Critical PaperCut RCE Flaws Let Attackers Compromise Domain Controllers
Key Takeaways Attackers exploited two zero-day vulnerabilities in PaperCut MF print servers (CVE-2026-81578 and CVE-2026-82078) to gain initial access. The compromise allowed attackers to move from...
Key Takeaways
- Attackers exploited two zero-day vulnerabilities in PaperCut MF print servers (CVE-2026-81578 and CVE-2026-82078) to gain initial access.
- The compromise allowed attackers to move from an internet-facing print server to a domain controller in under two days.
- The threat actors deployed an AdaptixC2 implant disguised within a modified Microsoft Copilot binary and leveraged stolen access tokens to escalate privileges.
- The attack highlights the critical risk posed by unpatched or exposed management applications and the importance of timely security updates.
- Organizations should update PaperCut MF/NG immediately and implement strict network segmentation and monitoring.
An unpatched PaperCut MF print server recently served as the initial breach point for a sophisticated attack that ultimately led to the compromise of an Active Directory domain controller. This incident underscores the significant risk that seemingly peripheral business systems can pose when left exposed and vulnerable, providing a direct pathway to an organization’s most sensitive identity infrastructure.
Table Of Content
The attack, detected on August 31, 2026, by security firm eSentire at an education-sector client, involved the exploitation of two previously undisclosed flaws in PaperCut MF, version 24.0.2, build 69746. Within a mere two days, the attackers successfully pivoted from the compromised print server to gain control over a domain controller, as detailed in a report shared with Cyber Security News (CSN).
Exploiting PaperCut Zero-Days
The initial compromise leveraged a chain of two critical vulnerabilities, CVE-2026-81578 and CVE-2026-82078. These flaws, when combined, allow an attacker to bypass authentication and execute arbitrary Java bytecode within the security context of the PaperCut server.
Attackers injected malicious Java code through the card or ID lookup field of the internet-facing PaperCut MF server. This led to the installation of an in-memory loader, which subsequently deployed a web shell. This web shell served as a persistent foothold, enabling the attackers to further deploy an AdaptixC2 implant. The implant was cleverly concealed within a modified Microsoft Copilot binary, a tactic designed to evade detection.
The first-stage loader was engineered for maximum compatibility across various Tomcat server versions. It reconstructed payload fragments in memory, initiated the next stage of the attack, and then meticulously erased its own files to hinder forensic analysis. The web shell, once active, received instructions via a unique HTTP header, executed commands, retrieved configuration data, and systematically purged traces from server logs and the application’s internal database. This thorough cleanup and the web shell’s integration early in the server’s request-processing chain aimed to maintain exclusive control and complicate investigation.
Following its deployment, the modified binary established communication with the attackers’ remote infrastructure but remained dormant for approximately 24 hours. This period of inactivity, followed by hands-on activity, illustrates a common tactic where threat actors utilize open-source command-and-control frameworks to expand their access post-breach.
Pathway to Domain Controller and Credential Theft
Once established, the attackers initiated reconnaissance, mapping hosts, network topology, domain trusts, and administrator groups. They identified a process operating under a domain-privileged service account. Instead of directly stealing a password, they copied its access token and relaunched their implant with the elevated privileges of that account. This token-based escalation allowed them to bypass traditional password requirements for lateral movement towards the domain controller.
With domain-level privileges, the threat group copied their malicious payload to the domain controller via an administrative file share. To execute the payload discreetly, they temporarily altered the Windows PlugPlay service configuration to launch their malicious code. After successful execution, they promptly stopped the service and restored its legitimate path, minimizing evidence of tampering.
On the domain controller, the attackers proceeded to dump credentials from both memory and the registry. They enabled Windows Restricted Admin mode, then used a recovered NTLM hash to authenticate over Remote Desktop Protocol (RDP). Their final objective on the domain controller was to create a copy of the Active Directory database. This database typically contains password hashes for every domain account, presenting a severe risk for further “pass-the-hash” attacks and extensive credential compromise. The exfiltrated database and supporting registry data were compressed into an archive.
The custom-built AdaptixC2 implant showcased advanced evasion techniques, including encrypted settings and obfuscated program logic, to thwart analysis. Furthermore, public sandboxes failed to execute the modified binary without its legitimate supporting Microsoft Copilot library, demonstrating a sophisticated approach to avoid detection. For detailed technical analysis, refer to the eSentire report.
What You Should Do
- Apply Updates Immediately: Ensure all PaperCut MF and NG installations are updated to the latest available version. Timely patching is crucial, especially for actively exploited vulnerabilities.
- Restrict Network Access: Limit access to PaperCut application servers to only trusted IP addresses. Avoid exposing these management interfaces directly to the internet.
- Monitor for Suspicious Activity: Implement robust monitoring for child processes initiated by the PaperCut service, unexpected deletions or truncations of server logs, and any unusual post-exploitation behaviors.
- Review Indicators of Compromise (IoCs): Consult the vendor advisory and security reports for specific IoCs, including file hashes, IP addresses, and URLs. Integrate these into your threat intelligence platforms.
- URLs:
hxxps://taibeianmo.oss-cn-hongkong.aliyuncs[.]com/mscopilot.exe,hxxps://uneedcargo.oss-accelerate.aliyuncs[.]com/65722.txt - IPv4:
47.79.64[.]225(Download),156.227.0[.]13(C2) - File Hashes (SHA256):
d2e55213a02fd16a077298c986130522eb63196bdf8a8c1aec0eed6ef318b222(Trojanized Microsoft Copilot),cf6dd15baf5ef66432a95b5a2ec64ba5c6de565b3fb9e10ae01b1a91612a1c2c(Trojanized wa_3rd_party_host_64.exe),bc5fd75b307c2a11a602fbedb8275e0836ddf81cdd43af00a6bf0d850ff6cf58(Java bytecode stage 1 loader, jakarta variant),33d0a8294d2520608dbc4901c3ebd525aaeb7b8eceba9d140f62efa419a8c55a(Java bytecode stage 1 loader, javax variant),a8ff38e5f21a5202e1ce33e62b9ddde4ec4faffabd52a4a146cff18c877fe7ca(Decompiled stage 1 loader, jakarta variant),f893ab902cf0ad1a62cdfe04c58ba7560db7a0f5153303af18bd549c6619a044(Decompiled stage 1 loader, javax variant),9c8760f8b973360701774bc56c7c97295eb42d49a02a281cbaadc32c973bd8b2(Java bytecode stage 2 shell, jakarta variant),d91c10536293d23bd3ebfc0f922e367303f455571556d83684170183dd6897f4(Java bytecode stage 2 shell, javax variant),8673371d266d041dae20f64e0532d2bca65c3b09a6c0faf16a6546e6067bac2e(Decompiled stage 2 shell, jakarta variant),1a7541b30dcccd91e969f0e1586ba18fbf3a7d78f960654a5c1489108e516180(Decompiled stage 2 shell, javax variant)
- URLs:
- Minimize Service Account Permissions: Reduce the privileges of service accounts to the absolute minimum required for their function. This limits the potential impact of an access token compromise.
- Enhance Endpoint Monitoring: Maintain rigorous endpoint detection and response (EDR) capabilities to detect and respond to anomalous process behavior and unauthorized changes to service configurations.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.