Bl00dy is a financially motivated ransomware operation active since May 2022. The name identifies an extortion operation using multiple ransomware codebases rather than a single independently developed malware family. Its operators have used open-source and leaked builders associated with LockBit, Babuk, and Conti, including the leaked LockBit builder from September 2022. Bl00dy has also been advertised as a ransomware-as-a-service program on the Russian-language RAMP cybercrime forum. Its attacks involve theft of victim data, encryption of systems, and ransom demands for decryption; the operation has used Telegram to advertise stolen data.
Bl00dy operators exploit vulnerabilities in internet-facing enterprise software to gain access to victim networks. In early May 2023, they targeted exposed PaperCut NG and MF servers vulnerable to CVE-2023-27350, an authentication bypass permitting unauthenticated remote code execution. These attacks affected organizations in the U.S. Education Facilities Subsector, with some intrusions resulting in data exfiltration and encryption. Bl00dy has also exploited the ConnectWise ScreenConnect vulnerabilities CVE-2024-1709 and CVE-2024-1708.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
“Authentication Bypass ... allows nefarious actors to generate their own administrative user on the platform, granting them complete control over the platform. (CVE-2024-1709)”
“Path Traversal: This secondary vulnerability provides attackers with a method to access unauthorized files, further compromising the integrity of the system. (CVE-2024-1708)”
The article identifies the Bl00dy ransomware gang among actors that weaponized the 2023 PaperCut vulnerability chain.
The article identifies the Bl00dy ransomware gang among actors that weaponized the 2023 PaperCut vulnerability chain.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Cybersecurity company Trend Micro says it has evidence that two ransomware groups, Black Basta and Bl00dy, are also exploiting the ScreenConnect vulnerabilities.
...attacks targeting PaperCut printing servers with Clop, Bl00dy, and LockBit ransomware.
2 distinct techniques documented for this family, organized by ATT&CK tactic.
RAMP hosted 60 threads in its dedicated RaaS section, where ransomware operators recruit affiliates... We identified 14 distinct RaaS programs: AvosLocker, Conti, Luna, BEAST, Nevada, CryptNet, Knight 3.0, NoEscape, Bl00dy, KUIPER, UBUD, PHOBOS, Zeppelin2, Wing 1.0.
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
11 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware group mentioned only as historical context for exploitation of the earlier PaperCut authentication-bypass-to-RCE chain.
A ransomware-as-a-service program advertised on RAMP.
Bl00dy is a ransomware group, considered an offshoot of the Conti ransomware group, involved in money laundering and ransomware operations.
Bl00dy is a ransomware group, considered an offshoot of the Conti ransomware group, involved in money laundering and ransomware operations.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.