°C
Air:
GOLD73,245 0.25%
SILVER84,520 0.29%
USD83.25 0.12%
EUR90.45 0.08%
GBP105.6 0.15%
ShinyHunters Claims Hijack of Rival Cl0p Dark Web Site Amid Cybercrime Dispute
Cyber Security

ShinyHunters Claims Hijack of Rival Cl0p Dark Web Site Amid Cybercrime Dispute

0 views
Text Size:

Organisations using business-critical applications should maintain security updates, monitor unusual activity and follow guidance issued by software vendors and security researchers.

A highly unusual dispute between two cybercrime groups has emerged publicly on the dark web after ShinyHunters claimed that it had taken control of a website operated by the rival Cl0p group. The incident has attracted attention because cybercriminal organisations generally operate in secrecy, making an openly reported confrontation between two major groups relatively uncommon.

According to Reuters, ShinyHunters said it breached Cl0p’s dark web site after discovering a vulnerability in the rival group’s software. The group claimed that the vulnerability allowed it to obtain extensive control over Cl0p’s infrastructure. ShinyHunters also told Reuters that it now had control over the rival group’s operations, although the full extent of that access could not be independently established.

The incident became more visible when Cl0p’s dark web website reportedly displayed a message stating that the domain had been seized by ShinyHunters. The website was later inaccessible when Reuters attempted to access it. A screenshot preserved by the cybersecurity research platform eCrime.ch reportedly showed the seizure message.

Cybersecurity specialists who spoke to Reuters said the confrontation appeared to be genuine. However, Reuters also noted that it could not immediately verify all of ShinyHunters’ claims about how the dispute began or the precise extent of the compromise.

The reported conflict is connected to a dispute over a zero-day vulnerability involving Oracle’s E-Business Suite, commonly known as Oracle EBS. A zero-day is a previously unknown software vulnerability that can be exploited before the affected software developer or security teams have had an opportunity to fully address it.

ShinyHunters claims that it discovered the Oracle EBS vulnerability before Cl0p and that Cl0p later obtained and used the exploit. According to the group, the disagreement over the exploit became a major source of tension between the two cybercrime organisations.

Cl0p has previously been associated with large-scale attacks involving vulnerabilities in enterprise software. Reuters reported that the group used an Oracle EBS vulnerability to steal data from more than 100 companies, based on an estimate from a Google analyst. Cl0p has also gained international attention for exploiting vulnerabilities in file-transfer platforms.

One of the most notable examples was the 2023 MOVEit campaign. Cl0p exploited a vulnerability in MOVEit Transfer and used it to obtain data from a large number of organisations. The campaign affected hundreds of companies and exposed information belonging to millions of individuals.

ShinyHunters has also been involved in major data theft and extortion campaigns. The group has attracted attention for claiming responsibility for breaches involving large quantities of corporate information. Its activities have included attacks against organisations in different sectors and have made the group a significant subject of cybersecurity investigations.

The latest confrontation demonstrates that cybercrime groups can also become targets of attacks from other criminal organisations. Cybercriminal operations depend heavily on websites, communication systems and other digital infrastructure to publish stolen data and communicate with victims. If those systems are compromised, a criminal group can potentially lose control of an important part of its operation.

The dispute also highlights the importance of vulnerabilities in software used by organisations and criminal groups alike. A vulnerability that is exploited against one target can potentially be reused against other systems if adequate security measures are not in place.

There are also questions about the claims made by ShinyHunters regarding the depth of its access to Cl0p’s infrastructure. Some reports have described claims involving source code, server information and other internal material. However, such claims should be treated carefully unless independently confirmed by cybersecurity researchers or other reliable evidence.

Cl0p had not responded to repeated requests for comment at the time of Reuters’ reporting. As a result, the public account of the dispute largely comes from ShinyHunters and observations of the affected website.

The incident is being closely monitored by cybersecurity researchers because any leaked information from the confrontation could potentially provide insight into how major cybercrime groups organise their operations. It could also reveal information about infrastructure, communication methods or previous criminal campaigns.

At the same time, a conflict between cybercriminal groups does not necessarily eliminate the broader threat they pose. Even if one group's infrastructure is disrupted, individuals involved in cybercrime can move to new platforms, create replacement infrastructure or reorganise into smaller groups.

For businesses and cybersecurity teams, the episode serves as another reminder that vulnerabilities in enterprise software can have significant consequences. Organisations using business-critical applications should maintain security updates, monitor unusual activity and follow guidance issued by software vendors and security researchers.

The ShinyHunters and Cl0p confrontation remains an evolving cybersecurity story. The website takeover has been observed and reported, but several of the competing claims surrounding the origin of the dispute and the extent of the compromise remain unverified. Further investigation by cybersecurity researchers and law enforcement agencies could provide more clarity about what information was accessed and how the attack was carried out.

A zero-day is a previously unknown software vulnerability that can be exploited before the affected software developer or security teams have had an opportunity to fully address it.