Attackers Use PaperCut RCE Chain to Steal Tokens and Access Domain Controller
Attackers chained PaperCut MF zero-days CVE-2026-81578 and CVE-2026-82078 to deploy a web shell and dump Active Directory from a domain controller.
eSentire detected an intrusion where threat actors exploited CVE-2026-81578 (authentication bypass) and CVE-2026-82078 (unsafe dynamic class loading, CVSS 9.4) against an internet-exposed PaperCut MF 24.0.2 server in the education sector; both CVEs are in CISA's KEV catalog. The attackers delivered hex-encoded Java classes through the card/ID lookup feature to load an in-memory Jetty web shell controlled via the X-Quad header. They then deployed a trojanized mscopilot.exe embedding an AdaptixC2 implant, duplicated a domain-privileged service account token, moved laterally to a domain controller, and created an NTDS.dit IFM backup for offline hash extraction.
- CVE-2026-81578 plus CVE-2026-82078 (CVSS 9.4) added to CISA KEV catalog
- In-memory loader rebuilt payload from .bin chunks via MethodHandles, then deleted artifacts
- Trojanized mscopilot.exe delivered AdaptixC2; msedge_elf.dll dependency evaded public sandboxes
- Operators hijacked PlugPlay service, used pass-the-hash RDP, archived NTDS.dit with ntdsutil
- Emergency patches cover v24, v25, v26 branches; restrict internet exposure of print servers
Vulnerabilities mentionedAll →
- CVE-2026-820789.44%Unsafe Reflection RCE in PaperCut NG/MF, Chained with Auth Bypass in Attackspublished · PaperCut NG KEV+1 related
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
CVE-2026-82078+1 related CVE |
Indicators of compromiseauto-extracted · verify before use · export allAll →
| Type | Indicator | Context |
|---|---|---|
| domain | aliyuncs.com | pe Value Description URL hxxps://taibeianmo.oss-cn-hongkong.aliyuncs[.]com/mscopilot.exe Download URL for AdaptixC2 implant URL hxxp |
| url | https://taibeianmo.oss-cn-hongkong.aliyuncs[ | ectory. Indicators of Compromise Type Value Description URL hxxps://taibeianmo.oss-cn-hongkong.aliyuncs[.]com/mscopilot.exe Download URL for AdaptixC2 implant URL h |
| url | https://uneedcargo.oss-accelerate.aliyuncs[ | [.]com/mscopilot.exe Download URL for AdaptixC2 implant URL hxxps://uneedcargo.oss-accelerate.aliyuncs[.]com/65722.txt Additional OSINT-discovered download URL for |
Full article924 words · extracted from gbhackers.com · click to collapse
Threat actors exploited a chained pair of PaperCut MF zero-day vulnerabilities to compromise an education-sector environment, steal a domain-privileged service account token, and reach a domain controller before attempting to extract the Active Directory database.
The campaign abused CVE-2026-81578, an authentication-bypass vulnerability in PaperCut MF and NG’s web management interface, together with CVE-2026-82078, a critical unsafe dynamic class-loading vulnerability in the database connector.
The combination allowed an unauthenticated attacker to alter configuration and execute arbitrary Java bytecode in the PaperCut server process context.
PaperCut’s advisory assigns a 9.4 CVSS score to CVE-2026-82078, while the pair has been added to CISA’s Known Exploited Vulnerabilities catalog.
The targeted server was running PaperCut MF 24.0.2 Build 69746 and was exposed to the internet.
Attackers delivered hex-encoded compiled Java classes through the application’s card/ID lookup functionality, leaving SQL statements and byte blobs beginning with the Java class-file signature 0xCAFEBABE in server.log.
The initial in-memory loader was built to support both Tomcat 9-or-earlier and Tomcat 10-or-later deployments, using either javax.servlet.Filter or jakarta.servlet.Filter.
It reconstructed a second-stage payload from numbered .bin chunks, loaded the Java bytecode directly in memory through MethodHandles.lookup().defineClass(), and deleted its artifacts after execution.
That payload acted as a Jetty filter-based web shell controlled through the X-Quad HTTP header.
Supported arbitrary JavaScript and expression-language evaluation, operating-system command execution, PaperCut configuration access, and log tampering.

