One of the world's best-known cybercrime ‌groups hacks its top rivals' dark web site

Newspoint
In an extraordinary public clash between two of the world’s most notorious hacking syndicates, ShinyHunters , famous for its extortion tactics, or ransomware, has claimed that it has successfully hacked the dark web portal of rival cybercrime group Cl0p, bringing a long-running underground feud out into the open, a report said. Known for executing aggressive data theft operations, ShinyHunters stated that it compromised Cl0p’s servers last week by uncovering an unpatched vulnerability in its software stack, using the flaw to establish broad administrative control over the rival group’s digital back-end.
Hero Image

“We basically own them now,” ShinyHunters said during an online exchange with news agency Reuters. While the group’s dark web site had gone completely offline when checked on Sunday (September 20), visitors to the portal on Saturday (September 19) were greeted by a defacement banner reading: “Domain Seized By ShinyHunters,” according to a screenshot archived by threat research hub eCrime.ch.

The report cited security specialists monitoring the incident noted that the takeover appears legitimate. Brandon Parsons , threat intelligence manager at Minnesota-based Ascent Solutions, remarked: “Street beefs on the dark web are a real thing.”

Joe Roosen , senior director of security research at Texas-based SpyCloud , called the direct assault unprecedented: “This was a twist for sure. It is rare I get to see these criminals fight each other.”

Hacking group fighting over Oracle zero-dayAccording to ShinyHunters, the ‘rivalry’ stemmed from the alleged theft of a prized software exploit last year targeting a previously undiscovered vulnerability in Oracle’s E-Business Suite (EBS). Such zero-day vulnerabilities are among the most valuable assets on the black market, offering hackers unrestricted initial entry into protected corporate networks.

A Google security analyst estimated that Cl0p, a Russian-speaking cyber gang, weaponised the Oracle EBS flaw to siphon sensitive files from over 100 corporations. However, ShinyHunters claimed that its own operatives discovered the software bug first.

As the dispute deepened over the past year, Cl0p allegedly threatened to “dox” and unmask the real-world identities of multiple ShinyHunters operators. ShinyHunters fired back with threats to publicly leak the internal mechanics and operational records behind Cl0p’s infrastructure.