ShinyHunters Hijacks Clop’s Tor Leak Site and Turns Extortion Against Its Operator
ShinyHunters hacked Clop's Tor leak site via Grav CMS flaw, defaced it, claims server logs and onion keys, and threatens 72-hour extortion.
Text generated by artificial intelligence, published without human review. AI transparency
Illustrative image generated with AI
ShinyHunters has compromised and defaced the Tor-based leak site operated by the Clop ransomware group, publicly threatening to extort one of the cybercrime ecosystem’s better-known extortion operations.
The intrusion moved beyond an unsupported claim. Reporting published on September 19, 2026, independently confirmed that ShinyHunters uploaded a file to Clop’s server and subsequently replaced the site’s content with a defacement under its control.
More extensive claims remain unverified. ShinyHunters says it obtained server logs, source code, Grav CMS plugins and the private keys associated with Clop’s onion service. If genuine, that material could expose Clop’s operators and let ShinyHunters impersonate the leak site at its established Tor address.
The compromise began with an unauthenticated upload
ShinyHunters said the intrusion started on a Friday night through an unauthenticated file-upload vulnerability in Grav CMS, the content management system running on Clop’s leak-site infrastructure.
The exact Grav CMS vulnerability has not been disclosed. No CVE identifier, affected version range or vendor advisory is available, so it is not known whether ShinyHunters exploited a flaw in the CMS itself, a plugin, or Clop’s particular configuration.
The first externally verified sign was a small text file uploaded to the leak site. The file was accessible directly from Clop’s Tor service, demonstrating that the attacker could place content on infrastructure controlled by the ransomware operation. Its message identified ShinyHunters, warned Clop against threatening the group and directed visitors to ShinyHunters’ own leak site.
Several hours later, Clop’s page began serving a complete defacement. It displayed ASCII artwork depicting Umbreon—the Pokémon used as a ShinyHunters emblem—a link to the group’s Tor site and the message: “rooting your systems since ’19 ;)”.
Cybersecurity researcher VXDB observed that the artwork matched imagery used during the August 2020 defacement of HackForums, which ShinyHunters also claimed at the time.
The file upload and altered page were independently verified through Clop’s service. They establish unauthorized write access but do not, by themselves, prove that ShinyHunters gained administrative or root-level control of the underlying server.
Claims of stolen logs and Tor identity keys raise the stakes
ShinyHunters described its access as complete and claimed to have copied source code, Grav CMS plugins, other server data and every file under /var/log. It said it was still downloading and examining the material.
Those claims have not been independently validated.
Linux systems commonly use /var/log for records associated with authentication, services, application errors and network activity. The precise contents depend on the host’s configuration. If Clop retained detailed access records, the stolen files could contain administrative events, connection information or IP addresses associated with people who visited or managed the service.
The potential exposure extends beyond Clop’s operators. Journalists, researchers, victims, negotiators and other visitors may have accessed the leak site. Whether any of their information appears in the allegedly stolen logs is unknown.
ShinyHunters also says it obtained the private keys for Clop’s onion service. Tor onion addresses are cryptographically tied to their key material. Valid service keys could therefore enable another operator to present a replacement service under Clop’s existing address, even after access to the original server was revoked.
Such a takeover would create several risks. Visitors might believe they were communicating with Clop when they were instead reaching infrastructure controlled by ShinyHunters. The replacement site could distribute false claims, collect messages or redirect victims and negotiators.
This scenario depends entirely on whether the keys are authentic, complete and usable. No independent evidence currently confirms that they were stolen.
A dispute between criminal groups becomes an extortion attempt
ShinyHunters said it plans to publish an extortion demand instructing Clop to make contact within 72 hours. That turns a technique usually directed at companies and public institutions against another extortion operation.
According to ShinyHunters, the intrusion was retaliation for threats allegedly made by a Clop representative. The group claims the conflict grew from Clop’s Oracle E-Business Suite data-theft campaign in October 2025.
During that campaign, Clop exploited several Oracle E-Business Suite vulnerabilities, including CVE-2025-61882, to steal organizational data for extortion. Actors using the “Scattered Lapsus$ Hunters” name, including ShinyHunters, published a proof-of-concept exploit around the same period. Oracle later confirmed that the proof of concept matched an exploit used in the Clop attacks.
ShinyHunters alleges that the exploit originally belonged to its members and that Clop obtained it without authorization. It further claims that a Clop representative threatened to identify and kill members of the group.
