Top Highlights
- Threat actors are exploiting recent PaperCut vulnerabilities (CVE-2026-81578 and CVE-2026-82078) for credential theft, remote code execution, and privilege escalation, targeting educational institutions across the U.S. and Europe.
- Attackers perform reconnaissance and post-exploitation activities such as system discovery commands (“whoami,” “tasklist”), credential harvesting with tools like “lsa_collect.exe,” and deploying Meterpreter payloads for remote access.
- Malicious activities include exfiltrating sensitive data via web requests, creating privileged accounts, and leveraging stolen login credentials to access critical systems, emphasizing the need for network restrictions and vigilant monitoring.
Threat, Attack Techniques, and Targets
Threat actors are exploiting recent vulnerabilities in PaperCut software, specifically CVE-2026-81578 and CVE-2026-82078. These flaws allow attackers to bypass user authentication and run remote code on affected systems. Once inside, they perform activities like command execution, system reconnaissance, and creating privileged user accounts.
The attackers use several methods to achieve these goals. They run commands such as uname, whoami, ver, and tasklist to gather system information. They also create new administrator accounts. The actors send GET requests to compromised servers to access files containing sensitive data. They deliver tools like lsa_collect.exe, save_hives.exe, and Java payloads to harvest credentials and establish control over the system.
The main targets are educational institutions, including K-12 schools and universities in the U.S. and Europe. These organizations use PaperCut, a print management system vulnerable to these exploits.
Impact, Security Implications, and Remediation Guidance
The exploitation of PaperCut flaws can lead to serious consequences. Attackers can steal user credentials and gain access to critical systems. They may also collect system information, create privileged accounts, and deploy malicious tools like Meterpreter. In the long term, this could allow attackers to move through the network and access sensitive data.
The security implications are significant because the stolen login details could be used to compromise other systems. The attackers also deploy malware that extracts registry keys and system credentials, making recovery more difficult.
For mitigation, organizations should limit PaperCut servers from being accessible over the internet. They should monitor their systems closely for commands like cmd.exe or powershell.exe, especially if these are run from unrelated parent processes. It is important to watch for commands such as whoami, tasklist, ver, or uname.
As for remediation, organizations should seek guidance from the PaperCut vendor or cybersecurity authorities. The detailed steps for fixing these vulnerabilities are not provided here and must be obtained from official sources.
Stay Ahead with the Latest Tech Trends
Learn how the Internet of Things (IoT) is transforming everyday life.
Discover archived knowledge and digital history on the Internet Archive.
ThreatIntel-V1
