logo

BL00DY Ransomware Targets Indian University

ID: d09b0772-7bb8-55c2-8fe4-2241184afb3e

STIX ID: report--d09b0772-7bb8-55c2-8fe4-2241184afb3e

Feed Name: Cyble Blog

Threat Score
78/100

Date Published: 2025-11-17

Date Updated: 2026-07-16

...
...

Bl00dy ransomware actively exploited the critical PaperCut NG vulnerability (CVE-2023-27350, CVSS 9.8) to compromise an Indian university on 28 May 2023, demonstrating administrative RDP access, exposed ports (9191/3389), access to Active Directory (10,014 systems), and exfiltration of servers/data with a USD 90,000 ransom demand; the report notes prior attacks on US educational institutions, cites ~1,013 publicly exposed vulnerable instances, references FBI/CISA advisories, and provides remediation and network-hardening recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.