“Clop” — 37 distilled results

Hacker gang ShinyHunters breaches rival ransomware gang Clop

Between September 19 and 21, the ShinyHunters extortion group infiltrated the Clop ransomware operation's data leak site, defacing it and allegedly stealing server data, source code, and Tor private keys. The defacement was confirmed; the broader theft claims remain unverified.

Multiple critical cybersecurity vulnerabilities disclosed

Security researchers and vendors disclosed numerous critical vulnerabilities including zero-day flaws in SonicWall SMA1000 devices, infrastructure flaws tracked in an InfraTrust report, and large-scale malware campaigns using GitHub repositories and DDoS botnets. The Dysphoria botnet has infected approximately 200,000 devices worldwide.

Clop gang develops targeted malware for enterprise software

Between August 18–20, 2026, security researchers linked a custom Java web shell to the Clop ransomware gang, designed specifically to exploit PTC Windchill and FlexPLM enterprise software servers. The tool included features to decrypt stored credentials and facilitate data theft.

ReliaQuest has documented a custom JSP web shell deployed by Clop after exploitation of CVE-2026-12569 on PTC Windchill and FlexPLM servers. The implant maps design vaults, decrypts keystore credentia

ReliaQuest has documented a custom JSP web shell deployed by Clop after exploitation of CVE-2026-12569 on PTC Windchill and FlexPLM servers. The implant maps design vaults, decrypts keystore credentials, and queries databases via the application's own identity.