Bl00dy is a ransomware-as-a-service (RaaS) operation that emerged in 2022 and is described in the content as a Conti spin-off or offshoot of the Russian-speaking Conti ransomware group. The group has targeted healthcare and education organizations, primarily in the United States. It is specifically documented targeting the U.S. Education Facilities Subsector in early May 2023 by exploiting vulnerable internet-exposed PaperCut MF/NG servers via CVE-2023-27350 to gain initial access; some intrusions led to data exfiltration and file encryption, with ransom notes left for decryption payment. The content also states that Bl00dy exploited PaperCut MF/NG vulnerabilities to deploy webshells for persistent access, and that Bl00dy was observed exploiting 2024 ConnectWise ScreenConnect vulnerabilities. One source in the content states the group first began operating in May 2022 and used open-source and leaked builders from other operators, including LockBit, Babuk, and Conti; another states Bl00dy used the LockBit builder from September 2022. The group is listed among RaaS programs advertised on the RAMP cybercrime forum. TRM Labs identified five confirmed Bl00dy victim payment addresses and additional laundering addresses, with non-VPN IP data geolocated to Ghana, and separately noted leaked RAMP data in which a Bl00dy-linked actor advertised a location in North Africa. Known alias in the provided content: bl00dy.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
13 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
7 malware families attributed to this actor across reporting.
2 additional families tracked in Mallory.
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
1 indicator attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named as a distinct RaaS program advertised on RAMP.
RaaS operation and Conti spin-off linked to laundering activity geolocated to Ghana; targeted healthcare and education organizations primarily in the United States.
Bl00dy is a ransomware group, considered an offshoot of the Conti group, involved in money laundering and ransomware operations, particularly in Africa.
Bl00dy is a ransomware group, considered an offshoot of the Conti group, involved in money laundering and ransomware operations, particularly in Africa.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.