Credential-access activity followed. The attackers attempted LSASS memory dumping, captured the SAM hive, and enabled Windows Restricted Admin mode by setting DisableRestrictedAdmin to 0.
It could also erase exploitation evidence from the PaperCut Derby database and server.log, then patch the abused request path to block competing attackers from reusing the same vulnerability.
PaperCut RCE Chain
Using the web shell, the operators downloaded a trojanized mscopilot.exe from 47.79.64[.]225, an IP associated with Alibaba-hosted infrastructure.
The intrusion, detected by eSentire’s Threat Response Unit on August 31, demonstrates how an exposed print-management server can become a direct route to enterprise-wide identity compromise.
The altered Microsoft Copilot binary contained an embedded AdaptixC2 implant, an open-source post-exploitation framework capable of remote shell access, file operations, proxying, credential theft, Active Directory attacks, and lateral movement.
The vulnerability used for initial access by filtering non-C2 requests and checking the service parameter against a regex pattern – if the path segments don’t match, the request is blocked with a 403 response (access denied).
The implant contacted 156.227.0[.]13 over HTTP and then remained dormant for approximately one day before operators returned for hands-on-keyboard activity.

Researchers found that the binary had been modified to redirect a C runtime call into the implant, while its malicious code used encrypted configuration, custom API hashing, PEB-field abuse for global storage, and control-flow flattening to complicate analysis.
The malware also depended on the legitimate signed msedge_elf.dll. Its absence prevented execution in public sandboxes, providing the attackers with a simple but effective analysis-evasion layer.
After discovering domain controllers through DNS SRV queries, the operators used AdaptixC2 to duplicate the token of a process running under a domain-privileged service account.
They relaunched the implant using that token and copied mscopilot.exe plus msedge_elf.dll to a domain controller over the C$ administrative share.

The actors then hijacked the built-in PlugPlay service by temporarily replacing its binary path with the implant, starting it remotely, and restoring the legitimate svchost.exe -k DcomLaunch -p path afterward.
On the domain controller, they enumerated active computers, Domain Admins membership, services, and trust relationships.
That setting enabled pass-the-hash RDP authentication using a recovered NTLM hash.
Inside the RDP session, the operators used ntdsutil.exe to create an installation-media-format backup of NTDS.dit, then used 7-Zip to archive the Active Directory database and related SYSTEM hive data for potential exfiltration.
Possession of this material would allow offline recovery of password hashes across the domain and fuel further pass-the-hash movement.
Organizations should immediately install PaperCut’s emergency patches for MF and NG, particularly on internet-facing application servers.
PaperCut states that the vulnerabilities affect versions before the relevant emergency fixes across its v24, v25, and v26 release branches, and recommends restricting external access to trusted IP addresses.
Defenders should review PaperCut server.log for suspicious hex-encoded Java content, unexpected .bin files, pcxboot_l.txt, filter-chain anomalies, and deletions involving cardID, XMLRPC, or UnsupportedClassVersionError.
Security teams should also investigate execution of mscopilot.exe from unusual paths, especially C:\microsoft.office365\, PlugPlay service configuration changes, Restricted Admin registry modifications, ntdsutil.exe IFM backups, and archive creation involving C:\nbak.
The incident underscores that print-management infrastructure must be treated as high-value enterprise software. Once attackers gained code execution on PaperCut, the objective was not the print server itself it was Active Directory.
Indicators of Compromise
| Type | Value | Description |
| URL | hxxps://taibeianmo.oss-cn-hongkong.aliyuncs[.]com/mscopilot.exe | Download URL for AdaptixC2 implant |
| URL | hxxps://uneedcargo.oss-accelerate.aliyuncs[.]com/65722.txt | Additional OSINT-discovered download URL for the same AdaptixC2 implant |
| IPv4 | 47.79.64[.]225 | Download IP for AdaptixC2 implant (ASN 45102 Alibaba (US) Technology Co., Ltd.) |
| IPv4 | 156.227.0[.]13 | AdaptixC2 C2 server IP |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC
Mayura Kathirhttps://gbhackers.com/
Mayura Kathir is a cybersecurity reporter at GBHackers News, covering daily incidents including data breaches, malware attacks, cybercrime, vulnerabilities, zero-day exploits, and more.