Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Critical Citrix ADC, Gateway Zero-Days Under Active Attack
September 30, 2026
Google Chrome Update Patches 32 Security Flaws Across Platforms
September 30, 2026
Cloudflare Launches Post-Quantum CA with Merkle Tree Certificates for Faster TLS
September 30, 2026
Home/Threats/Critical PaperCut RCE Flaws Let Attackers Compromise Domain Controllers
Threats

Critical PaperCut RCE Flaws Let Attackers Compromise Domain Controllers

Key Takeaways Attackers exploited two zero-day vulnerabilities in PaperCut MF print servers (CVE-2026-81578 and CVE-2026-82078) to gain initial access. The compromise allowed attackers to move from...

Emy Elsamnoudy
Emy Elsamnoudy
September 30, 2026 4 Min Read
3 0

Key Takeaways

  • Attackers exploited two zero-day vulnerabilities in PaperCut MF print servers (CVE-2026-81578 and CVE-2026-82078) to gain initial access.
  • The compromise allowed attackers to move from an internet-facing print server to a domain controller in under two days.
  • The threat actors deployed an AdaptixC2 implant disguised within a modified Microsoft Copilot binary and leveraged stolen access tokens to escalate privileges.
  • The attack highlights the critical risk posed by unpatched or exposed management applications and the importance of timely security updates.
  • Organizations should update PaperCut MF/NG immediately and implement strict network segmentation and monitoring.

An unpatched PaperCut MF print server recently served as the initial breach point for a sophisticated attack that ultimately led to the compromise of an Active Directory domain controller. This incident underscores the significant risk that seemingly peripheral business systems can pose when left exposed and vulnerable, providing a direct pathway to an organization’s most sensitive identity infrastructure.

Table Of Content

  • Key Takeaways
  • Exploiting PaperCut Zero-Days
  • Pathway to Domain Controller and Credential Theft
  • What You Should Do

The attack, detected on August 31, 2026, by security firm eSentire at an education-sector client, involved the exploitation of two previously undisclosed flaws in PaperCut MF, version 24.0.2, build 69746. Within a mere two days, the attackers successfully pivoted from the compromised print server to gain control over a domain controller, as detailed in a report shared with Cyber Security News (CSN).

Exploiting PaperCut Zero-Days

The initial compromise leveraged a chain of two critical vulnerabilities, CVE-2026-81578 and CVE-2026-82078. These flaws, when combined, allow an attacker to bypass authentication and execute arbitrary Java bytecode within the security context of the PaperCut server.

Attackers injected malicious Java code through the card or ID lookup field of the internet-facing PaperCut MF server. This led to the installation of an in-memory loader, which subsequently deployed a web shell. This web shell served as a persistent foothold, enabling the attackers to further deploy an AdaptixC2 implant. The implant was cleverly concealed within a modified Microsoft Copilot binary, a tactic designed to evade detection.

The first-stage loader was engineered for maximum compatibility across various Tomcat server versions. It reconstructed payload fragments in memory, initiated the next stage of the attack, and then meticulously erased its own files to hinder forensic analysis. The web shell, once active, received instructions via a unique HTTP header, executed commands, retrieved configuration data, and systematically purged traces from server logs and the application’s internal database. This thorough cleanup and the web shell’s integration early in the server’s request-processing chain aimed to maintain exclusive control and complicate investigation.

Following its deployment, the modified binary established communication with the attackers’ remote infrastructure but remained dormant for approximately 24 hours. This period of inactivity, followed by hands-on activity, illustrates a common tactic where threat actors utilize open-source command-and-control frameworks to expand their access post-breach.

Pathway to Domain Controller and Credential Theft

Once established, the attackers initiated reconnaissance, mapping hosts, network topology, domain trusts, and administrator groups. They identified a process operating under a domain-privileged service account. Instead of directly stealing a password, they copied its access token and relaunched their implant with the elevated privileges of that account. This token-based escalation allowed them to bypass traditional password requirements for lateral movement towards the domain controller.

With domain-level privileges, the threat group copied their malicious payload to the domain controller via an administrative file share. To execute the payload discreetly, they temporarily altered the Windows PlugPlay service configuration to launch their malicious code. After successful execution, they promptly stopped the service and restored its legitimate path, minimizing evidence of tampering.

On the domain controller, the attackers proceeded to dump credentials from both memory and the registry. They enabled Windows Restricted Admin mode, then used a recovered NTLM hash to authenticate over Remote Desktop Protocol (RDP). Their final objective on the domain controller was to create a copy of the Active Directory database. This database typically contains password hashes for every domain account, presenting a severe risk for further “pass-the-hash” attacks and extensive credential compromise. The exfiltrated database and supporting registry data were compressed into an archive.

