Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors DEV-0950

Also known as: Lace Tempest

Description

Lace Tempest, also known as DEV-0950, is a threat actor that exploited vulnerabilities in software such as SysAid and PaperCut to gain unauthorized access to systems. Lace Tempest is known for deploying the Clop ransomware and exfiltrating data from compromised networks.

AI Analysis

· 1 week ago

Executive Summary

DEV-0950, also known as Lace Tempest, is a cyber threat actor linked to the deployment of the Clop ransomware and data exfiltration through exploited vulnerabilities in software like SysAid and PaperCut. This group targets organizations with unpatched systems, leveraging known exploits to gain initial access and encrypt critical data for financial gain. Their operations pose significant risks to sectors reliant on these vulnerable platforms.

Goals & Targeting

The primary objective of DEV-0950 appears to be financial gain through ransom demands, as evidenced by the use of Clop ransomware and data exfiltration. Their targeting of software like SysAid and PaperCut aligns with efforts to compromise organizations with critical infrastructure dependencies, where system downtime can be highly disruptive. While no specific geographic regions or industries have been confirmed, the choice of vulnerabilities suggests a focus on sectors such as healthcare, education, and government, which may be more likely to pay ransoms to avoid operational halts. The actor’s activities also imply a lack of geopolitical motivation, prioritizing short-term financial returns over long-term strategic objectives.

Enhanced Description

Lace Tempest (DEV-0950) is a threat actor primarily associated with ransomware attacks, specifically deploying the Clop ransomware variant. The group exploits publicly known vulnerabilities in widely used software, such as SysAid (a helpdesk platform) and PaperCut (a print management system), to infiltrate networks. Once inside, they exfiltrate sensitive data before initiating encryption, a tactic consistent with double extortion schemes commonly seen in ransomware operations. While no specific sector or country has been explicitly tied to their activities, the targeting of infrastructure software suggests a focus on organizations that may prioritize operational continuity over robust cybersecurity measures. This group’s reliance on known exploits indicates a moderate level of sophistication, as they avoid advanced obfuscation techniques in favor of exploiting misconfigurations and unpatched systems. Their operations often lack attribution complexity, potentially to avoid detection and preserve operational flexibility.

Key Capabilities

  • Exploitation of known vulnerabilities in enterprise software (e.g., SysAid, PaperCut)
  • Deployment of Clop ransomware for data encryption and double extortion
  • Data exfiltration from compromised networks
  • Use of unpatched systems as initial access vectors
  • Operation without advanced obfuscation or zero-day exploits

MITRE ATT&CK Tactics

Initial Access
Execution
Persistence
Privilege Escalation
Defense Evasion
Credential Access
Discovery
Lateral Movement
Command and Control
Exfiltration
Impact

ATT&CK Techniques

T1210 - Exploit Public-Facing Application
T1530 - Data Encrypted for Impact
T1560 - Archive Collected Data
T1059.003 - Command-Line Interface
T1566.001 - Phishing

Software / Tooling

Clop Ransomware
Exploit kits targeting SysAid and PaperCut vulnerabilities
Custom data exfiltration utilities

Campaigns & Victims

DEV-0950’s campaigns follow a predictable pattern: exploiting unpatched vulnerabilities in specific software, deploying Clop ransomware, and exfiltrating data prior to encryption. Their operational tempo suggests a focus on quick strikes against targets with known unpatched systems, rather than prolonged network infiltration. Notable operations include attacks on organizations using outdated versions of SysAid and PaperCut, often resulting in significant financial and operational disruptions. The group’s activities indicate a lack of long-term campaign planning, with a focus on immediate financial gain through ransom payments.

IOC Patterns

  • Exploitation of unpatched SysAid and PaperCut vulnerabilities
  • Spear-phishing emails with malicious attachments or links
  • Clop ransomware signature detection
  • C2 communication over common protocols (e.g., HTTP, DNS)
  • Data exfiltration to external storage services

Recommended Actions

  • Apply security patches for SysAid and PaperCut immediately to mitigate exploitation risks.
  • Implement network segmentation to limit lateral movement post-compromise.
  • Deploy endpoint detection and response (EDR) tools to identify ransomware activity early.
  • Conduct regular phishing simulations to reduce the risk of initial access via social engineering.
  • Maintain offline backups of critical data to ensure recovery without paying ransoms.

Suggested Tags

APT
Ransomware
Data Exfiltration
Healthcare Sector
Education Sector
Government Sector

Confidence Assessment

The confidence level in this analysis is moderate due to limited data on DEV-0950’s primary motivation, sophistication level, and geographic targeting. While the exploitation of specific vulnerabilities and use of Clop ransomware are well-documented, gaps exist in understanding the actor’s command structure, long-term objectives, and potential ties to other threat groups. Further analysis of IOCs and network telemetry could refine these insights.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

Ransomware
APT
Data Exfiltration
Healthcare Sector
Education Sector
Government Sector

Details

Type
Unknown
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.