INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
ATTENTION: This report is based on previous data. New intelligence sources have been linked and the Executive Summary and Mitigations need to be re-synthesized.
PaperCut Zero-Days Exploited in Data Theft Attacks by Lazarus
| 2026-09-07 07:56 MEDIUM HIGH EXPLOITED VULNERABILITY
Executive Summary
AI-generated
Attackers Exploit PaperCut Flaws to Steal Credentials From Schools and Universities on 2026-09-05. The attackers are believed to be behind the incident, exploiting vulnerabilities in PaperCut servers across the education sector in the U.S. and Europe, affecting organizations ranging from K-12 schools to major universities. The attack works by using authentication bypass and remote code execution chains to conduct command execution and reconnaissance, as well as create privileged accounts. Currently, users are advised to restrict PaperCut servers from being exposed to the internet and monitor for suspicious activity, including the execution of [IOC HIDDEN • LOGIN REQUIRED] or [IOC HIDDEN • LOGIN REQUIRED] with commands containing whoami, tasklist, ver, or uname -a with [IOC HIDDEN • LOGIN REQUIRED] as the parent process.
Technical Mitigations AI-generated
• Block inbound GET requests from "45.142.193[.]132" that request for "/custom/pcp_*.txt" and "/custom/web/pcp_*.txt" files on compromised hosts.
• Use the PaperCut Software published indicators of compromise to block ongoing attacks, including the IP addresses "194.180.48[.]134".
• Restrict PaperCut servers from being exposed to the internet and monitor for the execution of <a href="/auth/login?next=/detail/TGYNTKAB-1kL6CVYQWj1" class="ioc-censored-pill text-decoration-none" title="Protected IoC: Sign in to view" data-bs-toggle="tooltip"><span class="badge bg-black text-warning border border-warning border-opacity-75 font-monospace ioc-lock-tag align-middle"><i class="bi bi-lock-fill me-1"></i>[IOC HIDDEN • LOGIN REQUIRED]</span></a>, <a href="/auth/login?next=/detail/TGYNTKAB-1kL6CVYQWj1" class="ioc-censored-pill text-decoration-none" title="Protected IoC: Sign in to view" data-bs-toggle="tooltip"><span class="badge bg-black text-warning border border-warning border-opacity-75 font-monospace ioc-lock-tag align-middle"><i class="bi bi-lock-fill me-1"></i>[IOC HIDDEN • LOGIN REQUIRED]</span></a>, or other scripting and command interpreters, along with commands containing whoami, tasklist, ver, or uname -a.
• Note: The above list only includes specific mitigations mentioned in the provided sources.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected
Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.
de•••••.log
se•••••.log
ud•••••.out
ls•••••.exe
po•••••.exe
cm•••••.exe
ce•••••.exe
194.180.•••.•••
45.142.•••.•••
c3f710••••••••••••••••••••••••••••••••••••••••••••••••••••••••••
14779d••••••••••••••••••••••••••••••••••••••••••••••••••••••••••
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2023-2533CVE-2023-2533
CVE-2026-82078CVE-2026-82078
CVE-2026-81578CVE-2026-81578
Target & Sectors
EUROPE
EUROPE
FIVE_EYES
FIVE_EYES
educationeducation
Incident Timeline
April 2023
Threat actors exploited two vulnerabilities, CVE-2023–27350 and CVE-2023–27351, in April 2023 to carry out data theft attacks linked to the LockBit and Clop ransomware gangs.
Click on any entity below to view its context and source!
tactic
Remote Code Execution
A critical remote code execution vulnerability (CVE–2023–27350) and a high-severity information disclosure flaw (CVE–2023–27351) were chained in April 2023 attacks
linked to the LockBit and Clop ransomware gangs
.
tactic
Ransomware
A critical remote code execution vulnerability (CVE–2023–27350) and a high-severity information disclosure flaw (CVE–2023–27351) were chained in April 2023 attacks
linked to the LockBit and Clop ransomware gangs
.
organisation
LockBit
A critical remote code execution vulnerability (CVE–2023–27350) and a high-severity information disclosure flaw (CVE–2023–27351) were chained in April 2023 attacks
linked to the LockBit and Clop ransomware gangs
.
May 2023
The Bl00dy Ransomware gang exploited the CVE-2023–27350 flaw for initial access to targets' networks.
Click on any entity below to view its context and source!
tactic
Ransomware
One month later, in May 2023, the FBI and CISA
warned
that the Bl00dy Ransomware gang had also begun exploiting the CVE–2023–27350 flaw for initial access to targets' networks.
attribution
FBI
One month later, in May 2023, the FBI and CISA
warned
that the Bl00dy Ransomware gang had also begun exploiting the CVE–2023–27350 flaw for initial access to targets' networks.
