Skip to main content
PaperCut RCE to Bl00dy Ransomware operation cover
COMING SOONIntermediatePRO

PaperCut RCE to Bl00dy Ransomware

Bl00dy ransomware actors exploited an unauthenticated access-control flaw (CVE-2023-27350) on an internet-facing PaperCut MF/NG print-management server, ran code as the application service account, staged a TrueBot loader and a Cobalt Strike beacon, installed Atera and AnyDesk for hands-on remote access, moved laterally over RDP, tunnelled the file share out through a Tor helper, and deployed the Bl00dy encryptor fleet-wide. Reconstruct the intrusion from SIEM, endpoint XDR, and perimeter firewall telemetry and classify the key ATT&CK techniques.

1h
8 tasks
50 points
Pro

Launches in 5 days

Jul 28, 2026

Tuesday, July 28, 2026 at 9:00 AM

View Pro plans

Pro unlocks this operation at launch.

Training Tools

SIEMXDRFirewall

What you'll investigate

8 objectives unlock when this operation goes live.

1Incident brief
2Find the foothold
3Classify the initial access
4Recover the loader hash
5Trace the loader C2
6Classify the remote-access tooling
7Trace the data theft
8Classify the impact

Be first when it launches

Create your account and grab Pro before launch. The moment this operation goes live on Jul 28, 2026, you can jump straight in.

Get Started Free