INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
ATTENTION: This report is based on previous data. New intelligence sources have been linked and the Executive Summary and Mitigations need to be re-synthesized.

PaperCut Zero-Days Exploited in Data Theft Attacks by Lazarus

| 2026-09-07 07:56 MEDIUM HIGH EXPLOITED VULNERABILITY
Executive Summary
AI-generated
Attackers Exploit PaperCut Flaws to Steal Credentials From Schools and Universities on 2026-09-05. The attackers are believed to be behind the incident, exploiting vulnerabilities in PaperCut servers across the education sector in the U.S. and Europe, affecting organizations ranging from K-12 schools to major universities. The attack works by using authentication bypass and remote code execution chains to conduct command execution and reconnaissance, as well as create privileged accounts. Currently, users are advised to restrict PaperCut servers from being exposed to the internet and monitor for suspicious activity, including the execution of [IOC HIDDEN • LOGIN REQUIRED] or [IOC HIDDEN • LOGIN REQUIRED] with commands containing whoami, tasklist, ver, or uname -a with [IOC HIDDEN • LOGIN REQUIRED] as the parent process.
Technical Mitigations AI-generated
• Block inbound GET requests from "45.142.193[.]132" that request for "/custom/pcp_*.txt" and "/custom/web/pcp_*.txt" files on compromised hosts. • Use the PaperCut Software published indicators of compromise to block ongoing attacks, including the IP addresses "194.180.48[.]134". • Restrict PaperCut servers from being exposed to the internet and monitor for the execution of <a href="/auth/login?next=/detail/TGYNTKAB-1kL6CVYQWj1" class="ioc-censored-pill text-decoration-none" title="Protected IoC: Sign in to view" data-bs-toggle="tooltip"><span class="badge bg-black text-warning border border-warning border-opacity-75 font-monospace ioc-lock-tag align-middle"><i class="bi bi-lock-fill me-1"></i>[IOC HIDDEN &bull; LOGIN REQUIRED]</span></a>, <a href="/auth/login?next=/detail/TGYNTKAB-1kL6CVYQWj1" class="ioc-censored-pill text-decoration-none" title="Protected IoC: Sign in to view" data-bs-toggle="tooltip"><span class="badge bg-black text-warning border border-warning border-opacity-75 font-monospace ioc-lock-tag align-middle"><i class="bi bi-lock-fill me-1"></i>[IOC HIDDEN &bull; LOGIN REQUIRED]</span></a>, or other scripting and command interpreters, along with commands containing whoami, tasklist, ver, or uname -a. • Note: The above list only includes specific mitigations mentioned in the provided sources.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected

Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.

de•••••.log
se•••••.log
ud•••••.out
ls•••••.exe
po•••••.exe
cm•••••.exe
ce•••••.exe
194.180.•••.•••
45.142.•••.•••
c3f710••••••••••••••••••••••••••••••••••••••••••••••••••••••••••
14779d••••••••••••••••••••••••••••••••••••••••••••••••••••••••••
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2023-2533CVE-2023-2533 CVE-2026-82078CVE-2026-82078 CVE-2026-81578CVE-2026-81578
Target & Sectors
EUROPE EUROPE FIVE_EYES FIVE_EYES educationeducation
Incident Timeline
‎April 2023
Threat actors exploited two vulnerabilities, CVE-2023–27350 and CVE-2023–27351, in April 2023 to carry out data theft attacks linked to the LockBit and Clop ransomware gangs.
tactic Remote Code Execution
tactic Ransomware
organisation LockBit
‎May 2023
The Bl00dy Ransomware gang exploited the CVE-2023–27350 flaw for initial access to targets' networks.
tactic Ransomware
attribution FBI
‎July 2025
Threat actors exploited a remote code execution vulnerability (CVE-2023-2533) in July 2025.
tactic Remote Code Execution
attribution CVE-2023-2533
‎2026/08/25
Threat actors are exploiting previously patched zero-day vulnerabilities in PaperCut NG and MF print management software to carry out data theft attacks.
organisation PaperCut NG
organisation MF
‎August 27, 2026
Threat actors used a tweaked version of the command "whoami & ver & tasklist" to capture system information, including running processes.
organisation whoami & ver &
‎Aug 28, 2026
Threat actors exploited a previously unknown vulnerability in PaperCut to carry out data theft attacks.
‎Aug 29th
Threat actors used the unpatched PaperCut NG/MF vulnerabilities CVE-2026-81578 and CVE-2026-82078 to exploit in data theft attacks observed by defenders starting late yesterday UTC on August 29th.
vulnerability CVE-2026-81578
vulnerability CVE-2026-82078
organisation PaperCut NG/MF
organisation UTC
‎2026/08/31
Threat actors used the unpatched PaperCut NG/MF vulnerabilities CVE-2026-81578 and CVE-2026-82078 to target an organization's systems.
vulnerability CVE-2026-81578
vulnerability CVE-2026-82078
organisation PaperCut NG/MF
organisation UTC
‎Sep 05, 2026
Threat actors exploited a previously unknown vulnerability in PaperCut to carry out data theft attacks.
‎2026/09/05
Threat actors are exploiting the newly disclosed PaperCut flaws to facilitate credential theft in attacks targeting the education sector in the U.S. and Europe.
organisation PaperCut Flaws to Steal
organisation Vulnerability / Web Security
organisation PaperCut
organisation The Hacker News
organisation PaperCut NG
organisation MF
organisation The Blue Report 2026
organisation The Arctic Wolf Adversary Research Team
data_breach 8.8 instantiates database driver classes
infrastructure Windows
infrastructure Linux
organisation BootKey
organisation SAM
victims 100 users
victims 70,000 organizations
organisation RCE
organisation Derby
organisation NG
organisation Microsoft
organisation Huntress
organisation PaperCut MF
organisation PaperCut Application
organisation IP
Tactical Metrics
Metrics
infrastructure
‎Windows
Affected Product
Metrics
victims
100,000,000
Users
Metrics
victims
70,000
Organizations
Metrics
data_breach
9
Instantiates Database Driver Classes
Metrics
infrastructure
‎Linux
Affected Product