CVE-2026-82078 and CVE-2026-81578 Exploited in PaperCut MF Zero-Day Attacks
Detection stack
- AIDR
- Alert
- ETL
- Query
Summary
Threat actors exploited zero-day vulnerabilities in PaperCut MF to deploy an in-memory Java loader alongside a web shell. The intrusion enabled delivery of a trojanized Microsoft Copilot binary carrying the AdaptixC2 implant. Attackers then moved laterally to a domain controller and ultimately compromised the Active Directory environment by extracting the NTDS.dit database containing domain credential data.
Investigation
The eSentire Threat Response Unit identified exploitation of an internet-facing print server within the Education industry. Investigators observed SQL injection being used to deliver Java bytecode, detected suspicious process activity associated with pc-app.exe, and traced attacker movement from the initial web shell to domain-level credential harvesting through abuse of NTLM hashes.
Mitigation
Organizations should upgrade PaperCut MF/NG to the latest available versions to address CVE-2026-82078 and CVE-2026-81578. Access to PaperCut application servers should be limited to trusted IP addresses. Organizations should also enforce the principle of least privilege for service accounts to reduce the risk of token theft and lateral movement.
Response
When malicious activity is detected, isolate the affected host to prevent further compromise. Monitor PaperCut server logs for unusual errors associated with JDBC drivers and card lookups. Review domain controller logs for unauthorized RDP sessions involving NTLM hashes, suspicious service configuration changes, and other indicators of lateral movement.
Attack Flow
We are still updating this part.
Detections
Suspicious Restricted Admin Mode Enable (via registry_event)
Possible Service Creation with Binary on UNC Share (via cmdline)
Possible Services Enumeration (via cmdline)
Possible Account or Group Enumeration / Manipulation (via cmdline)
Suspicious Domain Trusts Discovery (via cmdline)
IOCs (HashSha256) to detect: PaperCut MF Zero-Day Intrusion: Java Loader, Web Shell, and AdaptixC2 via CVE-2026-82078 and CVE-2026-81578 Attacks/Breaches
IOCs (SourceIP) to detect: PaperCut MF Zero-Day Intrusion: Java Loader, Web Shell, and AdaptixC2 via CVE-2026-82078 and CVE-2026-81578 Attacks/Breaches
IOCs (DestinationIP) to detect: PaperCut MF Zero-Day Intrusion: Java Loader, Web Shell, and AdaptixC2 via CVE-2026-82078 and CVE-2026-81578 Attacks/Breaches
AdaptixC2 Implant Detection on Domain Controllers [Windows File Event]
AdaptixC2 Implant Deployment via PaperCut MF Exploitation [Windows Process Creation]
Simulation Execution
-
Attack Narrative & Commands: The adversary has successfully exploited the PaperCut MF service. To ensure persistent access that survives a reboot, they aim to hijack the
PlugPlayservice. They first create a masqueraded directoryC:microsoft.office365to blend in with legitimate system paths. They then drop a malicious binary namedmscopilot.exe(the AdaptixC2 implant) into this folder. Finally, they execute a command via the compromisedpc-app.exeprocess to reconfigure thePlugPlayservice to execute their implant instead of the legitimate driver. -
Regression Test Script:
# Simulation Script: AdaptixC2 Implant Deployment via PaperCut MF Exploitation # Note: This script requires Administrative privileges. # 1. Create the masqueraded directory $targetDir = "C:microsoft.office365" if (!(Test-Path $targetDir)) { New-Item -Path $targetDir -ItemType Directory | Out-Null } # 2. Create a dummy 'implant' file to simulate mscopilot.exe $implantPath = "$targetDirmscopilot.exe" "Simulated AdaptixC2 Implant" | Out-File -FilePath $implantPath # 3. Simulate the 'pc-app.exe' process executing the malicious sc config command # We use a dummy process name to match the detection logic's 'Image' requirement Start-Process "cmd.exe" -ArgumentList "/c sc config PlugPlay binpath= C:microsoft.office365mscopilot.exe" -WindowStyle Hidden # Note: To strictly match the 'pc-app.exe' requirement in the rule, # in a real lab, one would rename a process to pc-app.exe. # For this script, we assume the caller is simulating the context of pc-app.exe. Write-Host "[+] Simulation commands executed. Check SIEM for alerts." -
Cleanup Commands:
# Cleanup Script: Remove simulated implant and directory $targetDir = "C:microsoft.office365" if (Test-Path $targetDir) { Remove-Item -Path $targetDir -Recurse -Force Write-Host "[+] Cleanup complete: $targetDir removed." } else { Write-Host "[!] Target directory not found. Nothing to clean." }