PaperCut disclosed an urgent security bulletin for its MF/NG products after vulnerabilities tracked as PO-1216 and PO-1219 were identified, with patches made available in March 2023. Subsequent reporting said the flaws had been reported earlier by Trend Micro and affected internet-exposed print management servers, prompting organizations to update systems immediately.
Ransomware operators, including actors linked to CL0P and other groups, were later reported exploiting the PaperCut vulnerabilities during intrusions, adding the bugs to a broader surge in ransomware activity. Separate April 2023 ransomware tracking also noted continued high victim volumes globally, with LockBit leading leak-site postings and AlphV/BlackCat and BianLian increasing activity, underscoring how quickly newly disclosed enterprise software flaws were being weaponized.

See which actors are running it and whether you're in range.
10 events from the most recent confirmed update back to the earliest known activity.
A new Nokoyawa leak site was identified in late May 2023. The article contrasts this with the group's original leak site being inaccessible as of May 2023.
Microsoft released a patch for the Windows CLFS zero-day CVE-2023-28252 on April 11, 2023 as part of its monthly security updates. The flaw had been exploited in attacks tied to attempted Nokoyawa deployment.
Japan recorded 9 ransomware victim cases in April 2023, placing it in the global top 10 victim countries for the month and first in Asia. Of those Japan-related leak-site postings, 5 were attributed to LockBit and 2 to Royal.
In late April 2023, Microsoft Threat Intelligence warned that CL0P-linked actors were exploiting vulnerabilities in PaperCut NG/MF. The article also notes that Bl00dy ransomware exploited the same vulnerabilities.
AKIRA appeared among the top 10 ransomware groups after its leak site was discovered in early April 2023. This indicated the arrival of another newly observed ransomware operation.
The Zero Day Initiative registered the PaperCut vulnerability on March 14, 2023. This marked a further public milestone in the vulnerability's disclosure timeline.
PaperCut released patches for the affected NG/MF vulnerabilities by March 8, 2023. Despite patch availability, exploitation continued afterward.
Money Message entered the top 10 ransomware groups after its leak site was discovered in late March 2023. Its emergence reflected the appearance of a new active ransomware brand.
Kaspersky observed exploitation of the Windows Common Log File System vulnerability CVE-2023-28252 beginning in February 2023. Attackers used the flaw for privilege escalation before attempting to deploy Nokoyawa ransomware.
The PaperCut NG/MF vulnerabilities were reported to PaperCut by Trend Micro in January 2023. This disclosure preceded later patching and subsequent exploitation by ransomware actors.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.