Hackers Turned a PaperCut Print Server Into a Path to the Domain Controller
Attackers chained two PaperCut MF zero-days to reach an education customer's domain controller in under two days.
eSentire reported that attackers exploited two PaperCut MF zero-days, CVE-2026-81578 and CVE-2026-82078, on an internet-facing version 24.0.2 server at an education customer. Unauthenticated Java execution led to an in-memory loader, a web shell, and an AdaptixC2 implant hidden in a modified Microsoft Copilot binary. Within two days the attackers stole a privileged service token, executed on a domain controller, dumped credentials, used an NTLM hash over RDP, and copied the Active Directory database. The flaws were described as actively exploited; eSentire isolated the host and advised patching and restricting access.
- Attackers chained CVE-2026-81578 and CVE-2026-82078 on PaperCut MF 24.0.2.
- eSentire detected the education-sector intrusion on August 31, 2026.
- An in-memory loader and web shell deployed AdaptixC2 inside a trojanized Copilot binary.
- Token theft and a modified PlugPlay service reached the domain controller in under two days.
- Attackers dumped credentials and copied the Active Directory database for exfiltration.
Vulnerabilities mentionedAll →
- CVE-2026-820789.44%Unsafe Reflection RCE in PaperCut NG/MF, Chained with Auth Bypass in Attackspublished · PaperCut NG KEV+1 related
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
CVE-2026-82078+1 related CVE |
Indicators of compromiseauto-extracted · verify before use · export allAll →
| Type | Indicator | Context |
|---|---|---|
| domain | aliyuncs.com | ndicator Description URL hxxps://taibeianmo.oss-cn-hongkong.aliyuncs[.]com/mscopilot.exe Download URL for AdaptixC2 implant URL hxxp |
| sha256 | 1a7541b30dcccd91e969f0e1586ba18fbf3a7d78f960654a5c1489108e516180 | 67bac2e Decompiled stage 2 shell, jakarta variant File hash 1a7541b30dcccd91e969f0e1586ba18fbf3a7d78f960654a5c1489108e516180 Decompiled stage 2 shell, javax variant Note: IP addresses |
| sha256 | 33d0a8294d2520608dbc4901c3ebd525aaeb7b8eceba9d140f62efa419a8c55a | f58 Java bytecode stage 1 loader, jakarta variant File hash 33d0a8294d2520608dbc4901c3ebd525aaeb7b8eceba9d140f62efa419a8c55a Java bytecode stage 1 loader, javax variant File hash a8ff3 |
| sha256 | 8673371d266d041dae20f64e0532d2bca65c3b09a6c0faf16a6546e6067bac2e | 6897f4 Java bytecode stage 2 shell, javax variant File hash 8673371d266d041dae20f64e0532d2bca65c3b09a6c0faf16a6546e6067bac2e Decompiled stage 2 shell, jakarta variant File hash 1a7541b |
| sha256 | 9c8760f8b973360701774bc56c7c97295eb42d49a02a281cbaadc32c973bd8b2 | 6619a044 Decompiled stage 1 loader, javax variant File hash 9c8760f8b973360701774bc56c7c97295eb42d49a02a281cbaadc32c973bd8b2 Java bytecode stage 2 shell, jakarta variant File hash d91c |
Full article892 words · extracted from cybersecuritynews.com · click to collapse
A vulnerable print server became the entry point for an Active Directory compromise after attackers exploited two PaperCut MF zero-day flaws.
The intrusion shows how an overlooked business system can give criminals access to sensitive identity infrastructure. The attackers targeted an internet-facing PaperCut MF server running version 24.0.2, build 69746.
They delivered Java code through the card or ID lookup field, installed an in-memory loader and web shell, used that foothold to deploy an AdaptixC2 implant hidden inside a modified Microsoft Copilot binary.
eSentire said in a report shared with Cyber Security News (CSN) that its analysts detected the intrusion on August 31, 2026, at an education-sector customer. Its analysts found that the attackers moved from the print server to a domain controller in less than two days.
The case underlines the danger of leaving management applications exposed online. It follows reports that the PaperCut flaws were actively exploited, with defenders warned to restrict public access and watch for suspicious activity from the service.
Hackers Turned a PaperCut Print Server
The initial compromise relied on CVE-2026-81578 and CVE-2026-82078, a pair of vulnerabilities that can be chained to alter settings without authentication and run malicious Java bytecode in the PaperCut server’s security context.
Earlier coverage of the actively exploited PaperCut flaws explains why internet-facing application servers need urgent attention. The first-stage loader was designed for broad compatibility across different Tomcat releases.
