Bl00dy is a ransomware operation active since at least May 2022. It has conducted extortion intrusions involving theft of victim data, encryption of victim systems, and ransom demands for decryption. In 2023, Bl00dy exploited the authentication-bypass vulnerability CVE-2023-27350 in internet-exposed PaperCut NG and MF servers to gain unauthenticated remote code execution. The activity particularly affected organizations in the U.S. Education Facilities Subsector. Bl00dy has also been advertised as a ransomware-as-a-service program and has been reported to use leaked or open-source ransomware builders, including LockBit-derived tooling.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The article identifies the Bl00dy ransomware gang among actors that weaponized the 2023 PaperCut vulnerability chain.
The article identifies the Bl00dy ransomware gang among actors that weaponized the 2023 PaperCut vulnerability chain.
Cicada3301 operators in February 2024 sought to exploit ScreenConnect vulnerabilities, (CVE-2024-1708 and CVE-2024-1709). The same vulnerabilities were also extensively exploited according to Trendmicro by other top tier ransomware such as BlackBasta ... and Bl00dy ransomware.
Cicada3301 operators in February 2024 sought to exploit ScreenConnect vulnerabilities, (CVE-2024-1708 and CVE-2024-1709). The same vulnerabilities were also extensively exploited according to Trendmicro by other top tier ransomware such as BlackBasta ... and Bl00dy ransomware.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
In early May 2023, according to FBI information, the Bl00dy Ransomware Gang gained access to victim networks across the Education Facilities Subsector where PaperCut servers vulnerable to CVE-2023-27350 were exposed to the internet. Ultimately, some of these operations led to data exfiltration and encryption of victim systems.
...attacks targeting PaperCut printing servers with Clop, Bl00dy, and LockBit ransomware.
2 distinct techniques documented for this family, organized by ATT&CK tactic.
RAMP hosted 60 threads in its dedicated RaaS section, where ransomware operators recruit affiliates... We identified 14 distinct RaaS programs: AvosLocker, Conti, Luna, BEAST, Nevada, CryptNet, Knight 3.0, NoEscape, Bl00dy, KUIPER, UBUD, PHOBOS, Zeppelin2, Wing 1.0.
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware group mentioned only as historical context for exploitation of the earlier PaperCut authentication-bypass-to-RCE chain.
A ransomware-as-a-service program advertised on RAMP.
Bl00dy is a ransomware group, considered an offshoot of the Conti ransomware group, involved in money laundering and ransomware operations.
Bl00dy is a ransomware group, considered an offshoot of the Conti ransomware group, involved in money laundering and ransomware operations.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.