July 2025
Threat actors exploited a remote code execution vulnerability (CVE-2023-2533) in July 2025.
Click on any entity below to view its context and source!
tactic
Remote Code Execution
The Cybersecurity and Infrastructure Security Agency (CISA)
flagged
another remote code execution vulnerability (CVE-2023-2533) as actively exploited in July 2025.
attribution
CVE-2023-2533
The Cybersecurity and Infrastructure Security Agency (CISA)
flagged
another remote code execution vulnerability (CVE-2023-2533) as actively exploited in July 2025.
2026/08/25
Threat actors are exploiting previously patched zero-day vulnerabilities in PaperCut NG and MF print management software to carry out data theft attacks.
Click on any entity below to view its context and source!
organisation
PaperCut NG
Two security vulnerabilities in the PaperCut NG and MF print management software, patched last week after being exploited as zero-days, are now being abused in data theft attacks.
organisation
MF
Two security vulnerabilities in the PaperCut NG and MF print management software, patched last week after being exploited as zero-days, are now being abused in data theft attacks.
August 27, 2026
Threat actors used a tweaked version of the command "whoami & ver & tasklist" to capture system information, including running processes.
Click on any entity below to view its context and source!
organisation
whoami & ver &
In another incident recorded on August 27, 2026, the threat actors are said to have used a different version of the .class file that runs a tweaked version of the command to also capture the list of running processes: "whoami & ver & tasklist"
Organizations that have PaperCut NG and MF in their environment are advised to remove public exposure immediately and apply the patch as soon as possible.
Aug 28, 2026
Threat actors exploited a previously unknown vulnerability in PaperCut to carry out data theft attacks.
Aug 29th
Threat actors used the unpatched PaperCut NG/MF vulnerabilities CVE-2026-81578 and CVE-2026-82078 to exploit in data theft attacks observed by defenders starting late yesterday UTC on August 29th.
Click on any entity below to view its context and source!
vulnerability
CVE-2026-81578
"We are observing CVE-2026-81578 / CVE-2026-82078 (PaperCut NG/MF) exploit activity in our honeypots since late yesterday UTC (Aug 29th),"
Defused said
.
vulnerability
CVE-2026-82078
"We are observing CVE-2026-81578 / CVE-2026-82078 (PaperCut NG/MF) exploit activity in our honeypots since late yesterday UTC (Aug 29th),"
Defused said
.
organisation
PaperCut NG/MF
"We are observing CVE-2026-81578 / CVE-2026-82078 (PaperCut NG/MF) exploit activity in our honeypots since late yesterday UTC (Aug 29th),"
Defused said
.
organisation
UTC
"We are observing CVE-2026-81578 / CVE-2026-82078 (PaperCut NG/MF) exploit activity in our honeypots since late yesterday UTC (Aug 29th),"
Defused said
.
2026/08/31
Threat actors used the unpatched PaperCut NG/MF vulnerabilities CVE-2026-81578 and CVE-2026-82078 to target an organization's systems.
Click on any entity below to view its context and source!
vulnerability
CVE-2026-81578
"We are observing CVE-2026-81578 / CVE-2026-82078 (PaperCut NG/MF) exploit activity in our honeypots since late yesterday UTC (Aug 29th),"
Defused said
.
vulnerability
CVE-2026-82078
"We are observing CVE-2026-81578 / CVE-2026-82078 (PaperCut NG/MF) exploit activity in our honeypots since late yesterday UTC (Aug 29th),"
Defused said
.
organisation
PaperCut NG/MF
"We are observing CVE-2026-81578 / CVE-2026-82078 (PaperCut NG/MF) exploit activity in our honeypots since late yesterday UTC (Aug 29th),"
Defused said
.
organisation
UTC
"We are observing CVE-2026-81578 / CVE-2026-82078 (PaperCut NG/MF) exploit activity in our honeypots since late yesterday UTC (Aug 29th),"
Defused said
.
Sep 05, 2026
Threat actors exploited a previously unknown vulnerability in PaperCut to carry out data theft attacks.
2026/09/05
Threat actors are exploiting the newly disclosed PaperCut flaws to facilitate credential theft in attacks targeting the education sector in the U.S. and Europe.
