PaperCut Zero-Days Used to Deploy AdaptixC2 and Compromise an Education Customer’s Domain

· Original article ↗

Summary

eSentire details an intrusion exploiting two PaperCut MF zero-days to deploy a web shell and AdaptixC2, move from an education customer’s print server to a domain controller, and extract Active Directory password hashes.

Key points

  • Attackers exploited CVE-2026-82078 and CVE-2026-81578 on an internet-facing PaperCut MF 24.0.2 server.
  • A Java loader deployed a web shell that downloaded and ran a trojanized Microsoft Copilot binary containing an AdaptixC2 implant.
  • Attackers stole a token from a domain-privileged service account and moved laterally to a domain controller.
  • They dumped credentials, enabled Restricted Admin mode, used pass-the-hash over RDP, and extracted the domain’s NTDS.dit database; exfiltration was not confirmed.
  • The implant used control-flow obfuscation, encrypted configuration, API hashing, and a missing DLL dependency that prevented execution in public sandboxes.
  • eSentire isolated the affected host and assisted with remediation; it recommends patching PaperCut, restricting server access, reviewing logs and indicators, and limiting account privileges.

Article Details

Attack Vectors
  • Threat actors exploited an internet-facing server running PaperCut MF 24.0.2 (Build 69746). The article attributes the intrusion to CVE-2026-82078 and CVE-2026-81578.
  • SQL injection through PaperCut's card/ID lookup field delivered Java bytecode chunks and a loader. The loader assembled and loaded a second-stage web shell in memory.
  • The web shell accepted commands through the X-Quad HTTP header and was used to download and execute a trojanized Microsoft Copilot binary carrying an AdaptixC2 implant.
  • After duplicating a domain-privileged service account's process token, threat actors copied the implant to a domain controller and changed the PlugPlay service's binary path to execute it.
  • Threat actors obtained an NTLM hash, enabled Windows Restricted Admin mode, authenticated to the domain controller over RDP using the hash, and copied the Active Directory database.
Defensive Notes
  • Update PaperCut MF/NG to the latest version and restrict access to PaperCut application servers to trusted IP addresses.
  • Apply least privilege to service accounts, particularly accounts with domain privileges.
  • Monitor PaperCut server logs for missing or deleted files and for the specific card-lookup and database errors identified in the article.
  • Monitor PaperCut application-server activity, including post-exploitation behavior and child processes of pc-app.exe.
  • eSentire reports that its analysts isolated the affected host and assisted the customer with remediation.

Indicators of compromise

TypeIndicatorContext
IPV4156[.]227[.]0[.]13AdaptixC2 command-and-control server IP observed in the implant.
IPV447[.]79[.]64[.]225IP address used to download the trojanized binary carrying the AdaptixC2 implant.
SHA2561a7541b30dcccd91e969f0e1586ba18fbf3a7d78f960654a5c1489108e516180Decompiled second-stage web shell artifact, javax variant.
SHA25633d0a8294d2520608dbc4901c3ebd525aaeb7b8eceba9d140f62efa419a8c55aJava bytecode first-stage loader, javax variant.
SHA2568673371d266d041dae20f64e0532d2bca65c3b09a6c0faf16a6546e6067bac2eDecompiled second-stage web shell artifact, jakarta variant.
SHA2569c8760f8b973360701774bc56c7c97295eb42d49a02a281cbaadc32c973bd8b2Java bytecode second-stage web shell, jakarta variant.
SHA256a8ff38e5f21a5202e1ce33e62b9ddde4ec4faffabd52a4a146cff18c877fe7caDecompiled first-stage loader artifact, jakarta variant.
SHA256bc5fd75b307c2a11a602fbedb8275e0836ddf81cdd43af00a6bf0d850ff6cf58Java bytecode first-stage loader, jakarta variant.
SHA256cf6dd15baf5ef66432a95b5a2ec64ba5c6de565b3fb9e10ae01b1a91612a1c2cTrojanized wa_3rd_party_host_64.exe, named PulseSecure.exe, carrying an AdaptixC2 implant.
SHA256d2e55213a02fd16a077298c986130522eb63196bdf8a8c1aec0eed6ef318b222Trojanized Microsoft Copilot binary carrying an AdaptixC2 implant.
SHA256d91c10536293d23bd3ebfc0f922e367303f455571556d83684170183dd6897f4Java bytecode second-stage web shell, javax variant.
SHA256f893ab902cf0ad1a62cdfe04c58ba7560db7a0f5153303af18bd549c6619a044Decompiled first-stage loader artifact, javax variant.
URLhxxps[:]//taibeianmo[.]oss-cn-hongkong[.]aliyuncs[.]com/mscopilot[.]exeSpecific download URL listed for the AdaptixC2 implant.
URLhxxps[:]//uneedcargo[.]oss-accelerate[.]aliyuncs[.]com/65722[.]txtAdditional OSINT-discovered download URL listed for the same AdaptixC2 implant.

MITRE ATT&CK

T1003.001 · LSASS MemoryThreat actors attempted to dump LSASS process memory during credential harvesting.T1003.002 · Security Account ManagerThreat actors saved a copy of the SAM registry hive during credential harvesting.T1003.003 · NTDSThreat actors used ntdsutil.exe to copy the domain's NTDS.dit database, which contains account password hashes.T1018 · Remote System DiscoveryThreat actors used DNS SRV lookups to locate domain controllers as lateral-movement targets.T1021.001 · Remote Desktop ProtocolThreat actors accessed the domain controller through an RDP session.T1021.002 · SMB/Windows Admin SharesThreat actors copied the implant and its dependency to a domain controller over a C$ administrative share.T1027 · Obfuscated Files or InformationThe AdaptixC2 implant used control-flow flattening, API hashing, and XOR-encrypted configuration values.T1059.007 · JavaScriptThe web shell could evaluate JavaScript in memory; threat actors used that capability to download and execute the AdaptixC2 implant.T1070.004 · File DeletionThe loader and web shell deleted payload chunks and loader files after loading, and the web shell removed exploit-related lines from server.log.T1071.001 · Web ProtocolsThe AdaptixC2 implant used HTTP for command-and-control check-ins and encrypted communications.T1105 · Ingress Tool TransferThreat actors downloaded the trojanized Microsoft Copilot binary carrying AdaptixC2 onto the compromised server.T1134.001 · Token Impersonation/TheftThreat actors duplicated the token of a process running under a domain-privileged service account.T1134.002 · Create Process with TokenThreat actors used the duplicated service-account token to respawn the implant via CreateProcessAsUser.T1190 · Exploit Public-Facing ApplicationThreat actors exploited vulnerabilities in an internet-facing PaperCut MF server for initial access.T1482 · Domain Trust DiscoveryThreat actors ran nltest /domain_trusts /all_trusts to enumerate domain trusts.T1505.003 · Web ShellA second-stage Java web shell injected itself into the server's Jetty servlet filter chain and accepted HTTP-header commands.T1543.003 · Windows ServiceThreat actors changed the domain controller's PlugPlay service binary path to run the AdaptixC2 implant, then restored the original path.T1550.002 · Pass the HashThreat actors used a recovered NTLM hash and Windows Restricted Admin mode to authenticate over RDP.T1560.001 · Archive via UtilityThreat actors used 7-Zip to archive the copied Active Directory database and accompanying backup output for exfiltration.

CVE

Malware

Vendors

Products

Tools

Industries

Related Articles