The notorious Clop ransomware gang has been forced to relocate its data leak operations to a new Tor address following a significant security breach of its previous server. This incident, confirmed by BleepingComputer, was exploited through an unpatched vulnerability in the Grav Content Management System (CMS), specifically an unauthenticated path traversal flaw. The breach, attributed to the ShinyHunters extortion group, highlights the persistent threat posed by unaddressed software vulnerabilities, even to sophisticated cybercriminal organizations.
The initial compromise of the Clop leak site occurred earlier this month, when ShinyHunters gained unauthorized access. The attackers first posted a small text file before escalating their defacement to a full-page display featuring the ShinyHunters’ Umbreon Pokémon logo. This prominent visual was accompanied by a direct link to ShinyHunters’ own data leak platform, effectively turning Clop’s infrastructure against them.
Following the defacement, ShinyHunters made further claims on its platform, asserting that it had successfully exfiltrated sensitive data from Clop’s compromised server. This alleged stolen information included source code, custom Grav CMS plugins, server logs, and crucially, the private keys associated with Clop’s Tor onion service. Armed with this perceived leverage, ShinyHunters issued a ransom demand, threatening to publicly release the purloined data if Clop did not comply with their financial demands.
In response to the breach and the subsequent extortion attempt, Clop has publicly announced a new onion address for its operations. The gang stated that their previous domain would remain accessible for a limited period before being permanently decommissioned. This move signifies a strategic effort to regain operational control and distance themselves from the compromised infrastructure.
Clop has vehemently denied any affiliation or ongoing dialogue with the ShinyHunters group. In a statement to BleepingComputer, a Clop representative declared, "We do not know them, we have never worked with them, and at the moment we are not in contact with them; furthermore, we have not provided them with any information, nor will we do so—either now or in the future." This assertion aims to distance the ransomware group from the perceived embarrassment and potential internal ramifications of such a breach.
When questioned about the specific method of intrusion, Clop acknowledged that its Grav installation had not been kept fully up-to-date. This admission directly corroborates the technical findings regarding the unpatched vulnerability. However, the Russian-based ransomware gang disputes the extent and value of the data allegedly stolen by ShinyHunters. Clop contends that the compromised server held no critical operational or financial information.
"We didn’t update the Grav plugin—though it happened eventually—but the server contained nothing but content (meaning there was absolutely no data or financial activity there, nor could there have been). Therefore, their claim is worthless—as are their words," Clop communicated. This statement suggests Clop believes ShinyHunters’ claims of significant data theft are exaggerated or fabricated, potentially as a tactic to increase pressure or gain credibility.

Despite Clop’s claims of no communication, an analysis of ShinyHunters’ data leak site revealed that Clop’s listing was quietly removed. This action is often interpreted within the cybersecurity community as an indicator that negotiations, or at least some form of interaction, may be taking place behind the scenes, even if publicly denied. When approached for comment on this discrepancy, ShinyHunters declined to provide further details, stating they did not wish to answer additional questions on the matter.
Grav CMS Confirms Vulnerability Exploited in Clop Breach
The Grav CMS development team has officially confirmed the accuracy of the vulnerability and exploitation details shared by ShinyHunters. The attack vector exploited an unauthenticated path traversal vulnerability within the Grav CMS, specifically impacting its form upload handling mechanisms.
ShinyHunters initially reported that the compromised Clop server was running Grav CMS version 1.7.43. They detailed how an unauthenticated file upload flaw allowed them to bypass security measures. The vulnerable code, according to ShinyHunters, improperly handled values submitted through form-related POST parameters when creating temporary upload directories. Crucially, these values were not adequately validated as safe filesystem path components before being incorporated into directory creation commands.
The attackers identified the __unique_form_id__ parameter as a key element in their exploit. By manipulating this parameter, they could influence the creation of temporary directories. The intended path for uploads was structured as tmp/forms/<session_id>/<unique_id>. However, by injecting directory traversal sequences, such as ../../../shhq, into the __unique_form_id__ parameter, ShinyHunters were able to instruct Grav to create directories outside the intended tmp/forms scope. This allowed them to place uploaded files in arbitrary locations within the Grav installation.
Upon receiving the technical details of the exploitation from BleepingComputer, Grav developers corroborated the threat actor’s findings. "Yes, it’s a legitimate flaw, and the threat actor’s description is accurate," a Grav spokesperson confirmed.
The vulnerability has been officially cataloged as CVE-2026-42608 and is classified as a path traversal vulnerability. It was initially reported privately and subsequently addressed in Grav version 2.0 (specifically, 2.0.0-beta.2) earlier this year. A public advisory detailing the vulnerability was published on April 27th.
