Bl00dy, also known as the Bl00dy Ransomware Gang, is a financially motivated ransomware operation that emerged in 2022 and has been characterized as a spin-off of the Russian-speaking Conti ransomware ecosystem. The operation has been associated with Ransomware-as-a-Service activity and use of open-source or leaked ransomware builders derived from other operations, including Conti, Babuk, and LockBit. Bl00dy targeted vulnerable internet-facing PaperCut print-management servers in 2023, using CVE-2023-27350 to obtain initial access, particularly against organizations in the United States education sector. Confirmed intrusions included data exfiltration, encryption of victim systems, and ransom demands. Bl00dy has also been observed exploiting vulnerabilities in ConnectWise ScreenConnect and deploying webshells following PaperCut compromise, enabling persistent access. Its activity has primarily affected U.S. healthcare and education organizations. Financial tracing has linked victim-payment laundering infrastructure to activity geolocated in Ghana, although this does not establish the group’s country of origin.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
14 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
7 malware families attributed to this actor across reporting.
2 additional families tracked in Mallory.
2 CVEs this actor has used in observed campaigns. 2 of them exploited in the wild.
The critical PaperCut remote-code-execution vulnerability CVE-2023-27350 and high-severity information-disclosure flaw CVE-2023-27351 were exploited together in April 2023 attacks linked to LockBit and Clop. Bl00dy later used CVE-2023-27350 for initial access.
In 2023, the CVE-2023-27350 / CVE-2023-27351 authentication-bypass-to-RCE chain in the same product was exploited within weeks of disclosure and subsequently weaponized by Cl0p, LockBit, Bl00dy, and Iranian state-sponsored intrusions. | In 2023, the CVE-2023-27350 / CVE-2023-27351 authentication-bypass-to-RCE chain in the same product was exploited within weeks of disclosure and subsequently weaponized by the Cl0p and LockBit ransomware operations, the Bl00dy ransomware gang, and Iranian state-sponsored intrusions.
10 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware group historically observed exploiting a PaperCut vulnerability to obtain initial network access.
Ransomware group that began exploiting CVE-2023-27350 for initial access to target networks in May 2023.
Historically associated in this reference with weaponizing the 2023 PaperCut authentication-bypass-to-RCE chain for ransomware activity.
Historically associated in this reference with weaponizing the 2023 PaperCut vulnerability chain for ransomware activity.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.