PaperCut Zero-Days Used to Deploy AdaptixC2 and Compromise an Education Customer’s Domain

Summary
eSentire details an intrusion exploiting two PaperCut MF zero-days to deploy a web shell and AdaptixC2, move from an education customer’s print server to a domain controller, and extract Active Directory password hashes.
Key points
- Attackers exploited CVE-2026-82078 and CVE-2026-81578 on an internet-facing PaperCut MF 24.0.2 server.
- A Java loader deployed a web shell that downloaded and ran a trojanized Microsoft Copilot binary containing an AdaptixC2 implant.
- Attackers stole a token from a domain-privileged service account and moved laterally to a domain controller.
- They dumped credentials, enabled Restricted Admin mode, used pass-the-hash over RDP, and extracted the domain’s NTDS.dit database; exfiltration was not confirmed.
- The implant used control-flow obfuscation, encrypted configuration, API hashing, and a missing DLL dependency that prevented execution in public sandboxes.
- eSentire isolated the affected host and assisted with remediation; it recommends patching PaperCut, restricting server access, reviewing logs and indicators, and limiting account privileges.
Article Details
- Attack Vectors
- Threat actors exploited an internet-facing server running PaperCut MF 24.0.2 (Build 69746). The article attributes the intrusion to CVE-2026-82078 and CVE-2026-81578.
- SQL injection through PaperCut's card/ID lookup field delivered Java bytecode chunks and a loader. The loader assembled and loaded a second-stage web shell in memory.
- The web shell accepted commands through the X-Quad HTTP header and was used to download and execute a trojanized Microsoft Copilot binary carrying an AdaptixC2 implant.
- After duplicating a domain-privileged service account's process token, threat actors copied the implant to a domain controller and changed the PlugPlay service's binary path to execute it.
- Threat actors obtained an NTLM hash, enabled Windows Restricted Admin mode, authenticated to the domain controller over RDP using the hash, and copied the Active Directory database.
- Defensive Notes
- Update PaperCut MF/NG to the latest version and restrict access to PaperCut application servers to trusted IP addresses.
- Apply least privilege to service accounts, particularly accounts with domain privileges.
- Monitor PaperCut server logs for missing or deleted files and for the specific card-lookup and database errors identified in the article.
- Monitor PaperCut application-server activity, including post-exploitation behavior and child processes of pc-app.exe.
- eSentire reports that its analysts isolated the affected host and assisted the customer with remediation.
Indicators of compromise
| Type | Indicator | Context |
|---|---|---|
| IPV4 | 156[.]227[.]0[.]13 | AdaptixC2 command-and-control server IP observed in the implant. |
| IPV4 | 47[.]79[.]64[.]225 | IP address used to download the trojanized binary carrying the AdaptixC2 implant. |
| SHA256 | 1a7541b30dcccd91e969f0e1586ba18fbf3a7d78f960654a5c1489108e516180 | Decompiled second-stage web shell artifact, javax variant. |
| SHA256 | 33d0a8294d2520608dbc4901c3ebd525aaeb7b8eceba9d140f62efa419a8c55a | Java bytecode first-stage loader, javax variant. |
| SHA256 | 8673371d266d041dae20f64e0532d2bca65c3b09a6c0faf16a6546e6067bac2e | Decompiled second-stage web shell artifact, jakarta variant. |
| SHA256 | 9c8760f8b973360701774bc56c7c97295eb42d49a02a281cbaadc32c973bd8b2 | Java bytecode second-stage web shell, jakarta variant. |
| SHA256 | a8ff38e5f21a5202e1ce33e62b9ddde4ec4faffabd52a4a146cff18c877fe7ca | Decompiled first-stage loader artifact, jakarta variant. |
| SHA256 | bc5fd75b307c2a11a602fbedb8275e0836ddf81cdd43af00a6bf0d850ff6cf58 | Java bytecode first-stage loader, jakarta variant. |
| SHA256 | cf6dd15baf5ef66432a95b5a2ec64ba5c6de565b3fb9e10ae01b1a91612a1c2c | Trojanized wa_3rd_party_host_64.exe, named PulseSecure.exe, carrying an AdaptixC2 implant. |
| SHA256 | d2e55213a02fd16a077298c986130522eb63196bdf8a8c1aec0eed6ef318b222 | Trojanized Microsoft Copilot binary carrying an AdaptixC2 implant. |
| SHA256 | d91c10536293d23bd3ebfc0f922e367303f455571556d83684170183dd6897f4 | Java bytecode second-stage web shell, javax variant. |
| SHA256 | f893ab902cf0ad1a62cdfe04c58ba7560db7a0f5153303af18bd549c6619a044 | Decompiled first-stage loader artifact, javax variant. |
| URL | hxxps[:]//taibeianmo[.]oss-cn-hongkong[.]aliyuncs[.]com/mscopilot[.]exe | Specific download URL listed for the AdaptixC2 implant. |
| URL | hxxps[:]//uneedcargo[.]oss-accelerate[.]aliyuncs[.]com/65722[.]txt | Additional OSINT-discovered download URL listed for the same AdaptixC2 implant. |
MITRE ATT&CK
T1003.001 · LSASS MemoryThreat actors attempted to dump LSASS process memory during credential harvesting.T1003.002 · Security Account ManagerThreat actors saved a copy of the SAM registry hive during credential harvesting.T1003.003 · NTDSThreat actors used ntdsutil.exe to copy the domain's NTDS.dit database, which contains account password hashes.T1018 · Remote System DiscoveryThreat actors used DNS SRV lookups to locate domain controllers as lateral-movement targets.T1021.001 · Remote Desktop ProtocolThreat actors accessed the domain controller through an RDP session.T1021.002 · SMB/Windows Admin SharesThreat actors copied the implant and its dependency to a domain controller over a C$ administrative share.T1027 · Obfuscated Files or InformationThe AdaptixC2 implant used control-flow flattening, API hashing, and XOR-encrypted configuration values.T1059.007 · JavaScriptThe web shell could evaluate JavaScript in memory; threat actors used that capability to download and execute the AdaptixC2 implant.T1070.004 · File DeletionThe loader and web shell deleted payload chunks and loader files after loading, and the web shell removed exploit-related lines from server.log.T1071.001 · Web ProtocolsThe AdaptixC2 implant used HTTP for command-and-control check-ins and encrypted communications.T1105 · Ingress Tool TransferThreat actors downloaded the trojanized Microsoft Copilot binary carrying AdaptixC2 onto the compromised server.T1134.001 · Token Impersonation/TheftThreat actors duplicated the token of a process running under a domain-privileged service account.T1134.002 · Create Process with TokenThreat actors used the duplicated service-account token to respawn the implant via CreateProcessAsUser.T1190 · Exploit Public-Facing ApplicationThreat actors exploited vulnerabilities in an internet-facing PaperCut MF server for initial access.T1482 · Domain Trust DiscoveryThreat actors ran nltest /domain_trusts /all_trusts to enumerate domain trusts.T1505.003 · Web ShellA second-stage Java web shell injected itself into the server's Jetty servlet filter chain and accepted HTTP-header commands.T1543.003 · Windows ServiceThreat actors changed the domain controller's PlugPlay service binary path to run the AdaptixC2 implant, then restored the original path.T1550.002 · Pass the HashThreat actors used a recovered NTLM hash and Windows Restricted Admin mode to authenticate over RDP.T1560.001 · Archive via UtilityThreat actors used 7-Zip to archive the copied Active Directory database and accompanying backup output for exfiltration.
CVE
CVE-2026-81578disclosed in our security advisory, PaperCut Discloses Zero-Day Vulnerabilities (CVE-2026-82078 and CVE-2026-81578), published on September 3, 2026 affecting a customer in the Education industry. In the intrusion,CVE-2026-82078vulnerabilities disclosed in our security advisory, PaperCut Discloses Zero-Day Vulnerabilities (CVE-2026-82078 and CVE-2026-81578), published on September 3, 2026 affecting a customer in the Education industry.
Malware
Vendors
Microsoftin turn deployed a web shell. Threat actors subsequently used the web shell to deploy a trojanized Microsoft Copilot binary carrying an AdaptixC2 implant.PaperCutUnit (TRU) detected exploitation of zero-day vulnerabilities disclosed in our security advisory, PaperCut Discloses Zero-Day Vulnerabilities (CVE-2026-82078 and CVE-2026-81578), published on September 3, 2026
Products
Microsoft Copilotin turn deployed a web shell. Threat actors subsequently used the web shell to deploy a trojanized Microsoft Copilot binary carrying an AdaptixC2 implant.PaperCut MFthe intrusion, threat actors exploited an internet-facing print server running a vulnerable version of PaperCut MF to load an in-memory Java loader, which in turn deployed a web shell. Threat actors subsequently usedPaperCut NGRestrict access to PaperCut NG/MF Application Servers to trusted IP addresses only.
Tools
7-ZipThreat actors then used the AdaptixC2 implant to drop 7-Zip to create an archive of the NTDS.dit database and the rest of the C:\nbak IFM output, including the required SYSTEM registry hive, into a single archive forAdaptixC2actors subsequently used the web shell to deploy a trojanized Microsoft Copilot binary carrying an AdaptixC2 implant.Binary Ninjaand the trojanized copy when reviewed in Binary Ninja's sidebar graph. There is a clear size difference between the images, suggesting the PE image shrunkCyberChefFigure 29 - Embedded RC4 key written byte-by-byte to allocated buffer and stored in global contextThe figure below displays the decrypted contents of the registration packet when decrypted using CyberChef.DispatchThisdiscussed in previous parts of this blog to a frontier LLM, we were able to easily extend our DispatchThis sample plugin for Binary Ninja to handle this particular shape. The plugin computes the stateExtension-KitThe figure below displays the Creds-BOF tools that were likely used in this process from AdaptixC2's Extension-Kit: hashdump, nanodump*, and lsadump*.ntdsutil.exeInside the RDP session, threat actors opened a command prompt and ran ntdsutil.exe to create a backup of the Active Directory database, writing a copy of NTDS.dit to C:\nbak\Active Directory\ntds.dit.sc.exeshare, then executed it by hijacking the built-in PlugPlay service's binary path through a series of sc.exe commands.