Attackers exploited the actively exploited PaperCut MF zero days CVE-2026-81578 and CVE-2026-82078 on an internet-facing PaperCut MF 24.0.2 Build 69746 server at an education-sector organization. Malicious Java code delivered through the card or ID lookup function installed an in-memory loader and memory-resident web shell, which accepted commands through the X-Quad HTTP header and removed forensic artifacts. The attackers then deployed an AdaptixC2 implant concealed in a trojanized Microsoft Copilot executable.
Using a duplicated token for a domain-privileged service account, the operators pivoted to the domain controller, hijacked the PlugPlay service for execution, dumped credentials, enabled Restricted Admin mode, and used pass-the-hash RDP. They created and archived an NTDS.dit backup with the SYSTEM hive, obtaining material capable of compromising all Active Directory accounts in the domain. eSentire isolated the affected host and urged organizations to patch PaperCut MF/NG immediately, limit PaperCut application-server access to trusted IPs, apply least privilege to service accounts, and investigate suspicious pc-app.exe child processes, PaperCut log manipulation, and service-configuration changes.

See which actors are running it and whether you're in range.
3 events from the most recent confirmed update back to the earliest known activity.
eSentire published its advisory covering the exploited PaperCut MF vulnerabilities CVE-2026-82078 and CVE-2026-81578.
eSentire's Threat Response Unit detected the intrusion at an education-sector customer and isolated the affected host, assisting the organization with remediation.
Attackers exploited CVE-2026-81578 and CVE-2026-82078 on an internet-facing PaperCut MF 24.0.2 Build 69746 server, delivering Java loaders and an in-memory web shell. They installed a trojanized Microsoft Copilot executable carrying AdaptixC2, escalated using a domain-privileged service account, moved to a domain controller, and created an archive containing NTDS.dit and the SYSTEM hive for exfiltration.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 16 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
2 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourceesentire.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.