you soon." The same person allegedly threatened to expose ShinyHunters' identities.
Cybercriminals often cooperate by sharing resources, renting each other's services and complementing campaigns, but such arrangements are usually temporary and collapse when trouble arises, according to TechRadar. The last major feud it cited occurred in 2022, when the Conti group publicly backed the Russian government after Russia's invasion of Ukraine and threatened to use its resources against anyone attacking Russian infrastructure.
The Conti announcement backfired. Many affiliates stopped working with the group and others attacked it, TechRadar reported. A Ukrainian researcher and an alleged affiliate soon leaked more than 60,000 messages, exposing Conti's operations and internal organization, and the group collapsed later that year. Its members dispersed into other groups, including Black Basta, Royal and Quantum, some of whom are allegedly still active.