HomeSecurityPaperCut servers attacks: Clop & Lockbit ransomware gangs are responsible

PaperCut servers attacks: Clop & Lockbit ransomware gangs are responsible

Microsoft has attributed the recent attacks on PaperCut servers to the gangs behind the Clop and LockBit ransomware . The hackers exploited vulnerabilities in PaperCut servers to steal corporate data .

PaperCut

Last month, two vulnerabilities in PaperCut Application Server. These vulnerabilities could allow attackers to perform remote code execution and information disclosure without authentication.

The vulnerabilities were the following:

  • CVE-2023–27350 / ZDI-CAN-18987 / PO-1216: Vulnerability that allows remote code execution without authentication. Affects PaperCut MF or NG versions 8.0 or later on all operating system platforms, for both application and site servers. (CVSS v3.1 Score: 9.8 – Critical)
  • CVE-2023–27351 / ZDI-CAN-19226 / PO-1219: Allows information disclosure and affects PaperCut MF or NG versions 15.0 or later on all operating system platforms for application servers. (CVSS v3.1 Score: 8.2 – High)

See also: Second ransomware group reported to be exploiting GoAnywhere security flaw

On April 19, PaperCut revealed that the two vulnerabilities had been exploited by cybercriminals and urged administrators to upgrade their servers to the latest version.

Things became more worrisome when a PoC exploit was released a few days later, allowing other threat actors to compromise servers using these exploits.

Lockbit ransomware

Ransomware gangs (Clop, Lockbit) behind attacks on PaperCut servers

As we mentioned above, Microsoft revealed that the Clop and LockBit ransomware gangs are behind these “PaperCut attacks.” Their goal is to steal important corporate data from vulnerable servers.

PaperCut is a print management softwarethat is compatible with all major printer brands and platforms. The company's website says that the software is used by hundreds of millions of people in more than 100 countries. Among them are large corporations, government agencies, and educational institutions.

In a series of tweets published on Wednesday afternoon, Microsoft says it has attributed the recent PaperCut attacks to the Clop ransomware gang.

See also: Nearly three-quarters of cyberattacks involve ransomware

“Microsoft attributes recent attacks exploiting vulnerabilities CVE-2023-27350 and CVE-2023-27351 in PaperCut print management software to the threat actor tracked as Lace Tempest for delivering the Clop ransomware,” the tweet.

Microsoft is tracking this particular threat actor as “Lace Tempest,” whose activity overlaps with FIN11 and TA505 , which are associated with the Clop ransomware operation.

Microsoft says attackers have been exploiting PaperCut vulnerabilities since April 13 to gain initial access to corporate networks. After gaining access to the server, the hackers deployed the TrueBot malware , which has also been linked to the Clop ransomware in the past. Then, according to Microsoft, a Cobalt Strike beacon is used for lateral movement on the network, while also stealing data via the MegaSync file-sharing application .

In addition to Clop, Microsoft says some of the intrusions have led to attacks related to the LockBit ransomware. However, it is unclear whether these attacks began after the exploits were made public.

Microsoft recommends that administrators apply available patches as soon as possible, as other threat actors will likely begin exploiting the vulnerabilities.

Clop ransomware

Clop ransomware

The PaperCut server exploit fits in with the attacks we've seen from the Clop ransomware gang over the past three years. The hackers are still encrypting files, but according to BleepingComputer, they've said they prefer to steal data to blackmail companies into paying ransom.

See also: SSD released that claims to have built-in ransomware prevention

All organizations using PaperCut MF or NG are recommended to upgrade to versions 20.1.7, 21.2.11 and 22.0.9 to fix vulnerabilities exploited by hackers.

As we all know, ransomware is a significant threat to both individuals and businesses. To protect yourself, it is essential to implement basic cybersecurity practices . As technology continues to evolve, it is important to stay informed and vigilant to stay safe from malicious attacks.

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS