ShinyHunters Breaches and Defaces Rival Clop Ransomware Leak Site with Pokémon Artwork

KnowBe4 lead CISO adviser Javvad Malik said the incident shows that cybercriminal groups are “not a single, coordinated ecosystem,” but competitive businesses whose reliance on “trust, reputation and money” makes betrayal likely.
The Pokémon artwork provided an attribution clue: researcher VXDB matched the Umbreon image to a HackForums defacement from August 2020 that was also claimed by ShinyHunters, although the match is not proof of responsibility.
The breach reportedly began with a smaller warning before the full defacement: ShinyHunters uploaded a text file stating, “THIS SITE HAS BEEN PWN3D BY SHINYHUNTERES #Skids10p - Maybe don't try to threaten us next time,” and linked to its own leak site.
Clop’s criminal track record includes the 2023 MOVEit Transfer campaign, which affected more than 2,000 organizations, as well as earlier campaigns involving GoAnywhere and Accellion.
Security guidance from the reporting recommends that operators of public-facing Grav installations inventory their deployments, update Grav core and plugins with the platform’s package manager, and block PHP execution in writable content directories; the reports identify no specific patched Grav release or CVE for the alleged upload flaw.
Rival ransomware gang ShinyHunters breached and defaced Clop's dark-web leak site, replacing it with Pokémon artwork and extortion demands. BleepingComputer confirmed attackers uploaded malicious files and altered the site. ShinyHunters claims it exploited an unauthenticated file-upload flaw in Grav CMS to steal Clop's source code and private keys, then gave Clop 72 hours to respond before threatening to extort the criminal group.
The attack escalates a long-running feud between the two groups over claims to a zero-day vulnerability in Oracle E-Business Suite servers. KnowBe4's lead CISO adviser noted that cybercriminal groups compete like "businesses driven by trust, reputation and money," making betrayal and extortion among them inevitable.
ShinyHunters exploited an unauthenticated file-upload flaw in Grav CMS, a content management system hosting Clop's Tor-based leak site. The attackers first uploaded a text file reading: "THIS SITE HAS BEEN PWN3D BY SHINYHUNTERES #Skids10p — Maybe don't try to threaten us next time." Within hours, the full site was defaced with Pokémon imagery and redirects to ShinyHunters' own platform.
ShinyHunters claims to have stolen Clop's source code, system logs, authentication records, and private encryption keys for the onion service. However, BleepingComputer emphasized these broader claims remain unverified, and researchers have not independently confirmed whether stolen keys could enable full site impersonation.
Researcher VXDB identified the ASCII Umbreon image used in the defacement as a strong attribution link. The same Pokémon artwork appeared in a ShinyHunters-claimed HackForums defacement from August 2020. While the artistic match is suggestive, it does not constitute proof of responsibility.
Clop orchestrated the 2023 MOVEit Transfer campaign, compromising more than 2,000 organizations worldwide. The gang also launched earlier attacks using GoAnywhere and Accellion vulnerabilities. If ShinyHunters retains access to Clop's stolen data and keys, thousands of existing Clop victims now face secondary extortion demands from a rival group.
Security teams running public-facing Grav installations should immediately inventory their deployments and update Grav core and all plugins using the platform's native package manager. Administrators should block PHP execution in writable content directories to prevent similar upload exploits. No official patched Grav release or CVE number has been assigned to the flaw exploited in this attack, making proactive hardening critical.
Publishers
54
Articles
77
Reach
131