BL00DY Ransomware Targets Indian University
ID: d09b0772-7bb8-55c2-8fe4-2241184afb3e
STIX ID: report--d09b0772-7bb8-55c2-8fe4-2241184afb3e
Feed Name: Cyble Blog
Bl00dy ransomware actively exploited the critical PaperCut NG vulnerability (CVE-2023-27350, CVSS 9.8) to compromise an Indian university on 28 May 2023, demonstrating administrative RDP access, exposed ports (9191/3389), access to Active Directory (10,014 systems), and exfiltration of servers/data with a USD 90,000 ransom demand; the report notes prior attacks on US educational institutions, cites ~1,013 publicly exposed vulnerable instances, references FBI/CISA advisories, and provides remediation and network-hardening recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
