• 5 minuti
  • Pubblicato

Ransomware gangs turn on each other in dark web sabotage

Barbara Carminati Autrice di cybersecurity e privacy QWERTYmag

Scritto da Barbara Carminati

Ransomware gangs turn on each other in dark web sabotage QWERTYmag © www.qwertymag.it
Ransomware gangs turn on each other in dark web sabotage © www.qwertymag.it

ShinyHunters hijacked Clop's leak site, setting off a fierce cyber feud that lays bare the cutthroat rivalries and shaky alliances inside the ransomware world. The fallout is hitting not just criminals, but also companies caught in the middle.

Clop's dark web leak site, once used to squeeze money from big companies, was suddenly taken over and defaced by ShinyHunters in September 2026. The site flashed a blunt message: "Domain Seized by ShinyHunters." Then it disappeared. This was a rare, public act of sabotage between cybercrime groups. Reuters reported that ShinyHunters claimed they had taken control of Clop's systems by finding and using a software flaw. Their message was clear: "We basically own them now."

This wasn't random vandalism. ShinyHunters said they found a weakness in Clop's backend and used it. Cybersecurity analysts confirmed the attack. The Register wrote that Clop's leak site went offline, replaced by the defacement page. It was both a warning and a show of technical muscle. Direct attacks like this between ransomware gangs don't happen often. It shows how the fight for power in the cybercrime world is heating up.

La posta in gioco: denaro, risorse e reputazione

This feud started over a stolen "zero-day" exploit in Oracle's E-Business Suite. ShinyHunters accused Clop of stealing the exploit-some sources link it to CVE-2025-61882-and using it to hack data from more than 100 companies. In response, ShinyHunters hijacked Clop's leak site and demanded a ransom in the eight-figure range. At first, they asked for 2.333% of Clop's estimated net worth. Later, they raised the stakes, demanding "all the money you made off the EBS campaign plus more AND WITH INTEREST," as reported by The Register.

For ransomware gangs, every exploit, affiliate, and victim is a prize. The criminal economy runs on competition for these assets. When trust breaks down, technical payback is the only option. These groups can't use contracts or courts. Their only currency is reputation and fear. The timing of the attack matched Oracle's September 2026 Critical Patch Update. It's a reminder that patching and quick vulnerability fixes matter for everyone, even criminals.

La vicenda dimostra come la mancata applicazione tempestiva delle patch critiche possa esporre infrastrutture anche criminali a rischi di compromissione, confermando la necessità di una gestione proattiva delle vulnerabilità secondo le linee guida ACN.

Quando i criminali diventano bersagli

The fight between ShinyHunters and Clop is more than a grudge match. It shows how fragile alliances are in the ransomware world. Affiliates jump ship. Stolen exploits get passed around. Hitting a rival's systems can bring in new intelligence, disrupt business, and show who's on top. But it also risks leaking sensitive data-details about victims, ransom talks, and payments. That can drag old victims back into danger. ShinyHunters even threatened to publish the names of companies that paid Clop, including how much and which Bitcoin addresses were used. That could bring regulatory trouble and damage reputations for those companies.

Both Clop and ShinyHunters have pulled off big hacks. Clop went after Shell and GE. ShinyHunters hit Rockstar Games and U.S. education platforms. Their public fight marks a shift from quiet rivalry to open war. The dark web is now a battlefield. Italy's Garante Privacy has warned that leaking ransom talks and payment data can trigger GDPR probes and force companies to report breaches. That makes things even harder for victims.

Il ciclo cannibalistico del ransomware

Ransomware groups are getting more professional. Their tactics keep changing. Rebranding is now a way to survive. Groups pick new names, set up fresh infrastructure, and switch payment systems to dodge law enforcement and AI detection. Ransomware attacks are rising fast-from 1,186 in 2024 to 1,885 in just the last three months. Disruptions don't wipe these groups out. They just adapt. GodDamn Ransomware and Helix, for example, have kept going under new names, showing that rebranding often hides the same people and methods.

Cybercriminals now use deepfakes, social engineering, and malware that disables security. Rebranding is also a way to market themselves on dark web forums. Law enforcement crackdowns can backfire. Evil Corp simply changed its name to avoid sanctions. The criminal world doesn't shrink under pressure-it changes shape.

Implicazioni per le aziende e la difesa

For companies, these fights between criminal groups are not just background noise. When one gang hacks another, stolen data about victims and ransom talks can resurface. That puts companies at risk again, even if they thought their ordeal was over. As a recent analysis points out, boardrooms that don't grasp how complex and unstable the ransomware world is are leaving themselves wide open.

The ShinyHunters-Clop fight shows that the lines in cyber warfare are breaking down. Criminals are now both attackers and targets. The fallout can easily hit legitimate companies. Defenders need to see that every breach-criminal or not-can spark new threats. In this world, only constant adaptation keeps you safe. The message is simple: in the ransomware game, letting your guard down is deadly. The next attack could come from anywhere.

Articoli correlati