Microsoft Confirms PaperCut Servers Used to Deliver LockBit and Cl0p Ransomware

Microsoft has determined that attacks aimed at delivering the Cl0p and LockBit ransomware families are connected to the active exploitation of PaperCut servers.

A portion of the incursions are being attributed by the tech giant’s threat intelligence team to an actor it tracks by the name of Lace Tempest (formerly known as DEV-0950), who shares similarities with other hacker outfits including FIN11, TA505, and Evil Corp.

Microsoft stated in a series of tweets that in the attacks it has observed, “Lace Tempest ran multiple PowerShell commands to deliver a TrueBot DLL, which connected to a C2 server, attempted to steal LSASS credentials, and injected the TrueBot payload into the conhost.exe service read more Microsoft Confirms PaperCut Servers Used to Deliver LockBit and Cl0p Ransomware.

With ReconBee.com Stay ahead of the latest threats with in-depth coverage of cyber attacks and cybersecurity trends, and the latest cybersecurity news.

Leave a Reply

Your email address will not be published. Required fields are marked *