SOC Prime Bias: Critical

05 Oct 2026 16:32 UTC

CVE-2026-82078 and CVE-2026-81578 Exploited in PaperCut MF Zero-Day Attacks

Author Photo
SOC Prime Team linkedin icon Follow
CVE-2026-82078 and CVE-2026-81578 Exploited in PaperCut MF Zero-Day Attacks
shield icon

Detection stack

  • AIDR
  • Alert
  • ETL
  • Query

Summary

Threat actors exploited zero-day vulnerabilities in PaperCut MF to deploy an in-memory Java loader alongside a web shell. The intrusion enabled delivery of a trojanized Microsoft Copilot binary carrying the AdaptixC2 implant. Attackers then moved laterally to a domain controller and ultimately compromised the Active Directory environment by extracting the NTDS.dit database containing domain credential data.

Investigation

The eSentire Threat Response Unit identified exploitation of an internet-facing print server within the Education industry. Investigators observed SQL injection being used to deliver Java bytecode, detected suspicious process activity associated with pc-app.exe, and traced attacker movement from the initial web shell to domain-level credential harvesting through abuse of NTLM hashes.

Mitigation

Organizations should upgrade PaperCut MF/NG to the latest available versions to address CVE-2026-82078 and CVE-2026-81578. Access to PaperCut application servers should be limited to trusted IP addresses. Organizations should also enforce the principle of least privilege for service accounts to reduce the risk of token theft and lateral movement.

Response

When malicious activity is detected, isolate the affected host to prevent further compromise. Monitor PaperCut server logs for unusual errors associated with JDBC drivers and card lookups. Review domain controller logs for unauthorized RDP sessions involving NTLM hashes, suspicious service configuration changes, and other indicators of lateral movement.

Attack Flow

We are still updating this part.

Detections

Suspicious Restricted Admin Mode Enable (via registry_event)

SOC Prime Team
01 Oct 2026

Possible Service Creation with Binary on UNC Share (via cmdline)

SOC Prime Team
01 Oct 2026

Possible Services Enumeration (via cmdline)

SOC Prime Team
01 Oct 2026

Possible Account or Group Enumeration / Manipulation (via cmdline)

SOC Prime Team
01 Oct 2026

Suspicious Domain Trusts Discovery (via cmdline)

SOC Prime Team
01 Oct 2026

IOCs (HashSha256) to detect: PaperCut MF Zero-Day Intrusion: Java Loader, Web Shell, and AdaptixC2 via CVE-2026-82078 and CVE-2026-81578 Attacks/Breaches

SOC Prime AI Rules
01 Oct 2026

IOCs (SourceIP) to detect: PaperCut MF Zero-Day Intrusion: Java Loader, Web Shell, and AdaptixC2 via CVE-2026-82078 and CVE-2026-81578 Attacks/Breaches

SOC Prime AI Rules
01 Oct 2026

IOCs (DestinationIP) to detect: PaperCut MF Zero-Day Intrusion: Java Loader, Web Shell, and AdaptixC2 via CVE-2026-82078 and CVE-2026-81578 Attacks/Breaches

SOC Prime AI Rules
01 Oct 2026

AdaptixC2 Implant Detection on Domain Controllers [Windows File Event]

SOC Prime AI Rules
01 Oct 2026

AdaptixC2 Implant Deployment via PaperCut MF Exploitation [Windows Process Creation]

SOC Prime AI Rules
01 Oct 2026

Simulation Execution

  • Attack Narrative & Commands: The adversary has successfully exploited the PaperCut MF service. To ensure persistent access that survives a reboot, they aim to hijack the PlugPlay service. They first create a masqueraded directory C:microsoft.office365 to blend in with legitimate system paths. They then drop a malicious binary named mscopilot.exe (the AdaptixC2 implant) into this folder. Finally, they execute a command via the compromised pc-app.exe process to reconfigure the PlugPlay service to execute their implant instead of the legitimate driver.

  • Regression Test Script:

    # Simulation Script: AdaptixC2 Implant Deployment via PaperCut MF Exploitation
    # Note: This script requires Administrative privileges.
    
    # 1. Create the masqueraded directory
    $targetDir = "C:microsoft.office365"
    if (!(Test-Path $targetDir)) {
        New-Item -Path $targetDir -ItemType Directory | Out-Null
    }
    
    # 2. Create a dummy 'implant' file to simulate mscopilot.exe
    $implantPath = "$targetDirmscopilot.exe"
    "Simulated AdaptixC2 Implant" | Out-File -FilePath $implantPath
    
    # 3. Simulate the 'pc-app.exe' process executing the malicious sc config command
    # We use a dummy process name to match the detection logic's 'Image' requirement
    Start-Process "cmd.exe" -ArgumentList "/c sc config PlugPlay binpath= C:microsoft.office365mscopilot.exe" -WindowStyle Hidden
    
    # Note: To strictly match the 'pc-app.exe' requirement in the rule, 
    # in a real lab, one would rename a process to pc-app.exe. 
    # For this script, we assume the caller is simulating the context of pc-app.exe.
    Write-Host "[+] Simulation commands executed. Check SIEM for alerts."
  • Cleanup Commands:

    # Cleanup Script: Remove simulated implant and directory
    $targetDir = "C:microsoft.office365"
    if (Test-Path $targetDir) {
        Remove-Item -Path $targetDir -Recurse -Force
        Write-Host "[+] Cleanup complete: $targetDir removed."
    } else {
        Write-Host "[!] Target directory not found. Nothing to clean."
    }