📈 Get daily crypto insights that make you smarter about your money

Bl00dy Ransomware Gang Exploits Critical PaperCut Flaw to Target Education Sector

The cybersecurity landscape witnessed another alarming development this week as the Bl00dy Ransomware Gang actively exploited a critical vulnerability in PaperCut print management servers, specifically targeting educational institutions across the United States. The Federal Bureau of Investigation (FBI) and the Cybersecurity and Infrastructure Security Agency (CISA) issued a joint cybersecurity advisory detailing the attacks, which occurred in early May 2023.

The Exploit Mechanics

At the heart of these attacks lies CVE-2023-27350, a now-patched critical security flaw affecting PaperCut MF and PaperCut NG servers. This vulnerability enables a remote attacker to bypass authentication entirely and execute arbitrary code on vulnerable installations. The affected versions span a wide range: 8.0.0 to 19.2.7, 20.0.0 to 20.1.6, 21.0.0 to 21.2.10, and 22.0.0 to 22.0.8. What makes this particularly dangerous is that exploitation requires no authentication whatsoever — an attacker simply needs network access to the vulnerable PaperCut server.

The Bl00dy actors leveraged this access to deploy legitimate Remote Management and Monitoring (RMM) software on compromised systems, which then served as a foothold for dropping additional malicious payloads including Cobalt Strike Beacons, DiceLoader, and TrueBot. The gang used TOR and other proxy tools from within victim networks to mask their malicious traffic and evade detection by standard network monitoring tools.

Affected Systems

The primary targets have been educational institutions running exposed PaperCut servers. However, cybersecurity firm eSentire uncovered an additional campaign exploiting the same vulnerability to deploy XMRig cryptocurrency miners on compromised systems. This dual-use exploitation pattern — ransomware deployment alongside crypto mining — indicates that multiple threat groups are leveraging the same vulnerability for different financial objectives.

Iranian state-sponsored threat groups, identified by Microsoft as Mango Sandstorm (also known as MuddyWater or Mercury) and Mint Sandstorm (also known as Phosphorus), have also been observed exploiting PaperCut servers since mid-April 2023. The convergence of financially motivated criminal groups and nation-state actors on the same vulnerability underscores the severity of the situation.

The Mitigation Strategy

Organizations running PaperCut MF or NG must immediately update to the latest patched versions. If patching is not immediately possible, administrators should restrict internet-facing access to PaperCut servers through firewall rules and VPN requirements. Network monitoring teams should look for indicators of compromise including unexpected RMM tool installations, TOR network connections from internal systems, and unusual Cobalt Strike beacon traffic.

For the broader crypto community, this incident serves as a reminder that infrastructure vulnerabilities extend beyond blockchain protocols. Organizations holding cryptocurrency assets or operating crypto-adjacent services must maintain rigorous patch management for all internet-facing systems, not just those directly handling digital assets.

Lessons Learned

The PaperCut incident illustrates several key security principles. First, print management servers are often overlooked in security assessments despite being internet-facing and handling sensitive data. Second, the speed at which multiple threat groups weaponize published vulnerabilities — in this case, exploitation began within weeks of disclosure — demands faster patching cycles. Third, the deployment of cryptocurrency miners alongside ransomware shows how threat actors maximize returns from each compromised target.

User Action Required

If your organization runs PaperCut MF or NG, check your version immediately against the affected ranges listed above. Apply the latest security patches without delay. Review network logs for any evidence of RMM tool deployment or TOR traffic originating from internal systems. Ensure that all internet-facing services are covered by your vulnerability management program, regardless of how mundane they may seem.

Disclaimer: This article is for informational purposes only and does not constitute financial or investment advice. Always conduct your own research before making any investment decisions.

🌱 FOR BUSINESSES BitcoinsNews.com
Reach 100K+ Crypto Readers
Sponsored content, press releases, banner ads, and newsletter placements. Put your brand in front of Bitcoin's most engaged audience.

