Bl00dy Ransomware Gang, also known as Bl00dy and bl00dy_ransomware_gang, is a financially motivated ransomware operation active since 2022 that operates a ransomware-as-a-service program. It targets education and healthcare organizations, primarily in the United States, and uses publicly available or leaked ransomware builders associated with LockBit, Babuk, and Conti rather than relying exclusively on proprietary malware. In early May 2023, the group exploited CVE-2023-27350 in internet-facing PaperCut NG and MF servers to gain initial access to educational organizations. Confirmed intrusions included data exfiltration, encryption of victim systems, and demands for payment to restore access. Bl00dy has also exploited ConnectWise ScreenConnect vulnerabilities disclosed in 2024. Its techniques include abuse of legitimate remote management software, deployment of webshells for persistent access, and use of Tor and other proxies to conceal malicious network traffic. The group uses Telegram to publicize victims. Its geographic origin is not established; Ghana-linked cryptocurrency laundering activity does not establish the location of its core operators.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
14 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
8 malware families attributed to this actor across reporting.
3 additional families tracked in Mallory.
4 CVEs this actor has used in observed campaigns. 4 of them exploited in the wild.
PaperCut servers vulnerable to CVE-2023-27350 implement improper access controls in the SetupCompleted Java class, allowing malicious actors to bypass user authentication and access the server as an administrator.
In 2023, the CVE-2023-27350 / CVE-2023-27351 authentication-bypass-to-RCE chain in the same product was exploited within weeks of disclosure and subsequently weaponized by Cl0p, LockBit, Bl00dy, and Iranian state-sponsored intrusions. | In 2023, the CVE-2023-27350 / CVE-2023-27351 authentication-bypass-to-RCE chain in the same product was exploited within weeks of disclosure and subsequently weaponized by the Cl0p and LockBit ransomware operations, the Bl00dy ransomware gang, and Iranian state-sponsored intrusions.
“Path Traversal: This secondary vulnerability provides attackers with a method to access unauthorized files, further compromising the integrity of the system. (CVE-2024-1708)”
“Authentication Bypass ... allows nefarious actors to generate their own administrative user on the platform, granting them complete control over the platform. (CVE-2024-1709)”
46 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware group historically observed exploiting a PaperCut vulnerability to obtain initial network access.
Ransomware group that began exploiting CVE-2023-27350 for initial access to target networks in May 2023.
Historically associated in this reference with weaponizing the 2023 PaperCut authentication-bypass-to-RCE chain for ransomware activity.
Historically associated in this reference with weaponizing the 2023 PaperCut vulnerability chain for ransomware activity.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.