
PaperCut RCE to Bl00dy Ransomware
Bl00dy ransomware actors exploited an unauthenticated access-control flaw (CVE-2023-27350) on an internet-facing PaperCut MF/NG print-management server, ran code as the application service account, staged a TrueBot loader and a Cobalt Strike beacon, installed Atera and AnyDesk for hands-on remote access, moved laterally over RDP, tunnelled the file share out through a Tor helper, and deployed the Bl00dy encryptor fleet-wide. Reconstruct the intrusion from SIEM, endpoint XDR, and perimeter firewall telemetry and classify the key ATT&CK techniques.
Start this operation
Investigation Tasks
Complete each task by investigating alerts and submitting your findings.
Incident brief
0Orient yourself before pivoting into the data. This is a no-answer briefing checkpoint.
Find the foothold
30Before anything else moved, someone reached the public print server without ever logging in and made it run code. Identify the external address behind the unauthenticated requests that took over the application.
Classify the initial access
15No credential was phished and no endpoint was infected. The attacker abused the internet-facing application itself. Map the initial breach to its MITRE ATT&CK technique.
Recover the loader hash
35From the foothold the attacker pulled a payload that unpacked a command-and-control loader to disk. Pin down its file-level indicator so it can be hunted fleet-wide. Provide the SHA-256 of the loader DLL.
Trace the loader C2
30The loader called home. Correlate the host beacon with the name resolution and the perimeter egress, and identify the command-and-control domain it reached.
Classify the remote-access tooling
20Rather than rely only on its malware, the crew installed legitimate management software to keep hands-on control. Identify the MITRE ATT&CK technique that covers this.
Trace the data theft
35Before encrypting anything, the attacker tunnelled data out for leverage. Correlate the host activity with the perimeter egress and identify the external endpoint that received the stolen file share.
Classify the impact
20Roughly ninety minutes after the initial exploit, files across several servers were encrypted. Classify the final objective with its MITRE ATT&CK technique.
8 tasks · 185 points total
Training Tools
Skills You'll Build
Requires foundational alert triage skills. Multiple data sources to correlate.
Prerequisites
- Basic understanding of security alerts
- Familiarity with SIEM concepts
- Familiarity with XDR concepts
- Familiarity with Firewall concepts
Ready to investigate?
More Operations
View allCopyright Lure to Rhadamanthys Stealer
A procurement officer opened a copyright-infringement notice, followed a shortened link, and ran a signed PDF reader out of a Downloads folder. Follow the chain from a CDN-fronted delivery domain through a DLL search-order hijack and a Run-key autostart to the Rhadamanthys stealer's single command-and-control channel, where the beacon and the stolen data ride together.
Emotet Revival: Triage the November Loader
An operations coordinator opened a thread-hijacked remittance spreadsheet and enabled its macro. A trusted Windows utility quietly fetched a loader from a compromised website, and the workstation started beaconing to addresses nobody recognized. Trace the rebuilt November Emotet loader from a hijacked mail thread through a regsvr32 download-and-register, an encrypted epoch command-and-control pool, and a Cobalt Strike second stage.
GootLoader: SEO Poisoning to Domain Control
A paralegal searching for a contract template clicked a poisoned search result and a quiet endpoint script alert turned into a domain controller compromise by nightfall. Follow the chain from a drive-by ZIP through an obfuscated JavaScript loader, scheduled-task and Run-key persistence, a Cobalt Strike beacon, and a SystemBC proxy to the domain controller.