Zero-Day PaperCut Flaws Lead to Domain Controller Compromise
Attackers exploited two chained zero-day vulnerabilities in PaperCut MF to gain initial access, moving from a print server to a domain controller in under two days to steal credentials and exfiltrate sensitive data.

A critical Active Directory compromise was initiated through the exploitation of two chained zero-day vulnerabilities in PaperCut MF, demonstrating how an overlooked business system can serve as a gateway to an organization's most sensitive identity infrastructure. The attackers specifically targeted an internet-facing PaperCut MF server running version 24.0.2, build 69746. They leveraged the card or ID lookup field to deliver malicious Java code, subsequently installing an in-memory loader and a web shell. This initial foothold was then used to deploy an AdaptixC2 implant, cleverly disguised within a modified Microsoft Copilot binary.
Researchers at eSentire detected the intrusion on August 31, 2026, at a customer in the education sector. Their analysis revealed a rapid lateral movement, with attackers progressing from the compromised print server to a domain controller in less than two days. This incident underscores the significant risks associated with exposing management applications, such as print servers, to the public internet. The exploitation of these PaperCut flaws had been previously reported, with defenders urged to restrict public access and monitor for suspicious activities.
The attack chain relied on CVE-2026-81578 and CVE-2026-82078, a pair of vulnerabilities that, when chained, allow attackers to alter server settings without authentication and execute malicious Java bytecode within the PaperCut server's security context. The first-stage loader was engineered for broad compatibility across various Tomcat releases, meticulously rebuilding payload fragments in memory, initiating the subsequent stage, and then erasing its own files to minimize forensic traces. The web shell component was designed to accept commands via a custom HTTP header, execute arbitrary commands, retrieve configuration details, and systematically delete evidence from logs and the internal application database.
This meticulous cleanup was crucial for the attackers' stealth. The web shell positioned itself early in the server's request-processing pipeline, effectively blocking unrelated attempts to exploit the same vulnerability and thus preserving their exclusive control over the compromised system. After establishing contact with remote attacker infrastructure, the modified binary remained dormant for approximately a day, allowing attackers to plan their next moves. This period of inactivity highlights a common tactic where threat actors use open-source command-and-control frameworks to expand their access after an initial breach.
Once the attackers became active, they began a thorough reconnaissance of the network, identifying hosts, network segments, domain trusts, and administrator groups. They discovered a process running under a domain-privileged service account, from which they copied the access token. This allowed them to relaunch the implant with elevated domain privileges, bypassing the need to steal administrator passwords. Using these acquired privileges, the threat group transferred their payload to the domain controller via an administrative file share.
To achieve execution on the domain controller, the attackers temporarily modified the Windows PlugPlay service configuration to launch their payload, subsequently stopping the service and restoring the legitimate service path. This sophisticated technique allowed for code execution while significantly reducing the digital footprint of their actions. On the domain controller, the attackers proceeded to dump credentials from memory and the registry. They then enabled Windows Restricted Admin mode, utilized a recovered NTLM hash to establish a Remote Desktop Protocol connection, and crucially, created a copy of the Active Directory database.
The exfiltrated Active Directory database copy poses a severe risk, as it can contain password hashes for every domain account, enabling further pass-the-hash attacks and widespread compromise. The attackers packaged this database along with supporting registry data into an archive for exfiltration. Their custom implant incorporated encrypted settings and obfuscated program logic to hinder analysis, and it was designed to evade detection in public sandboxes by requiring its legitimate supporting library to be present.
Security professionals are strongly advised to update PaperCut MF or NG to the latest version and restrict public access to its application servers, allowing connections only from trusted IP addresses. Continuous monitoring of child processes associated with the PaperCut service, detection of missing or unexpectedly truncated server logs, and vigilance for unusual post-exploitation activities are critical. Reviewing vendor advisories for indicators of compromise, investigating log errors, and scrutinizing unexpected changes to service configurations are essential steps in mitigating the risks posed by such sophisticated attacks. Furthermore, reducing service account permissions and maintaining robust endpoint monitoring are recommended practices.