Affected Systems
PaperCut NG and MF, all versions. Active targeting of K-12 schools and universities in the U.S. and Europe with internet-exposed PaperCut servers.
Exploitation Status
Active exploitation confirmed by Arctic Wolf. Attackers using CVE-2026-81578 (authentication bypass) and CVE-2026-82078 (remote code execution) in chain to deploy credential theft tools, Meterpreter payloads, and create privileged accounts. Command-and-control infrastructure identified at 45.142.193[.]132 and 194.180.48[.]134.
Business Impact
Attackers are harvesting Windows registry hives (SAM database access via BootKey extraction), LDAP credentials, and PaperCut configuration secrets. Credential theft enables lateral movement to other critical systems. Education sector heavily targeted. Post-compromise includes privileged account creation (e.g., "Administrator17") and deployment of Metasploit/Meterpreter for persistent access.
Urgency
đź”´ Immediate
Recommended Actions
- Immediately remove PaperCut NG and MF servers from internet exposure; place behind VPN or restrict access to trusted IP ranges
- Apply vendor patches for CVE-2026-81578 and CVE-2026-82078 as soon as available; monitor PaperCut security advisories
- Hunt for IOCs: check for connections to 45.142.193[.]132 and 194.180.48[.]134, search for lsa_collect.exe, lsa_collect_small.exe, save_hives.exe, and GET requests to /custom/pcp_*.txt paths
- Monitor for cmd.exe or powershell.exe spawned by pc-app.exe parent process; alert on discovery commands (whoami, tasklist, ver, uname) and certutil.exe downloading executables
- Audit privileged accounts for unauthorized creation (e.g., Administrator17 pattern); reset credentials for PaperCut service accounts and any LDAP bind accounts stored in PaperCut config files
---
# Threat Actor Context
Actor Profile
The threat actor behind this campaign remains unattributed. The activity was discovered and reported by the Arctic Wolf Adversary Research Team. Motivation appears to be credential theft targeting educational institutions, with post-exploitation activity suggesting objectives include establishing persistent access, harvesting credentials from Windows systems, and potentially enabling lateral movement across victim networks. The actor demonstrates familiarity with Windows credential extraction techniques and uses commodity tooling including Metasploit/Meterpreter payloads.
TTPs (Tactics, Techniques, Procedures)
Initial access achieved via exploitation of CVE-2026-81578 (authentication bypass) and CVE-2026-82078 (remote code execution) in PaperCut servers. Post-exploitation TTPs include: system and user discovery commands (T1082, T1033 - whoami, ver, uname, tasklist); privileged account creation (T1136 - "Administrator17" account); credential dumping via registry hive collection tools (T1003.002 - lsa_collect.exe, save_hives.exe targeting SAM database and BootKey extraction); ingress tool transfer via certutil.exe (T1105) from attacker infrastructure; command and scripting interpreter abuse (T1059 - cmd.exe, powershell.exe); deployment of Meterpreter Java payloads for C2 (T1071); and credential harvesting from configuration files using findstr to search for "password," "secret," "ldap," "bind," and "token" (T1552.001).
Targets & Patterns
The campaign exclusively targets the education sector, impacting K-12 schools and major universities across the United States and Europe. Target selection appears opportunistic, focusing on organizations running vulnerable internet-exposed PaperCut NG and MF print management servers. Educational institutions are attractive targets due to typically large user bases, often weaker security postures compared to enterprise environments, valuable research data, and extensive network connectivity that enables lateral movement. The credential theft focus suggests attackers aim to establish long-term access to educational networks for potential data exfiltration, ransomware deployment, or use as pivot points into connected research or government networks.
Historical Context
This represents active exploitation of newly disclosed PaperCut vulnerabilities (CVE-2026-81578 and CVE-2026-82078) in September 2026. PaperCut has been a target in previous campaigns, with the article referencing "PaperCut Zero-Day Exploited in Attacks, Affecting All NG and MF Versions" as related coverage. The use of credential harvesting tools and Metasploit payloads follows established post-exploitation patterns seen across multiple threat actor groups, though no specific attribution to known APT or cybercrime groups has been made. The rapid exploitation of newly disclosed vulnerabilities indicates either pre-existing knowledge or swift weaponization capabilities.
