Iran-linked APT groups started exploiting Papercut flaw

Pierluigi Paganini May 09, 2023

Microsoft warns of Iran-linked APT groups that are targeting vulnerable PaperCut MF/NG print management servers.

Microsoft warns that Iran-linked APT groups have been observed exploiting the CVE-2023-27350 flaw in attacks against PaperCut MF/NG print management servers.

The CVE-2023-27350 flaw is a PaperCut MF/NG Improper Access Control Vulnerability. PaperCut MF/NG contains an improper access control vulnerability within the SetupCompleted class that allows authentication bypass and code execution in the context of SYSTEM.

On April 19th, Print management software provider PaperCut confirmed that it is aware of the active exploitation of the CVE-2023-27350 vulnerability.

The company received two vulnerability reports from the cybersecurity firm Trend Micro for high/critical severity security issues in PaperCut MF/NG. 

Now Microsoft observed Iran-linked groups Mango Sandstorm (aka Mercury or Muddywater) and Mint Sandstorm (aka Phosphorus or APT35) exploiting the above flaw.

“More actors are exploiting unpatched CVE-2023-27350 in print management software Papercut since we last reported on Lace Tempest. Microsoft has now observed Iranian state-sponsored threat actors Mint Sandstorm (PHOSPHORUS) & Mango Sandstorm (MERCURY) exploiting CVE-2023-27350.” reads a tweet published by the Microsoft Threat Intelligence team.

Microsoft experts highlighted that both APT groups started exploiting the flaw shortly after public POCs were published for CVE-2023-27350. The attacks show the ability of both groups to rapidly adapt their operations by adding new POC exploits to their arsenal.

The researchers believe the PaperCut exploitation activity by the Mint Sandstorm group is opportunistic, they observed the Iranian group targeing organizations across sectors and geographies.

Microsoft reported that CVE-2023-27350 exploitation activity by the second Iranian APT, Mango Sandstorm, remains low. The state-sponsored hackers were observed using tools from prior intrusions to connect to their C2 infrastructure.

The IT giant urges organizations to address the CVE-2023-27350 vulnerability to prevent its exploitation by threat actors, including Iran-linked APT groups.

PaperCut MF and NG software should be immediately upgraded to versions 20.1.7, 21.2.11, and 22.0.9 and later.

We are in the final!

Please vote for Security Affairs (https://securityaffairs.com/) as the best European Cybersecurity Blogger Awards 2022 – VOTE FOR YOUR WINNERS
Vote for me in the sections where is reported Securityaffairs or my name Pierluigi Paganini

Please nominate Security Affairs as your favorite blog.

Nominate Pierluigi Paganini and Security Affairs here here: https://docs.google.com/forms/d/e/1FAIpQLSepvnj8b7QzMdLh7vWEDQDqohjBUsHyn3x3xRdYGCetwVy2DA/viewform

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, Iran)



you might also like

leave a comment