Hackers use PaperCut printer vulnerability to spread Clop ransomware
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2023-27350 | Authentication Bypass Leading to SYSTEM RCE in PaperCut MF/NG PaperCut MF and PaperCut NG print management software contain an improper access control flaw (CWE-284) in the SetupCompleted class that allows an unauthenticated attacker to bypass authentication and reach internal administrative functionality. The flaw is triggered by sending crafted, unauthenticated requests to the PaperCut application's web interface, without requiring valid user credentials. A successful attacker gains the ability to execute code in the context of the SYSTEM account on the PaperCut server, typically a Windows print server, giving full control of that host. Any organization running PaperCut MF or NG is potentially affected, and exposure is highest where the server's web interface is reachable from the internet or by untrusted networks. Exploitation is confirmed in the wild: CISA added the flaw to the KEV on 2023-04-21 with known ransomware use, and EPSS rates exploitation probability at 100% within 30 days. Do: Apply the vendor's updates as instructed (this is the required action in CISA KEV) — upgrade PaperCut MF/NG to the patched releases listed in PaperCut's security advisory rather than relying on unpatched installs. Until patched, restrict network access to the PaperCut web/admin interface so it is reachable only from trusted hosts, and check the server for signs of compromise given known ransomware use. Prioritize internet-facing PaperCut servers, which public scans show are exposed in the thousands. | 9.8 | 100% | KEV ransomware PoC ×3 |
| masstens of thousands of organizations (~70k+) and millions of users; thousands of internet-exposed PaperCut servers | |
| CVE-2023-27351 | Authentication Bypass in PaperCut NG/MF Print Management Software CVE-2023-27351 is an improper authentication flaw (CWE-287) in the SecurityRequestFilter class of PaperCut NG and MF print management software, where the authentication algorithm is improperly implemented. A remote, unauthenticated attacker can trigger it over the network with no user interaction or special privileges to bypass authentication on the affected server (CVSS 3.1: 7.5). Once authentication is bypassed, the attacker gains access to the PaperCut system; in observed campaigns this access was leveraged to deliver Cl0p and LockBit ransomware, as confirmed by Microsoft. Organizations running PaperCut NG (version 22.0.5, Build 63914, is cited in the advisory) or PaperCut MF are affected. The flaw was exploited as a zero-day, is CISA KEV-listed (added 2026-04-20) with known ransomware use, and EPSS places the 30-day exploitation probability at 78.1%. Do: Upgrade PaperCut NG/MF to the fixed release per the vendor's emergency patch advisory, first confirming the running build (NG 22.0.5, Build 63914, is cited as affected). Restrict internet-facing access to PaperCut servers and hunt for signs of post-exploitation, given confirmed use to deliver Cl0p and LockBit ransomware. US federal agencies must apply mitigations per CISA BOD 22-01 (or vendor instructions) or discontinue use of the product if mitigations are unavailable. | 7.5 | 78% | KEV ransomware |
| large≈75,000+ sites/organizations (PaperCut NG/MF is deployed at tens of thousands of organizations; public scans have found thousands of servers directly… |
Full article441 words · extracted from therecord.media · click to collapse
Hackers linked to the Clop ransomware operation are exploiting two recently-disclosed vulnerabilities in print management software PaperCut to steal corporate data from victims. In a series of tweets posted Wednesday, Microsoft said they attributed the attacks to a threat actor they track as Lace Tempest — a group whose activities overlap with FIN11 and TA505. The financially-motivated hacking group operates as a Clop affiliate, meaning they carry out attacks and deploy Clop ransomware, earning a commission for successful extortions. Microsoft is attributing the recently reported attacks exploiting the CVE-2023-27350 and CVE-2023-27351 vulnerabilities in print management software PaperCut to deliver Clop ransomware to the threat actor tracked as Lace Tempest (overlaps with FIN11 and TA505). Since at least April 13, Lace Tempest has been exploiting two PaperCut vulnerabilities — CVE-2023-27350 and CVE-2023-27351 — to deliver Clop ransomware, according to Microsoft. Last week, the Cybersecurity and Infrastructure Security Agency warned that hackers had exploited the vulnerabilities to gain access to unpatched servers on customer networks. PaperCut published its first advisory about the issue on March 8, releasing a fix for the bug. The company said it was informed of the vulnerabilities by Trend Micro researchers on January 10. The bugs allowed hackers to remotely access victim systems, and extract information about users stored within a customer’s servers, including usernames, full names, email addresses, and payment card numbers associated with the accounts. PaperCut produces printing management software for Canon, Epson, Xerox, and almost every other major printer brand. Its tools are used by more than 70,000 organizations, including government agencies, universities, and large companies around the world. According to Microsoft, Lace Tempest used several PowerShell commands to deliver a TrueBot malware downloader to targeted systems. TrueBot was created by a Russian-speaking hacking group known as Silence that is responsible for several high-impact attacks on financial institutions in several countries around the world. In previous attacks, Lace Tempest has been observed using Fortra’s GoAnywhere file transfer product exploits and the Raspberry Robin worm to deliver ransomware — two techniques that are commonly associated with the Clop ransomware group. “We’re monitoring other attacks also exploiting these vulnerabilities, including intrusions leading to Lockbit deployment,” Microsoft said, referring to another major ransomware operation. “More threat actors could follow suit.”
No previous article
No new articles
Daryna Antoniuk
is a reporter for Recorded Future News based in Ukraine. She writes about cybersecurity startups, cyberattacks in Eastern Europe and the state of the cyberwar between Ukraine and Russia. She previously was a tech reporter for Forbes Ukraine. Her work has also been published at Sifted, The Kyiv Independent and The Kyiv Post.
Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/hackers-use-papercut-vulnerabilities-to-deploy-clop-ransomware