Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
In May 2023, the FBI and CISA warned that the Bl00dy Ransomware gang had also begun exploiting the CVE-2023-27350 flaw for initial access to targets' networks.
7 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware operation reported to have exploited the PaperCut remote-code-execution flaw CVE-2023-27350 for initial access.
Ransomware family/gang reported exploiting a PaperCut RCE flaw for initial access into victim networks, particularly educational organizations.
Named in relation to a LockBit 3.0 builder reference; not a primary malware subject here.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.