ShinyHunters cybercrime gang takes over Cl0p ransomware site, demands extortion payment
The ShinyHunters cybercrime group has taken over the Cl0p ransomware site, demanding a substantial extortion payment and threatening to release details of Cl0p's past victims and payments. This action follows Cl0p's exploitation of vulnerabilities in file-transfer products, leading to significant financial gains for the ransomware group and prompting warnings from Oracle and various cybersecurity agencies. The takeover is part of a larger feud between the two groups stemming from Cl0p's unauthorized use of a vulnerability.
The ShinyHunters cybercrime group has taken over the dark web leak site formerly used by the Cl0p ransomware gang, demanding a substantial extortion payment and threatening to release details of Cl0p's past victims and payments. The site, previously used by Cl0p to name its hacking victims and pressure them into making an extortion payment, was defaced with a banner stating the domain had been seized by ShinyHunters.
Messages posted on the site purportedly from ShinyHunters set an unspecified eight-figure extortion demand, claiming it represented 2.333% of Cl0p’s net worth, implying self-claimed holdings of at least hundreds of millions of dollars. The group also demanded a public apology from Cl0p.
As part of the extortion attempt, the cybercriminals are threatening to release records showing which companies paid Cl0p, how much they paid, and which Bitcoin addresses were used. The attacks on Oracle’s E-Business Suite, a widely used business platform, prompted warnings from Oracle, the FBI and cybersecurity agencies in the United Kingdom and Singapore.
The campaign followed ShinyHunters’ public release of a proof-of-concept exploit for the Oracle vulnerability on Telegram. ShinyHunters said its feud with Cl0p stems from the ransomware group’s unauthorized use of the vulnerability and threats against one of its members.
ShinyHunters disrupted schools across the U.S. in May with an attack on a widely used education platform and stole information belonging to more than 4 million people in an April attack on the world’s largest medical device company. Other victims have included Carnival Cruise Line, Ticketmaster, AT&T, McGraw Hill, ADT and gaming company Rockstar. Cl0p is believed to have earned hundreds of millions of dollars by exploiting previously unknown vulnerabilities in widely used file-transfer products, including those from Cleo, MOVEit, GoAnywhere and Accellion.
