Product1 publisher2 min readPublished
ShinyHunters says it controls the private keys to Cl0p's onion address
ShinyHunters told BleepingComputer it took Cl0p's source code, the contents of /var/log and the private keys to the gang's Tor address, and gave Cl0p 72 hours to pay. That last item decides who can host the same onion URL.
The Product Desk · Product desk

What happened
- ShinyHunters has added Cl0p to its own data leak site and given the ransomware gang 72 hours to pay before all of the stolen files are released; TechRadar reports the sum demanded is not known.
- Cybernews reports the stolen material includes Cl0p's source code, its Grav CMS plugins, system logs and other information.
- ShinyHunters says it copied everything in the server's /var/log directory, including system activity records, authentication logs and IP addresses tied to connections to that server.
- Cybernews confirmed that Cl0p's website has been defaced and now carries an ASCII rendering of ShinyHunters' logo and a link to the group's Tor site.
Compiled by The Product DeskSomething wrong?How this is made
Why it matters
- capability An onion service answers to whoever holds its private key, so the address a paying company was told to check can be stood up and operated by a party that was never in the negotiation.
- constraint A deletion promise can only be as good as the seller's control of their own servers, and here that control failed to a file upload bug in an off-the-shelf CMS. An incident response owner has nothing to verify at the moment of payment.
- exposure Anyone whose IP address sits in those connection logs is now subject to a publication decision they cannot bargain over, though TechRadar doubts the material identifies Cl0p members.
- precedent Conti's collapse did not retire its operators, who resurfaced as Black Basta, Royal and Quantum, so a defender planning for Cl0p's end should be planning for its successors.
The line that matters to a company that once wired money to a ransomware crew is the one about onion keys. "We have their onion keys. So if they kick us out it wouldn't matter at all because we control the private keys to host the same exact onion URL," the group said, in remarks TechRadar attributes to BleepingComputer [6]. An onion address answers to whoever holds its private key, so on ShinyHunters' own telling the address is now servable by a second party.
The reported haul does not include victim data from Cl0p's own extortion campaigns [16]. By this account the haul is the machinery those campaigns ran on. "The data we stole includes source codes, gravCMS plugins, and other things. We are still downloading and reviewing them," ShinyHunters told BleepingComputer [10].
TechRadar doubts the log haul will identify any Cl0p member, noting the members are likely Russian and mostly free to operate [12]. Its suggested use for the material is narrower: helping defenders disrupt the group's infrastructure [13].
For whoever owns the incident response runbook, the useful split is between what a payment can be tested against and what it cannot. In the first column sits a decryptor that restores a sample file, checked before the money moves. In the second sits every promise that depends on the seller's continued control of their own servers, and that column has no test in it. ShinyHunters got into those servers, TechRadar reports, through an unauthenticated file upload flaw in the Grav CMS Cl0p was running [7].
ShinyHunters dates the grudge to Cl0p's 2025 Oracle E-Business Suite campaign. "During the Oracle EBS campaign they ran and stole from me last year, someone from cl0p personally messaged me and said, and I quote (translated from Russian): I have more money than you and all of your people combined, I'll kill you soon," the group told BleepingComputer [11]. The last comparable falling-out among criminal groups ended with a Ukrainian researcher and an alleged affiliate leaking more than 60,000 Conti messages in 2022, and with Conti's collapse later that year [14]. Its people came back as Black Basta, Royal and Quantum, and some are allegedly still working [15].
What to watch
- Whether ShinyHunters publishes after the 72 hours, and whether victim files turn up in what it posts.
- Whether Cl0p's onion address starts serving ShinyHunters' content. That would test the private-key claim in public.
- Whether Cl0p affiliates walk the way Conti's did after its 2022 statement of support for the Russian government.