Dev-0950

Threat Actor updated 5 months ago (2024-05-05T12:17:34.830Z)
Download STIX
Preview STIX
Lace Tempest, also known as DEV-0950 or TA-505, is a threat actor associated with the deployment of Clop ransomware. This group has been noted for its use of GoAnywhere exploits and Raspberry Robin infection hand-offs in past ransomware campaigns. Microsoft has attributed recent attacks exploiting the CVE-2023-27350 and CVE-2023-27351 vulnerabilities in PaperCut, a print management software, to this threat actor. These vulnerabilities have been leveraged by Lace Tempest to deliver Clop ransomware, posing significant cybersecurity threats. The threat actor incorporated the PaperCut exploits into their attack campaigns as early as April 13, according to Microsoft's security intelligence team. The exploitation of these vulnerabilities highlights the adaptive nature of Lace Tempest, which continuously incorporates new techniques and vulnerabilities into its arsenal to increase the effectiveness of its malicious activities. This evolution in tactics underscores the need for continuous monitoring and updating of cybersecurity defenses to keep pace with emerging threats. Microsoft’s threat intelligence team and SysAid’s Advisory have confirmed that the CVE-2023-27350 and CVE-2023-27351 vulnerabilities have been exploited in the wild by Lace Tempest. The confirmation of these exploits by two independent bodies lends credibility to the attribution and underscores the seriousness of the threat posed by Lace Tempest. This information serves as a critical warning for organizations to patch these vulnerabilities promptly and reinforce their security measures against the evolving tactics of threat actors like DEV-0950.
Description last updated: 2024-05-05T11:53:06.318Z
Aliases We are not currently tracking any aliases
Miscellaneous Associations
Other elements of context that could aid in the identification of relevance
Analyst Notes & Discussion
Be the first to leave your mark here! Log in to share your views and vote.
Source Document References
Information about the Dev-0950 Threat Actor was read from the documents corpus below. This display is limited to 20 results, create a free account to see more