The fix implemented by Grav involves the introduction of a sanitizeId() function. This function strictly enforces an allowlist for accepted identifier characters, permitting only those matching the regular expression [A-Za-z0-9,_-]1,64. This sanitization process effectively prevents the injection of malicious path traversal sequences. Grav confirmed that this mitigation strategy aligns precisely with the exploitation method described by ShinyHunters.
However, a critical oversight meant that while newer Grav 2.x releases were already protected, this crucial fix had not been backported to the widely used older Grav 1.7 branch. This gap left installations such as Clop’s running version 1.7.43 susceptible to attack. "The gap was the 1.7 line," Grav explained. "Grav 2.0 is the current major version, but plenty of sites are still on 1.7, and that fix hadn’t been backported there yet."

Following the notification from BleepingComputer regarding the exploitation of this unpatched 1.7.x version, Grav developers acted swiftly. They backported the necessary fix to the 1.7 branch, releasing Grav version 1.7.53.4 yesterday. This urgent update aims to secure the extensive user base still operating on the older branch.
Grav also clarified a common point of confusion: the vulnerability resides within the Grav core system itself, not specifically within the Form plugin. "The bug lives in Grav core, not the Form plugin, so the Form plugin version (7.3.0 in their example) doesn’t change whether a site is vulnerable. It’s the core version that matters," the developers emphasized. This distinction is vital for users to understand when assessing their exposure and applying the correct updates.
Grav strongly urges all users still running the 1.7 branch to upgrade to the patched version 1.7.53.4 immediately. Users of current Grav 2.x releases have been protected against this specific vulnerability for several months.
Broader Implications and Chronology of Events
The incident involving Clop and ShinyHunters underscores a broader trend in the cybercrime landscape: the increasing sophistication and interconnectivity of threat actors. The fact that a prominent ransomware group, known for its extensive victim base and operational capabilities, could be compromised by another hacking collective highlights several key points:
- The Ever-Present Threat of Unpatched Systems: Despite the advanced nature of many cybercriminal operations, the fundamental principle of maintaining up-to-date software remains a critical vulnerability. As demonstrated, even a single unpatched plugin or core component can provide a critical entry point for attackers.
- The Evolving Tactics of Extortion Groups: ShinyHunters, operating as an extortion group, has demonstrated a willingness to target other malicious actors. This suggests a potential shift towards a more complex ecosystem of cybercrime, where groups may engage in "hacking the hackers" to extract further profit or disrupt rival operations.
- The Potential for Internal Disruption: A successful breach of a ransomware gang’s infrastructure, particularly if sensitive operational data or private keys are compromised, can have significant internal repercussions. This could lead to loss of trust, internal power struggles, or even the collapse of the group.
- The Importance of Transparency (and its Limits): While Clop has publicly denied contact with ShinyHunters, the removal of their listing from ShinyHunters’ site suggests otherwise. This highlights the often-opaque nature of cybercriminal negotiations and the strategic use of public statements for misdirection or reputational management.
Timeline of Events:
- Prior to Early December 2024: Clop ransomware gang’s data leak site is running on a Grav CMS 1.7.43 installation that has not been updated to include a critical security patch for an unauthenticated path traversal vulnerability.
- Early December 2024: ShinyHunters extortion group exploits the unpatched Grav CMS vulnerability to gain unauthorized access to the Clop data leak site server.
- Early December 2024 (Initial Phase): ShinyHunters uploads a small text file to the Clop site.
- Early December 2024 (Escalation): ShinyHunters replaces the Clop site with a full-page defacement, featuring their Umbreon Pokémon logo and a link to their own data leak site.
- Early December 2024 (Claims and Demands): ShinyHunters claims to have stolen source code, Grav CMS plugins, server logs, and private keys from Clop’s server. They issue a ransom demand, threatening to leak the stolen data.
- Mid-December 2024: Clop confirms the breach and announces a new Tor onion address for its operations, stating the old domain will be retired.
- Mid-December 2024: Clop denies any relationship or negotiations with ShinyHunters and disputes the value of the stolen data.
- Mid-December 2024: Clop’s listing is quietly removed from ShinyHunters’ data leak site. ShinyHunters declines to comment.
- Mid-December 2024: Grav CMS confirms the unauthenticated path traversal vulnerability (CVE-2026-42608) used in the attack and confirms the accuracy of ShinyHunters’ exploitation details.
- Mid-December 2024: Grav developers backport the fix for CVE-2026-42608 to the Grav 1.7 branch, releasing version 1.7.53.4.
The incident serves as a stark reminder for all organizations, regardless of their nature, to prioritize robust cybersecurity practices, including regular software updates and vulnerability management. The attack on Clop’s infrastructure, while targeting a criminal entity, carries lessons applicable to legitimate businesses facing similar threats from sophisticated adversaries. The interconnectedness of the digital world means that vulnerabilities in one system can have cascading effects, impacting even those operating outside the bounds of the law.







