Hackers Turned a PaperCut Print Server Into a Path to the Domain Controller

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com


A vulnerable print server became the entry point for an Active Directory compromise after attackers exploited two PaperCut MF zero-day flaws.

The intrusion shows how an overlooked business system can give criminals access to sensitive identity infrastructure. The attackers targeted an internet-facing PaperCut MF server running version 24.0.2, build 69746.

They delivered Java code through the card or ID lookup field, installed an in-memory loader and web shell, used that foothold to deploy an AdaptixC2 implant hidden inside a modified Microsoft Copilot binary.

eSentire said in a report shared with Cyber Security News (CSN) that its analysts detected the intrusion on August 31, 2026, at an education-sector customer. Its analysts found that the attackers moved from the print server to a domain controller in less than two days.

The case underlines the danger of leaving management applications exposed online. It follows reports that the PaperCut flaws were actively exploited, with defenders warned to restrict public access and watch for suspicious activity from the service.

Hackers Turned a PaperCut Print Server

The initial compromise relied on CVE-2026-81578 and CVE-2026-82078, a pair of vulnerabilities that can be chained to alter settings without authentication and run malicious Java bytecode in the PaperCut server’s security context.

Earlier coverage of the actively exploited PaperCut flaws explains why internet-facing application servers need urgent attention. The first-stage loader was designed for broad compatibility across different Tomcat releases.

It rebuilt payload fragments in memory, started the next stage, and removed its own files. The web shell then accepted instructions through a custom HTTP header, ran commands, read configuration values, and deleted traces from logs and the internal application database.

Attack chain overview (Source – eSentire)

That cleanup mattered. The web shell also placed itself early in the server’s request-processing chain and blocked unrelated attempts to use the same weakness. In effect, the attackers tried to preserve exclusive control while making the original break-in harder to investigate.

The modified binary established contact with remote attacker infrastructure, then remained quiet for roughly a day. Operators then returned for hands-on activity, illustrating how attackers use open-source command-and-control attack frameworks to expand access after breaching a vulnerable server.

Credential Theft

Once active, the attackers surveyed hosts, networks, domain trusts, and administrator groups. They identified a process running under a domain-privileged service account, copied its access token, and relaunched the implant with that account’s rights.

No stolen administrator password was needed to begin the move toward the domain controller. Using those privileges, the group copied its payload to the domain controller through an administrative file share.

It then temporarily changed the Windows PlugPlay service configuration to start the payload, stopped the service after launch, and restored the legitimate service path.

That sequence allowed execution while reducing evidence of the change. On the domain controller, the attackers dumped credentials from memory and the registry.

They enabled Windows Restricted Admin mode, used a recovered NTLM hash to sign in over Remote Desktop Protocol, and created a copy of the Active Directory database.

That database can contain password hashes for every domain account, creating a serious risk of further pass-the-hash movement. The attackers packaged the database and supporting registry data into an archive for exfiltration.

Their customized implant used encrypted settings and scrambled program logic to hinder analysis. Public sandboxes also failed to run the modified binary when its legitimate supporting library was missing.

Administrators should update PaperCut MF or NG to the latest release and allow only trusted IP addresses to reach its application servers.

They should monitor child processes of the PaperCut service, missing or unexpectedly shortened server logs, and unusual post-exploitation behavior. Recent reporting on emergency PaperCut security updates also highlights the need to apply vendor fixes without delay.

Security teams should review the vendor advisory’s indicators, look for the log errors identified by the researchers, and investigate unexpected changes to service configurations.

Researchers also recommend reducing service-account permissions and maintaining endpoint monitoring. eSentire isolated the affected host and helped the customer with remediation following the intrusion.

Indicators of Compromise (IoCs):-

Type Indicator Description
URL hxxps://taibeianmo.oss-cn-hongkong.aliyuncs[.]com/mscopilot.exe Download URL for AdaptixC2 implant
URL hxxps://uneedcargo.oss-accelerate.aliyuncs[.]com/65722.txt Additional OSINT-discovered download URL for the same AdaptixC2 implant
IPv4 47.79.64[.]225 Download IP for AdaptixC2 implant
IPv4 156.227.0[.]13 AdaptixC2 command-and-control server IP
File hash d2e55213a02fd16a077298c986130522eb63196bdf8a8c1aec0eed6ef318b222 Trojanized Microsoft Copilot with AdaptixC2 implant
File hash cf6dd15baf5ef66432a95b5a2ec64ba5c6de565b3fb9e10ae01b1a91612a1c2c Trojanized wa_3rd_party_host_64.exe, named PulseSecure.exe, with AdaptixC2 implant
File hash bc5fd75b307c2a11a602fbedb8275e0836ddf81cdd43af00a6bf0d850ff6cf58 Java bytecode stage 1 loader, jakarta variant
File hash 33d0a8294d2520608dbc4901c3ebd525aaeb7b8eceba9d140f62efa419a8c55a Java bytecode stage 1 loader, javax variant
File hash a8ff38e5f21a5202e1ce33e62b9ddde4ec4faffabd52a4a146cff18c877fe7ca Decompiled stage 1 loader, jakarta variant
File hash f893ab902cf0ad1a62cdfe04c58ba7560db7a0f5153303af18bd549c6619a044 Decompiled stage 1 loader, javax variant
File hash 9c8760f8b973360701774bc56c7c97295eb42d49a02a281cbaadc32c973bd8b2 Java bytecode stage 2 shell, jakarta variant
File hash d91c10536293d23bd3ebfc0f922e367303f455571556d83684170183dd6897f4 Java bytecode stage 2 shell, javax variant
File hash 8673371d266d041dae20f64e0532d2bca65c3b09a6c0faf16a6546e6067bac2e Decompiled stage 2 shell, jakarta variant
File hash 1a7541b30dcccd91e969f0e1586ba18fbf3a7d78f960654a5c1489108e516180 Decompiled stage 2 shell, javax variant

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC

The post Hackers Turned a PaperCut Print Server Into a Path to the Domain Controller appeared first on Cyber Security News.