Those allegations have not been independently verified, and no response from Clop was available in the reporting. The confirmed evidence is narrower: ShinyHunters placed a file on Clop’s infrastructure and took control of the content shown by the leak site.
CVE-2025-61882 remains an active enterprise risk
The Grav CMS weakness allegedly used against Clop is separate from CVE-2025-61882. The latter is relevant because it sits at the center of the dispute and remains a serious risk for Oracle E-Business Suite operators.
CVE-2025-61882 affects the BI Publisher Integration component of Oracle Concurrent Processing in Oracle E-Business Suite. Affected versions are Oracle Concurrent Processing 12.2.3 through 12.2.14.
An unauthenticated attacker with HTTP network access can exploit the vulnerability remotely and potentially take over Oracle Concurrent Processing. It has a CVSS 3.1 score of 9.8 and the vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The classification is CWE-287, indicating an authentication problem. Exploitation requires neither privileges nor user interaction, while the expected confidentiality, integrity and availability impacts are all rated high.
CISA added CVE-2025-61882 to its Known Exploited Vulnerabilities catalog on October 6, 2025. The remediation deadline for US federal civilian agencies was October 27, 2025, and the catalog records the vulnerability as used in ransomware campaigns.
CISA requires organizations to apply Oracle’s mitigations, follow applicable BOD 22-01 guidance for cloud services, or discontinue the product when mitigations are unavailable.
This is not Oracle’s only recent appearance in the KEV catalog. Three other vulnerabilities associated with the vendor were added during the last 90 days: CVE-2026-46817 on July 15, 2026, CVE-2026-21962 on August 24, 2026, and CVE-2015-5287 on August 26, 2026.
What defenders should examine
Organizations running the affected Oracle E-Business Suite versions should prioritize vendor-provided patches or mitigations, particularly where Oracle Concurrent Processing or BI Publisher Integration is reachable over HTTP.
Security teams should review web and authentication logs for unauthenticated requests targeting the affected functionality. Investigations should also look for unexpected configuration changes, unauthorized administrative activity, anomalous access to business data and evidence that Oracle Concurrent Processing was modified or taken over.
Potentially compromised systems should have relevant evidence preserved before remediation. CISA marks forensic triage under BOD-26-04 as not required for this entry, but that designation does not rule out incident-specific evidence collection where exploitation is suspected.
For Grav CMS operators, the immediate guidance is less precise because the exploited condition, affected versions and patch status have not been disclosed. Administrators should restrict unnecessary access, inspect upload functionality and plugins, and review files and web content for unauthorized changes. The Clop incident shows that even a small unauthorized upload can become a path to public content control.
Confirmed damage is narrower than the most serious claims
ShinyHunters has demonstrated that it could modify Clop’s extortion platform and publicly undermine the group’s control over its own infrastructure. That alone damages the reliability of the site Clop uses to pressure victims.
The more consequential possibilities remain unresolved. There is no independent confirmation that ShinyHunters stole /var/log, acquired source code or obtained the onion-service keys. Nor is there evidence yet that it has successfully recreated Clop’s service elsewhere.
For now, the incident is a verified leak-site compromise surrounded by broader actor claims. If the alleged key and log theft is substantiated, it would become an intelligence breach of Clop’s operational infrastructure—not merely a defacement between rival cybercrime groups.
Sources
This article is an original reworking based on the sources below.
- primary sourceCISA
- BleepingComputer
CVEs covered in this article
- CVE-2026-21962Critical10.0Vulnerability in the Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in product of Oracle Fusion Middleware (component: Weblogic Server Proxy Plug-in for Apache HTTP Server, Weblogic Server Proxy Plug-in for IIS). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0 and 14.1.2.0.0
- CVE-2026-46817Critical9.8Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Payments. Successful a
- CVE-2025-61882Critical9.8Vulnerability in the Oracle Concurrent Processing product of Oracle E-Business Suite (component: BI Publisher Integration). Supported versions that are affected are 12.2.3-12.2.14. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Con
- CVE-2015-5287High7.8The abrt-hook-ccpp help program in Automatic Bug Reporting Tool (ABRT) before 2.7.1 allows local users with certain permissions to gain privileges via a symlink attack on a file with a predictable name, as demonstrated by /var/tmp/abrt/abrt-hax-coredump or /var/spool/abrt/abrt-hax-coredump.
