Microsoft says Clop, LockBit ransomware gangs behind PaperCut server attacks

printer-in-office
(Image credit: Future)

Microsoft has said its research found the Clop and LockBit ransomware operators are behind the latest data breach incidents related to the PaperCut MF/NG vulnerabilities.

The Redmond giant recently published a Twitter thread in which it points the finger toward these two groups.

“Microsoft is attributing the recently reported attacks exploiting the CVE-2023-27350 and CVE-2023-27351 vulnerabilities in print management software PaperCut to deliver Clop ransomware to the threat actor tracked as Lace Tempest (overlaps with FIN11 and TA505),” one of the tweets reads. 

Deploying Cobalt Strike

The company also said that “Lace Tempest’s” activity overlaps with FIN11 and TA505, both of whom are linked to the Clop ransomware operation. Furthermore, the threat actors used the access gained to deliver TrueBot malware, which has also been previously linked to Clop.

Finally, Lace Tempest was seen delivering a Cobalt Strike beacon, scouting for connected endpoints, and moving laterally using WMI. Any valuable data they could find - they would exfiltrate using the file-sharing app MegaSync, Microsoft added.

In March 2023, news broke that PaperCut’s developers fixed two flaws in the PaperCut Application Server which allowed for remote code execution to be done by unauthenticated actors.

The two flaws have since been tracked as CVE-2023–27350 / ZDI-CAN-18987 / PO-1216 (unauthenticated remote code execution flaw with a 9.8 severity score, affecting all PaperCut MF or NG versions from 8.0 onward on all operating systems) and CVE-2023–27351 / ZDI-CAN-19226 / PO-1219 (unauthenticated information disclosure flaw with an 8.2 severity score, affecting all PaperCut MF or NG versions 15.0 and newer on all OS’ for application servers).

Earlier this week, it was said that the flaws were most likely a lot more dangerous than initially thought, as two proofs-of-concept (PoC) were released. 

PaperCut is a print management software solution used by hundreds of enterprises and public sector companies around the world. 

Via: BleepingComputer

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
A stylized depiction of a padlocked WiFi symbol sitting in the centre of an interlocking vault.
59 organizations reportedly victim to breaches caused by Cleo software bug
Lock on Laptop Screen
Clop ransomware lists Cleo cyberattack victims
Ransomware
Fortinet firewall bugs are being targeted by LockBit ransomware hackers
A digital representation of a lock
Security experts are being targeted with fake malware discoveries
Russia
Major Russian hacking group shifts focus to US and UK targets
A concept image of someone typing on a computer. A red flashing danger sign is above the keyboard and nymbers and symbols also in glowing red surround it.
Microsoft Teams and other Windows tools hijacked to hack corporate networks
Latest in Security
ransomware avast
Ransomware attacks are costing Government offices a month of downtime on average
Lock on Laptop Screen
Data breach at Pennsylvania education union potentially exposes 500,000 victims
Data leak
Top collectibles site leaks personal data of nearly a million users
Spyware
Stalkerware data breach potentially hits over 2 million users, including thousands of Apple devices
An American flag flying outside the US Capitol building against a blue sky
Five Eyes "cannot replace US intel in Ukraine", claims former US Cyber Command Chief
Pirate skull cyber attack digital technology flag cyber on on computer CPU in background. Darknet and cybercrime banner cyberattack and espionage concept illustration.
Criminals are using a virtual hard disk image file to host and distribute dangerous malware
Latest in News
Citroen 2CV
The retro EV resurgence is in full swing, as Citroen confirms the iconic 2CV will return with batteries
Hugging Snap
This AI app claims it can see what I'm looking at – which it mostly can
Apple iPhone 16 Pro Max REVIEW
The latest batch of leaked iPhone 17 dummy units appear to show where glass meets metal on the new designs
Hornet swings their weapon in mid air
Hollow Knight: Silksong could potentially launch this year and I reckon it could be a great game for an Xbox handheld
ransomware avast
Ransomware attacks are costing Government offices a month of downtime on average
Cassian looking at someone off-camera from a TIE fighter cockpit in Andor season 2
Star Wars: Andor creator is taking a stance against AI by canceling plans to release its scripts, and I completely get why