Lace Tempest is a financially motivated cybercrime threat actor tracked by Microsoft and widely associated with the Cl0p ransomware and extortion ecosystem. The actor’s activity overlaps with clusters commonly referred to as FIN11 and TA505, and it has been linked to large-scale data theft, extortion, and ransomware deployment. Lace Tempest has been observed operating both as a ransomware affiliate and as an intrusion actor that exploits high-value enterprise software vulnerabilities for initial access, followed by data exfiltration and, in some cases, ransomware deployment. Lace Tempest is notable for opportunistic exploitation of internet-facing enterprise applications, particularly managed file transfer, print management, and IT service management platforms. Publicly linked operations include exploitation of vulnerabilities in MOVEit Transfer, PaperCut MF/NG, and SysAid on-premises software. In these campaigns, the actor used zero-day or newly disclosed vulnerabilities to gain access, deploy webshells or loaders, establish persistence, and steal data at scale. The MOVEit campaign was especially significant, aligning Lace Tempest with the Cl0p extortion model centered on mass exploitation and theft-driven extortion rather than solely encryption. Observed post-compromise tradecraft includes deployment of malware and tooling such as TrueBot, Cobalt Strike, Gracewire, FlawedGrace, and other loaders or implants associated with financially motivated intrusion sets. Reported behaviors include use of webshells for persistence, command execution through compromised application servers, lateral movement, staging and exfiltration of victim data, and delivery of ransomware payloads including Cl0p and, in some intrusions, LockBit. Lace Tempest has also been associated with extortion operations tied to stolen data and operation of the Cl0p leak site. The actor is part of the broader ransomware-as-a-service and cybercrime ecosystem and has been identified as one of the more notable ransomware affiliates. Microsoft has tracked the group under the temporary designation DEV-0950 before publicly naming it Lace Tempest. Lace Tempest has also been described as cooperating at times with other financially motivated actors, including overlap or collaboration involving Sangria Tempest. The group is not a nation-state actor; its operations are assessed as criminal and profit-driven, with targeting shaped primarily by vulnerable enterprise software and extortion opportunity rather than geopolitical objectives.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
17 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
9 malware families attributed to this actor across reporting.
4 additional families tracked in Mallory.
4 CVEs this actor has used in observed campaigns. 4 of them exploited in the wild.
June 2 The actively exploited vulnerability was assigned CVE-2023-34362 with a severity rating of 9.8 out of 10.
CVE-2023-27351 — PaperCut NG/MF | Improper Authentication | CVSS 8.2 An improper authentication flaw in PaperCut NG/MF that allows attackers to bypass authentication via the SecurityRequestFilter class. This is not a new discovery — exploitation has been confirmed in the wild since early 2023. The vulnerability was attributed to Lace Tempest, a Cl0p ransomware affiliate, in April 2023, used in campaigns delivering Cl0p and LockBit ransomware payloads.
Two vulnerabilities were fixed in the PaperCut Application Server that allows remote attackers to perform unauthenticated remote code execution and information disclosure: CVE-2023–27350 ... Unauthenticated remote code execution flaw impacting all PaperCut MF or NG versions 8.0 or later... PaperCut disclosed that these flaws were actively exploited in the wild... A PoC exploit for the RCE flaw was released... Microsoft ... attributed the recent PaperCut attacks to the Clop and LockBit ransomware operations.
A zero-day vulnerability was discovered in SysAid's on-premise software, exploited by the group DEV-0950 (Lace Tempest). The attackers uploaded a WebShell and other payloads, gaining unauthorized access and control. SysAid has released a patch (version 23.3.36) to remediate the vulnerability and urges customers to conduct a comprehensive compromise assessment.
14 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Linked to exploitation of CVE-2023-27351 to deploy Cl0p and LockBit ransomware.
Attributed with exploiting CVE-2023-27351 in PaperCut NG/MF in campaigns delivering Cl0p and LockBit ransomware payloads.
Referenced as a ransomware group that deployed webshells for persistent access via PaperCut MF/NG vulnerabilities.
Named ransomware gang reported (by Microsoft data context) as known for targeting hospitals/healthcare organizations.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.