It rebuilt payload fragments in memory, started the next stage, and removed its own files. The web shell then accepted instructions through a custom HTTP header, ran commands, read configuration values, and deleted traces from logs and the internal application database.
.webp)
That cleanup mattered. The web shell also placed itself early in the server’s request-processing chain and blocked unrelated attempts to use the same weakness. In effect, the attackers tried to preserve exclusive control while making the original break-in harder to investigate.
The modified binary established contact with remote attacker infrastructure, then remained quiet for roughly a day. Operators then returned for hands-on activity, illustrating how attackers use open-source command-and-control attack frameworks to expand access after breaching a vulnerable server.
Credential Theft
Once active, the attackers surveyed hosts, networks, domain trusts, and administrator groups. They identified a process running under a domain-privileged service account, copied its access token, and relaunched the implant with that account’s rights.
No stolen administrator password was needed to begin the move toward the domain controller. Using those privileges, the group copied its payload to the domain controller through an administrative file share.
It then temporarily changed the Windows PlugPlay service configuration to start the payload, stopped the service after launch, and restored the legitimate service path.
That sequence allowed execution while reducing evidence of the change. On the domain controller, the attackers dumped credentials from memory and the registry.
They enabled Windows Restricted Admin mode, used a recovered NTLM hash to sign in over Remote Desktop Protocol, and created a copy of the Active Directory database.
That database can contain password hashes for every domain account, creating a serious risk of further pass-the-hash movement. The attackers packaged the database and supporting registry data into an archive for exfiltration.
Their customized implant used encrypted settings and scrambled program logic to hinder analysis. Public sandboxes also failed to run the modified binary when its legitimate supporting library was missing.
Administrators should update PaperCut MF or NG to the latest release and allow only trusted IP addresses to reach its application servers.
They should monitor child processes of the PaperCut service, missing or unexpectedly shortened server logs, and unusual post-exploitation behavior. Recent reporting on emergency PaperCut security updates also highlights the need to apply vendor fixes without delay.
Security teams should review the vendor advisory’s indicators, look for the log errors identified by the researchers, and investigate unexpected changes to service configurations.
Researchers also recommend reducing service-account permissions and maintaining endpoint monitoring. eSentire isolated the affected host and helped the customer with remediation following the intrusion.
Indicators of Compromise (IoCs):-
| Type | Indicator | Description |
|---|---|---|
| URL | hxxps://taibeianmo.oss-cn-hongkong.aliyuncs[.]com/mscopilot.exe | Download URL for AdaptixC2 implant |
| URL | hxxps://uneedcargo.oss-accelerate.aliyuncs[.]com/65722.txt | Additional OSINT-discovered download URL for the same AdaptixC2 implant |
| IPv4 | 47.79.64[.]225 | Download IP for AdaptixC2 implant |
| IPv4 | 156.227.0[.]13 | AdaptixC2 command-and-control server IP |
| File hash | d2e55213a02fd16a077298c986130522eb63196bdf8a8c1aec0eed6ef318b222 | Trojanized Microsoft Copilot with AdaptixC2 implant |
| File hash | cf6dd15baf5ef66432a95b5a2ec64ba5c6de565b3fb9e10ae01b1a91612a1c2c | Trojanized wa_3rd_party_host_64.exe, named PulseSecure.exe, with AdaptixC2 implant |
| File hash | bc5fd75b307c2a11a602fbedb8275e0836ddf81cdd43af00a6bf0d850ff6cf58 | Java bytecode stage 1 loader, jakarta variant |
| File hash | 33d0a8294d2520608dbc4901c3ebd525aaeb7b8eceba9d140f62efa419a8c55a | Java bytecode stage 1 loader, javax variant |
| File hash | a8ff38e5f21a5202e1ce33e62b9ddde4ec4faffabd52a4a146cff18c877fe7ca | Decompiled stage 1 loader, jakarta variant |
| File hash | f893ab902cf0ad1a62cdfe04c58ba7560db7a0f5153303af18bd549c6619a044 | Decompiled stage 1 loader, javax variant |
| File hash | 9c8760f8b973360701774bc56c7c97295eb42d49a02a281cbaadc32c973bd8b2 | Java bytecode stage 2 shell, jakarta variant |
| File hash | d91c10536293d23bd3ebfc0f922e367303f455571556d83684170183dd6897f4 | Java bytecode stage 2 shell, javax variant |
| File hash | 8673371d266d041dae20f64e0532d2bca65c3b09a6c0faf16a6546e6067bac2e | Decompiled stage 2 shell, jakarta variant |
| File hash | 1a7541b30dcccd91e969f0e1586ba18fbf3a7d78f960654a5c1489108e516180 | Decompiled stage 2 shell, javax variant |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC
Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.