Hackers hacked the hackers: ShinyHunters takes over Russian gang cl0p's dark web site
One of the world's most notorious cybercriminal groups, ShinyHunters, claimed on Sunday that it had taken control over the dark web site of its main rival, the Russian-speaking gang cl0p. The move brought a long-simmering feud between the two gangs into public view, Reuters reported.
ShinyHunters, known for its aggressive data theft campaigns and specializing in digital extortion, said it broke into cl0p's site on Friday after finding a flaw in the rival group's software and using it to gain extensive control over its infrastructure.
"We basically own them now"
the group told Reuters in an online conversation. cl0p did not respond to repeated inquiries from the news agency. The site was inaccessible on Sunday, and on Saturday it displayed the message "Domain seized by ShinyHunters," according to a screenshot captured by the cybercrime research platform eCrime.ch. Reuters could not independently verify ShinyHunters' account. Two cybersecurity experts said the clash appeared to be genuine. "Turf wars are part of the reality on the dark web," said Brandon Parsons, head of threat intelligence at Ascent Solutions in Minnesota. Joe Roosen, director of security research at SpyCloud in Texas, said he had never seen two cybercriminal groups turn on each other so openly before. "It really was an unexpected turn. I rarely see these criminals fighting each other."
According to ShinyHunters, the feud began last year when cl0p allegedly stole an attack tool from it that exploited a previously unknown flaw in the Oracle E-Business Suite enterprise resource planning software. Such flaws, known as zero-day vulnerabilities—named because defenders have "zero days" to fix them—are especially prized by hackers because they can grant nearly unrestricted access to vulnerable networks. According to cybersecurity analysts at Google, starting in late September 2025 attackers tried to extort victims through a mass email campaign launched from hundreds of compromised third-party accounts. A Google analyst estimated that cl0p stole data from more than a hundred companies by exploiting the flaw; ShinyHunters claims it discovered the vulnerability first. The dispute escalated to the point where, according to ShinyHunters, cl0p threatened to expose the identities of several of its members, while ShinyHunters intended to leak details of cl0p's internal operations.
cl0p is considered one of the world's most prolific and inventive cybercriminal groups, largely because of its skill at identifying and exploiting flaws in corporate software. In 2023, it exploited a vulnerability in the file-transfer software MOVEit to steal data belonging to tens of millions of people from more than six hundred companies. Last month, it claimed to have obtained large volumes of data from nearly fifty companies worldwide, including Philips, Shell, Fiserv and GE. ShinyHunters is similarly active. In April, it made headlines after claiming to have stolen millions of business records from Rockstar Games, the developer of the Grand Theft Auto series, and in May it launched an attack on Instructure, the company that runs the Canvas education platform, causing widespread disruption in American schools. The group has also been linked to an attack on RingCentral and the recent cyberattack on Manchester Airports Group.
In a report published on September 10, artificial intelligence developer Anthropic said it had identified and shut down several financially motivated cybercriminal groups it suspects are affiliated with ShinyHunters. According to the report, these groups used the Claude models to speed up target reconnaissance, exploit vulnerabilities and take over systems. One member, using the French-language alias "frkoo," built an automated system across ten cloud servers that downloaded, decompiled and scanned 1.8 million Android applications in search of embedded passwords and access keys. The data obtained this way was later used in confirmed breaches, including one in which the hackers gained access to the data of about two hundred customers of a software service provider by breaching it. Anthropic said it had disabled the accounts and strengthened its defense mechanisms.
Ugar
Tetszett a cikk?
Támogassa a munkánkat egy kis adománnyal
Biztonságos fizetés Stripe-on keresztül • Min. 2 EUR
Gesta-ajánló:

A Georgescu-polip: nincs itt semmi orosz szál, csak egy kis Dugin
Călin Georgescu hívei tegnap óta azt harsogják a TikTokon, hogy a DIICOT ügye koholmány, az egymillió eurós csalás a „rendszer" bosszúja, Oroszországnak pedig semmi köze az egészhez. Hát persze, hogy semmi. Legfeljebb annyi, hogy a pénz az ügyészség szerint egy orosz kézben lévő bankon keresztül vándorolt a bűntársak számláira. Meg annyi, hogy az ember, aki a megkárosított üzletembert…

Hackerek törték fel a hackereket: a ShinyHunters átvette az orosz cl0p sötét webes oldalát
A világ egyik legismertebb kiberbűnözői csoportja, a ShinyHunters vasárnap azt állította, hogy átvette az irányítást fő riválisa, az orosz nyelvű cl0p sötét webes (dark web) oldala fölött. A lépés nyilvánosság elé hozta a két banda közötti régóta húzódó viszályt – írta a Reuters.

Szele Tamás: A menekülő forgatócsoport esete
Valamikori, nagyon kedves, sajnos már megboldogult főszerkesztőnőm egyik legtöbbet hangoztatott mondása jut eszembe, akkor szokta elővenni, ha valami borzalmas hibát látott egyik-másik sajtó(vég)termékben: „Ez valaha egy szakma volt...”

Nulla kockázat, száznál több ország: így építené fel a Revolut a globális bankot
Nik Storonsky, a Revolut alapítója és vezérigazgatója a Financial Timesnak adott hétfői interjújában felvázolta, milyen globális bankot szeretne építeni. A modell lényege, hogy a cég a betéteknek csak töredékét helyezné ki hitel formájában, így Storonsky szavaival „gyakorlatilag nulla kockázatot" vállal. A terv abban az időszakban kerül nyilvánosság elé, amikor a londoni fintechcég sorra szerzi…

Három éves szankció-hosszabbítás, de Magyarország támogatásával lekerült a listáról Fridman és Uszmanov
Az Európai Unió tagállamai kedden három évre meghosszabbították a csaknem háromezer orosz magánszemélyt és szervezetet érintő egyéni szankciókat, a listáról azonban lekerült két, Moszkvához közel állónak tartott milliárdos: Aliser Uszmanov orosz-üzbég üzletember és Mihail Fridman orosz oligarcha. A megállapodás csak az utolsó pillanatban született meg, miután Lettország hétfő este még megvétózta…