Interestana
Home/News/ShinyHunters Exploits Grav CMS Flaw to Hack Clop Leak Site
BleepingComputer••3 min read

By Interestana AI Editorial — AI-drafted, human-overseen. How we report

ShinyHunters Exploits Grav CMS Flaw to Hack Clop Leak Site

The Clop ransomware gang's data leak site, previously hosted at a Tor address, was compromised and defaced by threat actor ShinyHunters. This breach occurred due to an unpatched Grav Content Management System (CMS) flaw, identified as an unauthenticated path traversal vulnerability. BleepingComputer learned of the specific vulnerability exploited in the attack. The Clop gang confirmed the compromise of their server and subsequently moved their data leak operations to a new Tor address. This incident highlights the ongoing risks associated with unpatched vulnerabilities in widely used CMS platforms, even for sophisticated cybercriminal organizations.

Grav CMS is a popular flat-file CMS known for its flexibility and ease of use, making it a common choice for websites that do not require a traditional database. Its flat-file architecture stores content and configuration in files and folders, which can simplify backups and migrations. However, like any software, it is susceptible to security vulnerabilities if not kept up-to-date. Path traversal, also known as directory traversal, is a web security vulnerability that allows an attacker to access files and directories that are outside of the web root folder. This can be achieved by manipulating variables that reference files with "dot-dot-slash" (../) sequences, or variations thereof, that move up the directory tree. An unauthenticated path traversal vulnerability means that an attacker does not need to log in or possess any special privileges to exploit the flaw, significantly lowering the barrier to entry for attackers.

ShinyHunters is a threat actor group known for its involvement in data breaches and for selling stolen data on various forums. Their modus operandi often involves identifying and exploiting vulnerabilities in web applications to gain access to sensitive information. The targeting of the Clop gang's data leak site is a notable development, as it represents a direct attack on the infrastructure of another cybercriminal entity. This type of inter-criminal conflict, while not entirely unprecedented, can have ripple effects within the cybercrime ecosystem. The Clop ransomware gang itself is a significant player in the ransomware landscape, known for its "big game hunting" tactics, which involve targeting large organizations for substantial ransom payments. They have been linked to numerous high-profile attacks, often using sophisticated methods to exfiltrate data before encrypting it, a tactic known as double extortion.

The defacement of the Clop leak site suggests that ShinyHunters gained administrative control over the Grav CMS instance hosting the site. This allowed them to alter the content displayed on the site, likely as a demonstration of their capabilities or as a form of disruption. The Clop gang's swift response in migrating to a new address indicates their operational resilience, but the incident underscores the inherent insecurity of even the digital underground. The reliance on Grav CMS, even for cybercriminal operations, means they are subject to the same security challenges faced by legitimate organizations. The unpatched nature of the vulnerability is a critical factor, emphasizing the universal importance of regular software updates and security patching for all internet-facing systems, regardless of the owner's intent.

Original source — read the full reporting at the publisher:

Read on BleepingComputer

Get the weekly AI digest

AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.

Read next