โŒ

Reading view

Clop gets a taste of its own medicine after ShinyHunters hijack leak site

Clop has discovered what life is like on the receiving end of an extortion demand after rival crew ShinyHunters hijacked its leak site and demanded an eight-figure payout. The takeover surfaced over the weekend, when Clop's dark web leak site displayed a large "DOMAIN SEIZED BY SHINYHUNTERS" banner and the tagline "rooting your systems since '19 ;)." ShinyHunters told Reuters that it broke into the site on Friday by exploiting a vulnerability in the software powering it. The crew claimed this gave it extensive access to Clop's infrastructure. "We basically own them now," it said. Clop has not responded publicly, although two security researchers told Reuters that the clash appeared genuine. The Register has also viewed the defaced site, where ShinyHunters is posting increasingly colorful demands. According to ShinyHunters, the feud dates back to Clop's attacks on Oracle E-Business Suite (EBS) customers last year. ShinyHunters claims it discovered the zero-day first, only for Clop to obtain the exploit and use it against corporate networks. It now wants a share of the proceeds. In a message posted on September 19, ShinyHunters demanded an eight-figure payment, claiming the sum represented 2.333 percent of its own net worth. A later update raised the demand to "all the money you made off the EBS campaign plus more AND WITH INTEREST." ShinyHunters also threatened to identify companies that allegedly paid Clop and publish the sums and Bitcoin addresses involved. ShinyHunters turned the screw again on September 21, warning that its demands would increase with every 24 hours that Clop failed to respond. It now also wants a public apology, because apparently having your dark web extortion site hijacked isn't embarrassing enough. Clop is one of the most prolific data extortion groups in cybercrime. The gang has spent years exploiting vulnerabilities in enterprise software to steal data and extort victims, most notoriously during the 2023 MOVEit campaign, which affected thousands of organizations and exposed information belonging to tens of millions of people. ShinyHunters has an extensive rap sheet of its own, having been linked to numerous large-scale data theft and extortion campaigns. Its latest target is rather more familiar with that business model than most. The potential damage to Clop goes beyond the defacement of its leak site. If ShinyHunters has the wider access it claims and publishes records of previous ransom payments, the fallout could extend to companies that believed paying Clop had kept their identities and negotiations private. For now, though, those claims remain unverified. There is also the small matter of Clop's reputation. Leak sites are intended to demonstrate that an extortion crew has both the stolen goods and control of its operation. Having yours hijacked by a rival and repurposed to demand money from you is not exactly a glowing advertisement. ShinyHunters says the price will continue rising every 24 hours until Clop responds. The extortionists have become the extorted. ยฎ

  •  

Rustaceans warned of job interviews with a malicious payload

The Rust project has warned that attackers appear to be targeting its contributors and crate owners in an attempt to compromise their devices and accounts, potentially allowing malware to be distributed through its package ecosystem. Posting to the Rust blog, security-focused software engineer Adam Harvey said the tactics resemble those used in North Korean fake recruiter campaigns. "A video call is set up for something positive โ€“ maybe for a job, maybe for a project, maybe for a contract opportunity โ€“ and then that's used as a vector to either get the target to install something on their computer (such as a purportedly missing audio codec) or execute another command (for example, via putting a command on the clipboard)," Harvey wrote. "These attackers are setting up new but legitimate-seeming company profiles, including plausible LinkedIn presences, in order to pass cursory inspection." The warning follows several attacks targeting the Rust community over the summer. In June, Rust developers were targeted with fake interview approaches purporting to come from a Singaporean venture capital firm. Matt Mastracci, who maintains packages on Rust's crates.io registry, said the supposedly recruiting business turned out to be defunct. The initial approach nevertheless appeared convincing and almost led to his machine being infected with a remote access trojan (RAT). The attempted deployment of a RAT resembles activity described in an international advisory issued last week by agencies in Australia, Germany, Japan, and the US. The advisory said North Korean operators had used fake job interviews to compromise more than 30,000 devices and steal over $10 million. Separately, Rust's package ecosystem suffered a supply chain attack in August, when malicious versions of the arrayref crate were published that downloaded malware onto users' machines. Arrayref had recorded 245 million downloads over its lifetime, although the malicious releases were available for less than two hours. The evidence suggested that a maintainer's credentials had been compromised rather than the malware being deliberately introduced by the project's developers. Harvey urged Rustaceans to scrutinize unsolicited approaches even when the sender appears legitimate, and to conduct calls through trusted platforms. ยฎ

  •  
โŒ