Click on any entity below to view its context and source!
organisation
PaperCut Flaws to Steal
Attackers Exploit PaperCut Flaws to Steal Credentials From Schools and Universities.
organisation
Vulnerability / Web Security
Ravie Lakshmanan
Sep 05, 2026
Vulnerability / Web Security
Threat actors are exploiting the newly disclosed PaperCut flaws to facilitate credential theft in attacks targeting the education sector in the U.S. and Europe.
Ravie Lakshmanan
Aug 28, 2026
Vulnerability / Web Security
Malicious actors are exploiting a
newly patched security flaw
in PaperCut NG and MF to execute arbitrary code on susceptible instances, as the company released a fresh emergency fix with additional hardening.
organisation
PaperCut
Ravie Lakshmanan
Sep 05, 2026
Vulnerability / Web Security
Threat actors are exploiting the newly disclosed PaperCut flaws to facilitate credential theft in attacks targeting the education sector in the U.S. and Europe.
"An actor is abusing the auth bypass to hijack PaperCut's external user-lookup.
"This vulnerability gives an unauthenticated attacker remote control over PaperCut's trusted configuration, which could be used to execute arbitrary Java code inside the application's process," Huntress researchers John Hammond and Andrew Brandt
said
.
organisation
The Hacker News
The cybersecurity company told The Hacker News that the activity has targeted vulnerable PaperCut servers across the education sector, impacting organizations ranging from K-12 schools to major universities in the U.S. and Europe.
"At this time, we don't have enough evidence to determine the threat actors' ultimate end goal," John Hammond, senior principal security researcher at Huntress, told The Hacker News.
organisation
PaperCut NG
Ravie Lakshmanan
Aug 28, 2026
Vulnerability / Web Security
Malicious actors are exploiting a
newly patched security flaw
in PaperCut NG and MF to execute arbitrary code on susceptible instances, as the company released a fresh emergency fix with additional hardening.
organisation
MF
Ravie Lakshmanan
Aug 28, 2026
Vulnerability / Web Security
Malicious actors are exploiting a
newly patched security flaw
in PaperCut NG and MF to execute arbitrary code on susceptible instances, as the company released a fresh emergency fix with additional hardening.
organisation
The Blue Report 2026
The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.
organisation
The Arctic Wolf Adversary Research Team
The Arctic Wolf Adversary Research Team
said
it observed attackers exploiting
CVE-2026-81578 and CVE-2026-82078
– an authentication bypass and remote code execution chain – to conduct command execution and reconnaissance, as well as create privileged accounts.
data_breach
8.8 instantiates database driver classes
The application instantiates database driver classes based on configurable driver names without validating against an allowlist of approved drivers
CVE-2026-81578
(CVSS score: 8.8) -
infrastructure
Windows
"Observed post-exploitation activity included delivery of Windows registry hive collection tools, Metasploit/Meterpreter-related Java payloads, and commands used to identify hosts, users, processes, and sensitive configuration data," Arctic Wolf said.
Post-compromise activity included deployment of Windows registry," Arctic Wolf said in a statement.
…ommands on the targeted server as part of post-exploitation activity to determine user account and operating system using a chained command "whoami & ver."
Also deployed as part of the attack is a Java .class file that's operating system agnostic and can run commands under either Linux or Windows systems to fingerprint the machine and obtain a directory listing of files stored on the computer.
infrastructure
Linux
…ommands on the targeted server as part of post-exploitation activity to determine user account and operating system using a chained command "whoami & ver."
Also deployed as part of the attack is a Java .class file that's operating system agnostic and can run commands under either Linux or Windows systems to fingerprint the machine and obtain a directory listing of files stored on the computer.
organisation
BootKey
…ve Meterpreter Java payloads from, and establish sessions to, "194.180.48[.]134"
Use "findstr" to search PaperCut *.config files for the terms "password," "secret," "ldap," "bind,v and "token"
Arctic Wolf said it also detected "lsa_collect.exe" in a sandbox that extracted specific registry keys to reconstruct the system BootKey, which can then grant the attacker access to the SAM database.
organisation
SAM
…ve Meterpreter Java payloads from, and establish sessions to, "194.180.48[.]134"
Use "findstr" to search PaperCut *.config files for the terms "password," "secret," "ldap," "bind,v and "token"
Arctic Wolf said it also detected "lsa_collect.exe" in a sandbox that extracted specific registry keys to reconstruct the system BootKey, which can then grant the attacker access to the SAM database.
victims
100 users
According to PaperCut Software, the software is used by 100 million users across more than 70,000 organizations, including large companies, state agencies, and educational institutions.
victims
70,000 organizations
According to PaperCut Software, the software is used by 100 million users across more than 70,000 organizations, including large companies, state agencies, and educational institutions.
