ShinyHunters hijacks Clop's dark-web leak site and steals its Tor private keys
ShinyHunters defaced the Clop ransomware gang's Tor leak site via a Grav CMS path-traversal flaw and claimed to have stolen source code, server logs and the site's onion private keys.
- Victim
- Clop
On 19 September 2026, the data-extortion group ShinyHunters was reported to have hijacked the dark-web leak site of Clop (also written Cl0p), one of the most prolific ransomware and mass-extortion operations, in a rare public feud between two cybercrime crews.
The intrusion began on 18 September, when ShinyHunters exploited a path-traversal vulnerability in Grav CMS β the content-management system running Clop's Tor site β tracked as CVE-2026-42608. The bug had been fixed in the Grav 2.x branch earlier in 2026 but was never backported to the older 1.7 line, leaving Clop's 1.7.43 deployment exposed. After first demonstrating access by uploading a taunting text file, the group defaced the site with its own branding and ASCII mascot.
From defacement to extortion
ShinyHunters subsequently claimed on its own leak site to have exfiltrated source code, Grav plugins, server logs and the private keys for Clop's onion service β material that, if genuine, would let it impersonate or dismantle the gang's infrastructure. It issued an eight-figure extortion demand with a 72-hour deadline, inverting the pressure tactics ransomware crews normally aim at their victims.
A criminal-on-criminal breach
The episode is unusual because the victim is itself a criminal enterprise: Clop, widely attributed to a Russian-speaking group tied to the TA505 cluster, has extorted hundreds of organizations through mass-exploitation campaigns. The compromise of its leak-site keys raised questions about the fate of data Clop had stolen from its own victims, though neither group's claims could be independently verified. With the standoff unresolved, the incident's status remained unknown.
Timeline
ShinyHunters exploits a Grav CMS path-traversal flaw (CVE-2026-42608) on Clop's Tor site, uploading a taunting file to demonstrate access.
The compromise escalates into a full defacement and public extortion demand, with ShinyHunters claiming to hold Clop's source code, logs and onion private keys.
Sources
- bleepingcomputer.comhttps://www.bleepingcomputer.com/news/security/shinyhunters-hacked-clop-leak-site-using-grav-cms-path-traversal-flaw/
- socradar.iohttps://socradar.io/blog/clop-hack-shinyhunters-hijacks-data-leak-site/
- darkreading.comhttps://www.darkreading.com/cyberattacks-data-breaches/shinyhunters-hacked-clop-what-about-clops-victims