The custom-built AdaptixC2 implant showcased advanced evasion techniques, including encrypted settings and obfuscated program logic, to thwart analysis. Furthermore, public sandboxes failed to execute the modified binary without its legitimate supporting Microsoft Copilot library, demonstrating a sophisticated approach to avoid detection. For detailed technical analysis, refer to the eSentire report.

What You Should Do

  • Apply Updates Immediately: Ensure all PaperCut MF and NG installations are updated to the latest available version. Timely patching is crucial, especially for actively exploited vulnerabilities.
  • Restrict Network Access: Limit access to PaperCut application servers to only trusted IP addresses. Avoid exposing these management interfaces directly to the internet.
  • Monitor for Suspicious Activity: Implement robust monitoring for child processes initiated by the PaperCut service, unexpected deletions or truncations of server logs, and any unusual post-exploitation behaviors.
  • Review Indicators of Compromise (IoCs): Consult the vendor advisory and security reports for specific IoCs, including file hashes, IP addresses, and URLs. Integrate these into your threat intelligence platforms.
    • URLs: hxxps://taibeianmo.oss-cn-hongkong.aliyuncs[.]com/mscopilot.exe, hxxps://uneedcargo.oss-accelerate.aliyuncs[.]com/65722.txt
    • IPv4: 47.79.64[.]225 (Download), 156.227.0[.]13 (C2)
    • File Hashes (SHA256): d2e55213a02fd16a077298c986130522eb63196bdf8a8c1aec0eed6ef318b222 (Trojanized Microsoft Copilot), cf6dd15baf5ef66432a95b5a2ec64ba5c6de565b3fb9e10ae01b1a91612a1c2c (Trojanized wa_3rd_party_host_64.exe), bc5fd75b307c2a11a602fbedb8275e0836ddf81cdd43af00a6bf0d850ff6cf58 (Java bytecode stage 1 loader, jakarta variant), 33d0a8294d2520608dbc4901c3ebd525aaeb7b8eceba9d140f62efa419a8c55a (Java bytecode stage 1 loader, javax variant), a8ff38e5f21a5202e1ce33e62b9ddde4ec4faffabd52a4a146cff18c877fe7ca (Decompiled stage 1 loader, jakarta variant), f893ab902cf0ad1a62cdfe04c58ba7560db7a0f5153303af18bd549c6619a044 (Decompiled stage 1 loader, javax variant), 9c8760f8b973360701774bc56c7c97295eb42d49a02a281cbaadc32c973bd8b2 (Java bytecode stage 2 shell, jakarta variant), d91c10536293d23bd3ebfc0f922e367303f455571556d83684170183dd6897f4 (Java bytecode stage 2 shell, javax variant), 8673371d266d041dae20f64e0532d2bca65c3b09a6c0faf16a6546e6067bac2e (Decompiled stage 2 shell, jakarta variant), 1a7541b30dcccd91e969f0e1586ba18fbf3a7d78f960654a5c1489108e516180 (Decompiled stage 2 shell, javax variant)
  • Minimize Service Account Permissions: Reduce the privileges of service accounts to the absolute minimum required for their function. This limits the potential impact of an access token compromise.
  • Enhance Endpoint Monitoring: Maintain rigorous endpoint detection and response (EDR) capabilities to detect and respond to anomalous process behavior and unauthorized changes to service configurations.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackBreachCVEExploitHackerSecurityThreatzero-day

Share Article

Emy Elsamnoudy

Emy Elsamnoudy

Emy is a cybersecurity analyst and reporter specializing in threat hunting, defense strategies, and industry trends. With expertise in proactive security measures, Emily covers the tools and techniques organizations use to detect and prevent cyber attacks. She is a regular speaker at security conferences and has contributed to industry reports on threat intelligence and security operations. Emily's reporting focuses on helping organizations improve their security posture through practical, actionable insights.

Previous Post

Attackers Impersonate Zoom, PDF Installers to Deliver Remote Access Trojans

Next Post

Critical Microsoft 365 Flaw Let Attackers Access Accounts

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
APT28 Targets Organizations With RedFlick Phishing Attacks
September 30, 2026
AI Coding Agents Leak 13,000+ Internal Screenshots from 300+ Companies on GitHub
September 30, 2026
Critical Microsoft 365 Flaw Let Attackers Access Accounts
September 30, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
David kimber
David kimber
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us