Summary:
Security researchers have issued a warning about attacks conducted by the Bl00dy Ransomware Gang targeting vulnerable PaperCut servers in the education facilities sector. The threat actor gained access to victim networks in the Education Facilities Subsector by exploiting PaperCut servers exposed to the internet with the vulnerability identified as CVE-2023-27350. As a result, data exfiltration and encryption of victim systems occurred, with the ransomware gang leaving ransom notes demanding payment for file decryption.[/subscribe_to_unlock_form]
Summary:
Security researchers have issued a warning about attacks conducted by the Bl00dy Ransomware Gang targeting vulnerable PaperCut servers in the education facilities sector. The threat actor gained access to victim networks in the Education Facilities Subsector by exploiting PaperCut servers exposed to the internet with the vulnerability identified as CVE-2023-27350. As a result, data exfiltration and encryption of victim systems occurred, with the ransomware gang leaving ransom notes demanding payment for file decryption.[emaillocker id="1283"]
The Bl00dy Ransomware Gang employed legitimate remote management and maintenance (RMM) software, which was downloaded and executed on victim systems through commands issued via PaperCut's print scripting interface. To conceal their malicious network traffic, the threat actors utilized external network communications through Tor and other proxies within victim networks. This tactic aimed to mask their activities and evade detection. Further analysis revealed evidence of the Bl00dy Gang's utilization of command and control (C2) malware, including DiceLoader, TrueBot, and Cobalt Strike Beacons. However, it remains unclear at which stage of the attack these tools were executed.
Threat Profile:

References:
The following reports contain further technical details:
https://thehackernews.com/2023/05/bl00dy-ransomware-gang-strikes.html
https://Eventus Security.com/advisory/hackers-actively-exploit-critical-rce-bugs-in-papercut-servers/
https://Eventus Security.com/advisory/print-management-software-papercut-actively-exploited-in-the-wild/