Clop Ransomware Group changes Server and vows Not to Pay ShinyHunters

The ongoing cyber conflict between ransomware groups has taken another turn, with the Clop ransomware operation reportedly moving its data-leak website to a new server after an attack allegedly carried out by the ShinyHunters cybercrime group.

Nearly 10 days ago, ShinyHunters claimed that it had successfully infiltrated infrastructure belonging to the Clop ransomware gang. The group also claimed to have gained access to and defaced Clop’s leak forum, which was hosted as a Tor hidden service and accessible only through the Tor network. Such forums are commonly used by ransomware operators to publish stolen information and pressure victims into paying ransom demands.

The incident initially appeared to represent a significant setback for Clop. However, subsequent developments suggest that the ransomware group has responded by relocating its data-leak infrastructure rather than negotiating with its attackers.

Reports indicate that Clop has moved its leak site to a new address after the previous server was reportedly compromised by exploiting a vulnerability in Grav CMS, a file-based content management system. The alleged exploitation demonstrates how vulnerabilities in publicly accessible software can potentially expose even infrastructure operated by sophisticated cybercriminal organizations.

According to cybersecurity publication BleepingComputer, which was among the first outlets to report on the development, Clop members have reportedly shown no interest in paying a ransom demanded by ShinyHunters. Instead, the group is said to be considering retaliation against those responsible for the intrusion.

The development is notable because ransomware groups generally operate by targeting businesses, government organizations, and other institutions for financial gain. An attack in which one cybercriminal organization targets another highlights the increasingly competitive and hostile nature of the underground cybercrime ecosystem.

The alleged breach also illustrates an important cybersecurity principle- organizations and individuals operating internet-facing services remain exposed to vulnerabilities regardless of their intentions or activities. A weakness in a widely used software platform can potentially become an entry point for attackers if it is not identified and patched in time.

For now, details surrounding the alleged ShinyHunters intrusion remain based largely on claims and reports from cybersecurity sources, and the full extent of the compromise has not been independently established. It is also unclear what information, if any, was accessed or stolen during the incident.

Nevertheless, Clop’s decision to move its infrastructure indicates that the group considers the previous server compromised. Rather than paying ShinyHunters, the group reportedly intends to restore its operations at a different location while potentially planning retaliatory action.

If the reported plans for retaliation materialize, the incident could lead to another round of attacks between the two cybercrime groups. Such developments would further demonstrate how vulnerabilities in underground infrastructure can trigger conflicts between threat actors themselves, creating an unpredictable environment within the broader cybercrime landscape.

Join our LinkedIn group Information Security Community!

Naveen Goud
Naveen Goud is a writer at Cybersecurity Insiders covering topics such as Mergers & Acquisitions, Startups, Cyber Attacks, Cloud Security and Mobile Security

No posts to display