logo

Ransomware Roundup: 05.22.23

ID: bc1761cb-6f59-593d-8fb6-dce8ffcaa519

STIX ID: report--bc1761cb-6f59-593d-8fb6-dce8ffcaa519

Feed Name: Halcyon Blog

Threat Score
78/100

Date Published: 2023-05-22

Date Updated: 2026-04-28

...
...

This briefing reviews a series of recent ransomware and data-extortion incidents and trends: a disruptive ransomware attack at the Philadelphia Inquirer, mass exploitation of PaperCut CVE-2023-27350 by the Bl00dy group, large-scale automated campaigns such as Cl0p exploiting enterprise software, the emergence of highly automated strains (e.g., Rorschach) and exfiltration-focused gangs like BianLian, plus high-profile payments and sanctions/indictments linked to actors associated with Hive/LockBit/Babuk. The report emphasizes active exploitation, automation that increases scale, impacts to critical infrastructure and public-sector victims, and recommends timely patching, incident response preparedness, and resilience planning.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.