Desk live·
ForensicPost
Cloud/Exploitation/File 23-0413

Cl0p and LockBit Both Exploited PaperCut a Month After the Patch Shipped

PaperCut patched an unauthenticated remote code execution flaw in March 2023. Exploitation began around 13 April, and both Cl0p and LockBit — competitors — were using the same vulnerability within weeks.

Constructed geometry · not a chart of case data
JurisdictionUSAthe affected organisation’s jurisdiction, not the actor’s suspected origin
TargetPaperCut MF/NG operators
ActorCl0p, LockBit
S. Rosler11 min readConfidence: high3 sources reviewed

CVE-2023-27350 is an unauthenticated remote code execution flaw in PaperCut MF and NG print management software, permitting code execution as SYSTEM. PaperCut released a patch in March 2023. Reporting places exploitation from around 13 April 2023, and CISA subsequently issued a joint advisory.

Both the Cl0p and LockBit operations were reported using it, along with other actors; a group identifying itself as Bl00dy was reported targeting education sector servers in early May.

Nobody Inventories The Print Server

Print management is administrative plumbing. It is installed to meter and charge for printing, it runs on a server nobody visits, and it typically runs with high privilege because managing printers requires it.

That combination — high privilege, low attention, frequently reachable — is the profile we keep recording. At 22-0930 it was on-premises Exchange; at 22-0118 a self-service password tool; at 23-1010 a network appliance. The vulnerable thing is rarely the system anyone would name if asked what mattered.

Competitors Do Not Compete On Vulnerabilities

Cl0p and LockBit were rivals for affiliates, victims and reputation. Both adopted the same flaw within weeks of exploitation beginning.

An exploitable vulnerability is not a competitive asset once it is public; it is shared infrastructure, and the window between disclosure and mass exploitation is the only variable a defender controls. We have recorded the same convergence at 23-0203 and 23-0601, where a single file transfer flaw supplied a whole season of victims.

The Patch Preceded The Exploitation

A fix existed roughly a month before attacks began. This is not a zero-day story; it is a patch-application story, and the population reached was the population that had not updated an unglamorous internal server.

We filed that pattern at 22-0118, where a humanitarian organisation was reached through a flaw fixed months earlier, and at 23-0518. The desk does not read it as negligence: the organisations that fall to this are the ones without an inventory complete enough to know the server exists.

How we reported this

Compiled from vendor research, CISA’s joint advisory and contemporaneous reporting, listed below. Actor naming here follows the vendors’ own clustering and is carried as attribution, not as established fact. No victim count is asserted — no authoritative total was published. No exploit detail or indicator is reproduced. Graded high. Corrections: corrections@forensicpost.com.

Sources
  1. Malicious Actors Exploit CVE-2023-27350 in PaperCut MF and NG (AA23-131A)CISA
  2. CVE-2023-27350: Ongoing Exploitation of PaperCut VulnerabilityRapid7
  3. PaperCut vulnerabilities leveraged by Clop, LockBit ransomware affiliatesHelp Net Security
S. Rosler
Covers extortion groups and leak-site economics. Verifies our sample sets.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary