Clop Ransomware Leak Site Defaced After Exploit of Unpatched Grav CMS Flaw, Operators Move to New Tor Address
Cybercrime group Clop was forced to relocate its public data‑leak platform to a fresh Tor address after security researchers confirmed that the previous site had been compromised and visibly defaced. The intrusion was traced to an unauthenticated path‑traversal vulnerability in the open‑source Grav content‑management system, which the group had failed to patch.
Clop, like several other ransomware outfits, maintains a dark‑web portal where it publishes stolen files to pressure victims into paying ransoms. The site, which operated on a hidden service, served as both a showcase of the gang's reach and a repository for data exfiltrated from compromised networks. When the Grav flaw was weaponized, the attackers—identified by the moniker ShinyHunters—gained direct file‑system access, allowing them to replace the landing page with their own defacement message and potentially expose the underlying data.
The vulnerability in question is a path‑traversal bug that permits an attacker to request arbitrary files outside the intended web root without any form of authentication. Because Grav is widely used for lightweight websites, many installations run with default settings and infrequent updates, making the flaw an attractive target. BleepingComputer reported that the exploit was publicly known and that the specific instance used by Clop had not been updated to mitigate the issue, leaving the leak site exposed to takeover.
The breach underscores a growing concern that ransomware groups, which often rely on off‑the‑shelf software for their infrastructure, may neglect basic cybersecurity hygiene. A compromised leak site not only jeopardizes the gang's operational secrecy but also risks leaking victim data unintentionally, potentially accelerating law‑enforcement investigations. In response, Clop quickly announced a new Tor address, presumably hosted on a hardened server, and warned its affiliates of the compromise.
Security analysts expect the incident to prompt a wave of remediation across similar dark‑web services that employ Grav or comparable CMS platforms. Vendors are likely to issue patches, while operators of illicit sites may adopt more rigorous hardening practices or shift to custom‑built solutions. Meanwhile, investigators will monitor the newly published address for further activity, and the episode serves as a reminder that even criminal enterprises are vulnerable to the same software flaws that affect legitimate businesses.
Comments (0)
Be the first to comment.
Join the discussion