The Rising Threat: PaperCut Ransomware Attacks Unveiling Cl0p and LockBit Connections

Microsoft has confirmed that the active exploitation of PaperCut servers is linked to attacks designed to deliver Cl0p and LockBit ransomware families. The tech giant’s threat intelligence team has attributed a subset of the intrusions to a financially motivated actor it tracks under the name Lace Tempest, highlighting the evolving threat landscape that businesses and organizations face as bad actors continue to adapt and innovate.

Active exploitation of PaperCut servers linked to Cl0p and LockBit ransomware families

Over the last few months, a series of cyber-attacks involving ransomware has hit numerous organizations around the world. These attacks leverage a range of techniques, including exploiting vulnerabilities in commonly used software and social engineering tactics.

Microsoft has confirmed that the active exploitation of PaperCut servers has been linked to a range of attacks designed to deliver Cl0p and LockBit ransomware families. In April 2023, the threat actors incorporated PaperCut flaws (2023-27350 and CVE-2023-27351) into their attack toolkit, which allowed them to gain access to vulnerable systems and deploy the ransomware.

According to Microsoft, a separate cluster of activity has also been detected weaponizing the same flaws, including the ones that lead to LockBit ransomware infections. This highlights the ongoing threat posed by ransomware and emphasizes the importance of keeping software up-to-date and patched.

Raspberry Robin/QNAP Worm believed to be Access-as-a-Service malware

Another example of the evolving threat landscape is Raspberry Robin, also called QNAP worm. Microsoft has stated that it is believed to be an “access-as-a-service” malware that is used as a delivery vehicle for next-stage payloads, such as IcedID, Cl0p, and LockBit. The malware infects vulnerable devices, such as enterprise storage systems, which can then be used to launch further attacks against a target organization.

Attribution of a subset of intrusions to financially motivated actor “Lace Tempest”

Microsoft’s threat intelligence team has attributed a subset of the intrusions involving PaperCut servers and ransomware to a financially motivated actor it tracks under the name Lace Tempest. The group is known for its use of various tactics, including prolific phishing campaigns that target both individuals and businesses.

The group has used a range of tactics to evade detection, including using legitimate cloud services to host their malware. Microsoft’s attribution of the attacks to Lace Tempest highlights the importance of strong cybersecurity measures and the need to remain vigilant against such threats.

FIN7 Cybercrime Group is linked to attacks that exploit unpatched Veeam backup software instances

The FIN7 cybercrime group has been linked to attacks that exploit unpatched Veeam backup software instances. WithSecure detected the activity on March 28, 2023, and it likely involved the abuse of CVE-2023-27532. The group is notorious for its attacks on financial institutions and retailers, and frequently uses tactics such as spear-phishing and social engineering.

Utilization of Custom PowerShell Scripts in FIN7 Attacks

The FIN7 group also utilized custom PowerShell scripts to retrieve stored credentials from the backup servers, gather system information, and establish an active foothold in the compromised host by executing DICELOADER. This highlights the need for comprehensive security measures, including strong passwords, multi-factor authentication, and monitoring for anomalous activity.

Mirai botnet authors have updated the malware to exploit a high-severity flaw in TP-Link Archer AX21 routers

In another example of the evolving threat landscape, the authors of the Mirai botnet have updated their malware to include CVE-2023-1389, a high-severity flaw in TP-Link Archer AX21 routers that could allow an unauthenticated adversary to execute arbitrary code on affected installations. The first signs of in-the-wild exploitation emerged on April 11, 2023, highlighting the need for prompt patching and vulnerability management.

The threat landscape facing businesses and organizations today is constantly evolving, and bad actors are continually innovating and adapting their tactics to evade detection and cause harm. The recent attacks involving ransomware and access-as-a-service malware, as well as the Mirai botnet’s exploitation of a high-severity flaw in routers, serve as stark reminders of the importance of strong cybersecurity measures, comprehensive vulnerability management, and ongoing vigilance against emerging threats. It is essential that organizations remain up-to-date with the latest security patches and advisories, as well as maintain strong defenses against phishing and other social engineering tactics.

Explore more

Closing the Feedback Gap Helps Retain Top Talent

The silent departure of a high-performing employee often begins months before any formal resignation is submitted, usually triggered by a persistent lack of meaningful dialogue with their immediate supervisor. This communication breakdown represents a critical vulnerability for modern organizations. When talented individuals perceive that their professional growth and daily contributions are being ignored, the psychological contract between the employer and

Employment Design Becomes a Key Competitive Differentiator

The modern professional landscape has transitioned into a state where organizational agility and the intentional design of the employment experience dictate which firms thrive and which ones merely survive. While many corporations spend significant energy on external market fluctuations, the real battle for stability occurs within the structural walls of the office environment. Disruption has shifted from a temporary inconvenience

How Is AI Shifting From Hype to High-Stakes B2B Execution?

The subtle hum of algorithmic processing has replaced the frantic manual labor that once defined the marketing department, signaling a definitive end to the era of digital experimentation. In the current landscape, the novelty of machine learning has matured into a standard operational requirement, moving beyond the speculative buzzwords that dominated previous years. The marketing industry is no longer occupied

Why B2B Marketers Must Focus on the 95 Percent of Non-Buyers

Most executive suites currently operate under the delusion that capturing a lead is synonymous with creating a customer, yet this narrow fixation systematically ignores the vast ocean of potential revenue waiting just beyond the immediate horizon. This obsession with immediate conversion creates a frantic environment where marketing departments burn through budgets to reach the tiny sliver of the market ready

How Will GitProtect on Microsoft Marketplace Secure DevOps?

The modern software development lifecycle has evolved into a delicate architecture where a single compromised repository can effectively paralyze an entire global enterprise overnight. Software engineering is no longer just about writing logic; it involves managing an intricate ecosystem of interconnected cloud services and third-party integrations. As development teams consolidate their operations within these environments, the primary source of truth—the