Defensive Recommendations
- Immediately patch PaperCut NG and MF servers to address CVE-2026-81578 and CVE-2026-82078; restrict PaperCut servers from internet exposure and place behind VPN or zero-trust access controls
- Monitor for suspicious parent-child process relationships, specifically cmd.exe or powershell.exe spawned by pc-app.exe, and alert on discovery commands (whoami, tasklist, ver, uname -a) executed in this context (T1059)
- Block or alert on certutil.exe usage for file downloads (T1105), particularly from external IPs; implement application whitelisting to prevent execution of credential dumping tools like lsa_collect.exe and save_hives.exe (T1003.002)
- Monitor for anomalous privileged account creation (T1136), especially accounts with naming patterns like 'Administrator[number]'; enable enhanced logging for SAM database access and registry hive operations
- Block known malicious infrastructure: 45.142.193[.]132 and 194.180.48[.]134; monitor for GET requests to /custom/pcp_*.txt and /custom/web/pcp_*.txt paths; implement file integrity monitoring on PaperCut *.config files and alert on findstr searches for credential-related terms
---
# Geopolitical Context
Geopolitical Context
The active exploitation of CVE-2026-81578 and CVE-2026-82078 against educational institutions in the United States and Europe represents a continuation of adversary focus on the education sector as a high-value, often under-resourced target environment. Educational institutions maintain extensive repositories of personal data, research intellectual property, and federated authentication systems that can serve as pivot points into broader academic and research networks. The targeting pattern—spanning K-12 through university systems across two major Western regions—suggests either an opportunistic campaign exploiting newly disclosed vulnerabilities at scale, or a coordinated effort to establish persistent access across educational infrastructure. The use of credential harvesting tools, registry extraction utilities, and Meterpreter payloads indicates a post-exploitation focus on lateral movement and long-term access rather than immediate financial gain, which may point to espionage or pre-positioning objectives.
State Actor Alignment
No state actor attribution is provided in the available reporting. The observed tactics—credential theft, registry hive collection, and deployment of widely available post-exploitation frameworks like Metasploit/Meterpreter—are consistent with both state-sponsored advanced persistent threat (APT) operations and financially motivated cybercriminal activity. The infrastructure identified (IP addresses 45.142.193[.]132 and 194.180.48[.]134) would require further investigation to assess potential links to known threat groups or state-sponsored campaigns. The education sector has historically been targeted by state-aligned actors seeking research data, particularly in dual-use technology domains, as well as by ransomware operators exploiting budget constraints and legacy systems. Without additional indicators, definitive alignment remains indeterminate.
Business Impacty pro region
The transatlantic scope of the campaign—affecting both U.S. and European educational institutions—underscores shared vulnerabilities in Western education infrastructure and the cross-border nature of cyber threats facing the sector. Educational institutions in both regions face similar resource constraints, often maintaining internet-exposed management systems with limited security monitoring capabilities. The credential theft focus raises concerns about potential downstream impacts on research collaboration networks, student data protection obligations under frameworks like GDPR and FERPA, and the integrity of federated identity systems that increasingly link academic, government, and private sector research environments. If the compromised credentials enable access to research data or collaborative platforms, the incident may have implications for transatlantic research security, particularly in sensitive technology domains. The campaign may also prompt renewed policy attention to cybersecurity requirements for educational institutions receiving public funding in both the U.S. and EU member states.
Forecast
If the threat actors successfully leverage stolen credentials for lateral movement, affected institutions are likely to face extended incident response efforts and potential exposure of sensitive research or personal data. Should the campaign prove to be state-sponsored or espionage-focused, additional targeting of research institutions with defense, technology, or dual-use research portfolios is probable in the near term. If the activity is financially motivated, ransomware deployment or data extortion attempts may emerge in the coming weeks as actors monetize their access. Broader adoption of the CVE-2026-81578/CVE-2026-82078 exploit chain by additional threat groups is likely given the disclosure of technical details and the large attack surface presented by internet-exposed PaperCut servers. Regulatory scrutiny of affected institutions' data protection practices may intensify, particularly in Europe under GDPR enforcement mechanisms. If high-profile universities or research institutions are confirmed among the victims, legislative or policy responses mandating enhanced cybersecurity standards for the education sector may gain momentum in both the U.S. and EU.
