The Rising Threat: PaperCut Ransomware Attacks Unveiling Cl0p and LockBit Connections

Microsoft has confirmed that the active exploitation of PaperCut servers is linked to attacks designed to deliver Cl0p and LockBit ransomware families. The tech giant’s threat intelligence team has attributed a subset of the intrusions to a financially motivated actor it tracks under the name Lace Tempest, highlighting the evolving threat landscape that businesses and organizations face as bad actors continue to adapt and innovate.

Active exploitation of PaperCut servers linked to Cl0p and LockBit ransomware families

Over the last few months, a series of cyber-attacks involving ransomware has hit numerous organizations around the world. These attacks leverage a range of techniques, including exploiting vulnerabilities in commonly used software and social engineering tactics.

Microsoft has confirmed that the active exploitation of PaperCut servers has been linked to a range of attacks designed to deliver Cl0p and LockBit ransomware families. In April 2023, the threat actors incorporated PaperCut flaws (2023-27350 and CVE-2023-27351) into their attack toolkit, which allowed them to gain access to vulnerable systems and deploy the ransomware.

According to Microsoft, a separate cluster of activity has also been detected weaponizing the same flaws, including the ones that lead to LockBit ransomware infections. This highlights the ongoing threat posed by ransomware and emphasizes the importance of keeping software up-to-date and patched.

Raspberry Robin/QNAP Worm believed to be Access-as-a-Service malware

Another example of the evolving threat landscape is Raspberry Robin, also called QNAP worm. Microsoft has stated that it is believed to be an “access-as-a-service” malware that is used as a delivery vehicle for next-stage payloads, such as IcedID, Cl0p, and LockBit. The malware infects vulnerable devices, such as enterprise storage systems, which can then be used to launch further attacks against a target organization.

Attribution of a subset of intrusions to financially motivated actor “Lace Tempest”

Microsoft’s threat intelligence team has attributed a subset of the intrusions involving PaperCut servers and ransomware to a financially motivated actor it tracks under the name Lace Tempest. The group is known for its use of various tactics, including prolific phishing campaigns that target both individuals and businesses.

The group has used a range of tactics to evade detection, including using legitimate cloud services to host their malware. Microsoft’s attribution of the attacks to Lace Tempest highlights the importance of strong cybersecurity measures and the need to remain vigilant against such threats.

FIN7 Cybercrime Group is linked to attacks that exploit unpatched Veeam backup software instances

The FIN7 cybercrime group has been linked to attacks that exploit unpatched Veeam backup software instances. WithSecure detected the activity on March 28, 2023, and it likely involved the abuse of CVE-2023-27532. The group is notorious for its attacks on financial institutions and retailers, and frequently uses tactics such as spear-phishing and social engineering.

Utilization of Custom PowerShell Scripts in FIN7 Attacks

The FIN7 group also utilized custom PowerShell scripts to retrieve stored credentials from the backup servers, gather system information, and establish an active foothold in the compromised host by executing DICELOADER. This highlights the need for comprehensive security measures, including strong passwords, multi-factor authentication, and monitoring for anomalous activity.

Mirai botnet authors have updated the malware to exploit a high-severity flaw in TP-Link Archer AX21 routers

In another example of the evolving threat landscape, the authors of the Mirai botnet have updated their malware to include CVE-2023-1389, a high-severity flaw in TP-Link Archer AX21 routers that could allow an unauthenticated adversary to execute arbitrary code on affected installations. The first signs of in-the-wild exploitation emerged on April 11, 2023, highlighting the need for prompt patching and vulnerability management.

The threat landscape facing businesses and organizations today is constantly evolving, and bad actors are continually innovating and adapting their tactics to evade detection and cause harm. The recent attacks involving ransomware and access-as-a-service malware, as well as the Mirai botnet’s exploitation of a high-severity flaw in routers, serve as stark reminders of the importance of strong cybersecurity measures, comprehensive vulnerability management, and ongoing vigilance against emerging threats. It is essential that organizations remain up-to-date with the latest security patches and advisories, as well as maintain strong defenses against phishing and other social engineering tactics.

Explore more

How Can XOS Pulse Transform Your Customer Experience?

This guide aims to help organizations elevate their customer experience (CX) management by leveraging XOS Pulse, an innovative AI-driven tool developed by McorpCX. Imagine a scenario where a business struggles to retain customers due to inconsistent service quality, losing ground to competitors who seem to effortlessly meet client expectations. This challenge is more common than many realize, with studies showing

How Does AI Transform Marketing with Conversionomics Updates?

Setting the Stage for a Data-Driven Marketing Era In an era where digital marketing budgets are projected to surpass $700 billion globally by 2027, the pressure to deliver precise, measurable results has never been higher, and marketers face a labyrinth of challenges. From navigating privacy regulations to unifying fragmented consumer touchpoints across diverse media channels, the complexity is daunting, but

AgileATS for GovTech Hiring – Review

Setting the Stage for GovTech Recruitment Challenges Imagine a government contractor racing against tight deadlines to fill critical roles requiring security clearances, only to be bogged down by outdated hiring processes and a shrinking pool of qualified candidates. In the GovTech sector, where federal regulations and talent scarcity create formidable barriers, the stakes are high for efficient recruitment. Small and

Trend Analysis: Global Hiring Challenges in 2025

Imagine a world where nearly 70% of global employers are uncertain about their hiring plans due to an unpredictable economy, forcing businesses to rethink every recruitment decision. This stark reality paints a vivid picture of the complexities surrounding talent acquisition in today’s volatile global market. Economic turbulence, combined with evolving workplace expectations, has created a challenging landscape for organizations striving

Automation Cuts Insurance Claims Costs by Up to 30%

In this engaging interview, we sit down with a seasoned expert in insurance technology and digital transformation, whose extensive experience has helped shape innovative approaches to claims handling. With a deep understanding of automation’s potential, our guest offers valuable insights into how digital tools can revolutionize the insurance industry by slashing operational costs, boosting efficiency, and enhancing customer satisfaction. Today,