ZeroHour
The Recordpublished ()ingested 1

CISA: Bl00dy Ransomware Gang using printer vulnerability to attack schools

highRansomwareimportance 60CVE-2023-27350

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2023-27350
Authentication Bypass Leading to SYSTEM RCE in PaperCut MF/NG

PaperCut MF and PaperCut NG print management software contain an improper access control flaw (CWE-284) in the SetupCompleted class that allows an unauthenticated attacker to bypass authentication and reach internal administrative functionality. The flaw is triggered by sending crafted, unauthenticated requests to the PaperCut application's web interface, without requiring valid user credentials. A successful attacker gains the ability to execute code in the context of the SYSTEM account on the PaperCut server, typically a Windows print server, giving full control of that host. Any organization running PaperCut MF or NG is potentially affected, and exposure is highest where the server's web interface is reachable from the internet or by untrusted networks. Exploitation is confirmed in the wild: CISA added the flaw to the KEV on 2023-04-21 with known ransomware use, and EPSS rates exploitation probability at 100% within 30 days.

Do: Apply the vendor's updates as instructed (this is the required action in CISA KEV) — upgrade PaperCut MF/NG to the patched releases listed in PaperCut's security advisory rather than relying on unpatched installs. Until patched, restrict network access to the PaperCut web/admin interface so it is reachable only from trusted hosts, and check the server for signs of compromise given known ransomware use. Prioritize internet-facing PaperCut servers, which public scans show are exposed in the thousands.

9.8100% KEV ransomware PoC ×3
  • PaperCut MF
  • PaperCut NG
masstens of thousands of organizations (~70k+) and millions of users; thousands of internet-exposed PaperCut servers
Full article413 words · extracted from therecord.media · click to collapse

The Cybersecurity and Infrastructure Security Agency (CISA) and FBI said a relatively new ransomware group has been exploiting an issue with a popular printing software to attack schools across the U.S.

In an advisory on Thursday, CISA said that since the middle of April the Bl00dy Ransomware Gang has been exploiting CVE-2023-27350 – a vulnerability discovered earlier this year that affects PaperCut software used by tens of thousands of companies, schools, and government agencies around the world.

CISA specifically urged K-12 schools to patch the vulnerability and use the detection methods in this advisory.

The agencies said organizations that did not immediately patch the bug should “assume compromise and hunt for malicious activity using the detection signatures in this CSA.”

“Education Facilities Subsector entities maintained approximately 68% of exposed, but not necessarily vulnerable, U.S.-based PaperCut servers. In early May 2023, according to FBI information, the Bl00dy Ransomware Gang gained access to victim networks across the Education Facilities Subsector where PaperCut servers vulnerable to CVE-2023-27350 were exposed to the internet,” the agencies said in the advisory.

“Ultimately, some of these operations led to data exfiltration and encryption of victim systems. The Bl00dy Ransomware Gang left ransom notes on victim systems demanding payment in exchange for decryption of encrypted files.”

CISA ordered all federal civilian agencies to patch the vulnerability by May 12 but that has not stopped both cybercriminals and nation-states from using it to attack a variety of organizations.

Since a March 8 advisory from PaperCut, several ransomware groups, including Clop and LockBit, have been seen exploiting the bug, according to Microsoft. Last week, Microsoft said two nation-state actors from Iran were seen exploiting it as well.

CISA explained that there are currently two publicly known proofs of concept for achieving remote code execution in vulnerable PaperCut software that allow hackers to take a range of actions in a victim’s system.

The advisory provides a sample of the ransomware note from Bl00dy, which provides victims with an email to contact for ransom negotiations.

The advisory comes amid a string of ransomware attacks on K-12 schools, colleges and universities, hindering final exams and commencement ceremonies across the U.S.

No previous article

No new articles

Jonathan Greig

is a Breaking News Reporter at Recorded Future News. Jonathan has worked across the globe as a journalist since 2014. Before moving back to New York City, he worked for news outlets in South Africa, Jordan and Cambodia. He previously covered cybersecurity at ZDNet and TechRepublic.

Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/cisa-warns-of-bl00dy-ransomware-gang-using-papercut-vulnerability