26 thoughts on “Bl00dy Ransomware Gang Exploits Critical PaperCut Flaw to Target Education Sector”

  1. papercut_survivor

    we had three PaperCut servers exposed to the internet in 2023. took one look at CVE-2023-27350 and pulled them behind VPN the same day. some orgs took weeks

    1. shadow_it_hunter

      papercut_survivor the problem wasnt IT knowing about the servers. it was the biology dept buying their own PaperCut license on a pcard and never telling anyone

  2. CVSS 9.8 and zero auth required. bl00dy didnt even need credentials, just network access. universities running exposed print servers in 2023 is wild to me

  3. CVE-2023-27350 with no auth required and schools as targets. ransomware crews love soft targets with slow IT budgets. this was entirely predictable

    1. ^ the version range is wild. 8.0.0 to 22.0.8, thats basically every PaperCut install ever. most universities run outdated print servers and never patch

    2. universities are the worst for patch management. decentralized IT departments, no central policy, budget cycles measured in years. ransomware groups know this

      1. Dietmar Fuchs

        central IT policy means nothing when the physics dept bought their own PaperCut license on a credit card. shadow IT is the real vulnerability here

        1. shadow_it_tracker

          Dietmar Fuchs shadow IT is spot on. every university has some department running unpatched servers on a credit card budget. PaperCut was just the tip

  4. print management software being the attack vector for ransomware is so 2023. whoever decided those servers needed internet facing interfaces should reconsider

    1. print servers with internet facing interfaces was a choice. we isolated ours behind VPN in 2019 and never looked back

    2. print servers exposed to the open internet in 2023 is negligence. why does a campus printer need a public IP

      1. cve-2023-27350 was exploited for weeks before the advisory. schools running unpatched papercut servers was basically an open door

  5. RMM tools as persistence mechanism is standard tradecraft now. Bl00dy using legitimate software makes detection way harder since it blends into normal admin traffic

  6. CVE-2023-27350 required zero auth and had a CVSS of 9.8. CISA gave orgs 3 weeks to patch before exploits went wild. most schools never bothered

  7. bl00dy targeting education sector specifically because it staffing is thin and patch management is non-existent there

  8. segment_fault_

    Bl00dy targeting universities specifically because IT staffing is one guy covering 2000 endpoints on a community college budget. ransomware crews do reconnaissance on org charts now

    1. segment_fault_ the version range 8.0.0 to 22.0.8 is basically every PaperCut install ever shipped. universities running unpatched print servers on public IPs was a ticking bomb

      1. Sun-hee Y. CISA gave 3 weeks to patch and most schools needed 3 days max before Bl00dy was already inside deploying RMM tools. the patch gap is where ransomware actually lives

  9. CVSS 9.8 with zero auth required and CISA gave 3 weeks. schools needed 3 days max before Bl00dy was already inside. the patch gap is where ransomware lives

    1. cve_radar_ 3 weeks is generous. most schools I contracted at didnt have a full time security team. one guy handling 2000 endpoints doesnt patch CVSS 9.8s in 72 hours

  10. CVSS 9.8 zero auth required and universities still didnt patch for 3 weeks. the patch gap is where ransomware actually lives

    1. print servers facing the public internet in 2023 was a choice. isolate behind VPN and this exploit vector disappears entirely

      1. Dario Ortega print servers on public IP was pandemic level remote work patching debt. every department bought a cheap print server and forgot about it. universities had hundreds

  11. CVE-2023-27350 had a patch available for weeks before Bl00dy started exploiting it. schools running unpatched PaperCut servers is honestly a governance failure not a vulnerability issue

  12. RMM software as the persistence layer is textbook now. every ransomware crew from LockBit to Bl00dy does the same thing because defender ignores signed RMM tools by default

  13. cve_collector_

    the FBI and CISA advisory specifically called out education sector because university IT budgets are basically zero. easy targets with lots of sensitive data

Leave a Comment

Your email address will not be published. Required fields are marked *

BTC$64,915.00-0.1%ETH$1,918.90-0.1%SOL$76.32+1.7%BNB$603.61+1.5%XRP$1.04-0.3%ADA$0.1961-1.8%DOGE$0.0701-0.4%DOT$0.8055-1.7%AVAX$6.47-0.8%LINK$8.29-0.6%UNI$3.98-0.1%ATOM$1.38-1.1%LTC$46.10+1.1%ARB$0.0774-2.8%NEAR$1.61-0.2%FIL$0.7079-1.1%SUI$0.69070.0%BTC$64,915.00-0.1%ETH$1,918.90-0.1%SOL$76.32+1.7%BNB$603.61+1.5%XRP$1.04-0.3%ADA$0.1961-1.8%DOGE$0.0701-0.4%DOT$0.8055-1.7%AVAX$6.47-0.8%LINK$8.29-0.6%UNI$3.98-0.1%ATOM$1.38-1.1%LTC$46.10+1.1%ARB$0.0774-2.8%NEAR$1.61-0.2%FIL$0.7079-1.1%SUI$0.69070.0%
Scroll to Top