ShinyHunters cybercrime gang takes over Cl0p ransomware site, demands extortion payment
The ShinyHunters extortion group hijacked the dark web leak site of the prolific Cl0p ransomware gang, according to material posted on the site over the weekend.
The site, which Cl0p has used for years to name its hacking victims and pressure them into making an extortion payment, was used for those purposes against Cl0p itself.
It was defaced with a banner saying the domain had been seized by ShinyHunters, a group better known for social engineering and data extortion than technical hacking.
In messages posted on the site purportedly from ShinyHunters, the group set an unspecified eight-figure extortion demand and described that amount as “2.333%” of Cl0p’s net worth, implying self-claimed holdings of at least hundreds of millions of dollars.
“I hope you can pay that much because that is the demand, negotiable. Get your bosses in front of the white board in the war room. Clock is ticking moron. Kindly excuse our unprofessionalism,” the notice said.
The hackers claimed their demands would increase every 24 hours that Cl0p failed to respond. By Monday, the demands had expanded to include a public apology from Cl0p.
A message posted Sunday named three people identified as Cl0p operators, all of whom have previously been named in public reporting. It also demanded proceeds from Cl0p’s recent campaign targeting Oracle’s E-Business Suite, “plus more.”
“Be sure to bring an English interlocutor so you can comprehend my literacy in acquiring your bank account,” the message stated.
The attacks on E-Business Suite, a widely used business platform, prompted warnings from Oracle, the FBI and cybersecurity agencies in the United Kingdom and Singapore.
The campaign followed ShinyHunters’ public release of a proof-of-concept exploit for the Oracle vulnerability on Telegram. ShinyHunters said its feud with Cl0p stems from the ransomware group’s unauthorized use of the vulnerability and threats against one of its members.
As part of the extortion attempt, the cybercriminals are threatening to release records showing which companies paid Cl0p, how much they paid and which Bitcoin addresses were used.
The defaced site was replaced on Monday by a message apparently from Cl0p, stating: “Shiny Hunters we trying to reach you Your email does not work. Come online old platform no email[.]”
ShinyHunters disrupted schools across the U.S. in May with an attack on a widely used education platform and stole information belonging to more than 4 million people in an April attack on the world’s largest medical device company.
Other victims have included Carnival Cruise Line, Ticketmaster, AT&T, McGraw Hill, ADT and gaming company Rockstar.
Cl0p is believed to have earned hundreds of millions of dollars by exploiting previously unknown vulnerabilities in widely used file-transfer products, including those from Cleo, MOVEit, GoAnywhere and Accellion.
Alexander Martin
is the UK Editor for Recorded Future News. He was previously a technology reporter for Sky News and a fellow at the European Cyber Conflict Research Initiative, now Virtual Routes. He can be reached securely using Signal on: AlexanderMartin.79