organisation
RCE
Unlike the RCE path in public writeups, the actor goes for data theft - dumping DB tables via Derby.
organisation
Derby
Unlike the RCE path in public writeups, the actor goes for data theft - dumping DB tables via Derby.
organisation
NG
"
Internet security watchdog Shadowserver currently
tracks over 800 PaperCut MF and NG servers exposed online
, although there is no information on how many are honeypots or have already been secured against these attacks.
organisation
Microsoft
Microsoft revealed two weeks later that the
Muddywater
and
APT35
Iranian state-backed hacking groups had also
joined the attacks
.
organisation
Huntress
Huntress has explained the flaw as follows -
In unpatched versions of PaperCut NG and PaperCut MF, a specifically crafted request can refer to one page that is rendered for the response, and another page that owns the component or action being executed.
organisation
PaperCut MF
Huntress has explained the flaw as follows -
In unpatched versions of PaperCut NG and PaperCut MF, a specifically crafted request can refer to one page that is rendered for the response, and another page that owns the component or action being executed.
organisation
PaperCut Application
It's also recommended to restrict PaperCut Application Server web access to trusted IP addresses or place it behind a VPN or another controlled administrative path.
organisation
IP
It's also recommended to restrict PaperCut Application Server web access to trusted IP addresses or place it behind a VPN or another controlled administrative path.
Tactical Metrics
Metrics
infrastructure
Windows
Affected Product
Click for context!
"Observed post-exploitation activity included delivery of Windows registry hive collection tools, Metasploit/Meterpreter-related Java payloads, and commands used to identify hosts, users, processes, and sensitive configuration data," Arctic Wolf said.
Post-compromise activity included deployment of Windows registry," Arctic Wolf said in a statement.
…ommands on the targeted server as part of post-exploitation activity to determine user account and operating system using a chained command "whoami & ver."
Also deployed as part of the attack is a Java .class file that's operating system agnostic and can run commands under either Linux or Windows systems to fingerprint the machine and obtain a directory listing of files stored on the computer.
Metrics
victims
100,000,000
Users
According to PaperCut Software, the software is used by 100 million users across more than 70,000 organizations, including large companies, state agencies, and educational institutions.
Metrics
victims
70,000
Organizations
According to PaperCut Software, the software is used by 100 million users across more than 70,000 organizations, including large companies, state agencies, and educational institutions.
Metrics
data_breach
9
Instantiates Database Driver Classes
The application instantiates database driver classes based on configurable driver names without validating against an allowlist of approved drivers
CVE-2026-81578
(CVSS score: 8.8) -
Metrics
infrastructure
Linux
Affected Product
…ommands on the targeted server as part of post-exploitation activity to determine user account and operating system using a chained command "whoami & ver."
Also deployed as part of the attack is a Java .class file that's operating system agnostic and can run commands under either Linux or Windows systems to fingerprint the machine and obtain a directory listing of files stored on the computer.
Intelligence Sources
The Hacker News
2026-08-28
The Hacker News
2026-09-05
BleepingComputer
2026-09-01
Recently patched PaperCut zero-days used in data theft attacks
BleepingComputer
AlienVault OTX
2026-09-05
AlienVault OTX
2026-09-07
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-10-07T10:15
Comprehensive Tactical Telemetry
Highly Correlated Entities
23x
organisation
Identified Entity
Hackers Actively Exploiting PaperCut Servers Command Execution
entity
10x
timeline
Temporal Reference
Sep 05, 2026
date
4x
tactic
MITRE ATT&CK Technique
T1588.006 - Vulnerabilities
technique
4x
attribution
Attributing Entity
FBI
authority
3x
tactic
Cyber Operation Type
Reconnaissance
tactic
3x
vulnerability
Exploited CVE
CVE-2026-81578
cve
2x
infrastructure
Affected Product
Windows
software
Contextual Telemetry
Context Block
14 METRICS
industry
Targeted Sector
Education
sector
target region
Target Region
EUROPE
region
general metric
Sep
5
sep
general metric
Ravie Lakshmanan
2,026
ravie lakshmanan
malware
Offensive Tool
Metasploit
tool
victims
Users
100,000,000
users
victims
Organizations
70,000
organizations
general metric
Papercut Mf
800
papercut mf
source region
Origin Country
Iran, Islamic Republic of
country
general metric
Simulations
338,000,000
simulations
general metric
Score
9
score
data breach
Instantiates Database Driver Classes
9
instantiates database driver classes
general metric
Aug
28
aug
target region
Target Country
Australia
country
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.