VMTech
Discuss a project

PaperCut Exploit Chain Targets Education Credentials

PaperCut Exploit Chain Targets Education Credentials

Attackers are exploiting two newly disclosed PaperCut vulnerabilities to steal credentials from educational organizations in the United States and Europe. Arctic Wolf observed activity against vulnerable PaperCut servers at targets ranging from K-12 schools to major universities, using CVE-2026-81578 and CVE-2026-82078 as an authentication-bypass and remote-code-execution chain.

The reported activity moved beyond initial access. Operators executed commands for reconnaissance, created privileged accounts and deployed tools designed to collect Windows registry hives. Arctic Wolf said the combination could expose credentials that provide a route into other critical systems in an affected environment.

From PaperCut access to credential collection

Observed commands included uname, whoami, ver and tasklist, which can reveal information about the operating system, current user, running processes and reachable hosts. Researchers also saw creation of a privileged account named Administrator17.

Attackers used findstr to scan PaperCut *.config files for terms including password, secret, ldap, bind and token. Such searches can identify stored credentials and configuration data that may be useful after the initial compromise.

Arctic Wolf also identified inbound GET requests from 45.142.193[.]132 for /custom/pcp_*.txt and /custom/web/pcp_*.txt files on compromised hosts. The files contained harvested system and user data. The same address was used with certutil.exe to deliver credential-harvesting tools named lsa_collect.exe, lsa_collect_small.exe and save_hives.exe.

Registry hives raise the impact of the intrusion

In sandbox analysis, lsa_collect.exe extracted selected registry keys that can be used to reconstruct the Windows BootKey. That key can enable access to the Security Account Manager database, or SAM, which stores local account credential material.

The researchers also observed Metasploit/Meterpreter-related Java payloads retrieved from 194.180.48[.]134, followed by attempts to establish sessions to that address. This activity, together with account creation and configuration-file searches, indicates attackers were conducting post-compromise work rather than simply probing exposed servers.

Defensive actions for education IT teams

Arctic Wolf recommends restricting PaperCut servers from exposure to the public internet. Security teams should also monitor for cmd.exe, powershell.exe and other command or scripting interpreters launched with pc-app.exe as the parent process.

Priority detections should include command lines containing whoami, tasklist, ver or uname -a, as well as unexpected privileged accounts, registry-hive collection utilities and access to PaperCut configuration files. For schools and universities, the practical implication is to treat PaperCut as a potential entry point to wider identity systems and investigate suspicious server activity before harvested credentials are reused elsewhere.

#papercut#cybersecurity#credentialtheft#educationit
Open analytics
On the site 0 views
min read 3 05.09.2026
Instagram

PaperCut Exploit Chain Targets Education Credentials

Open the post on Instagram ↗