eSentire TRU detected exploitation of PaperCut MF zero-days (CVE-2026-82078 and CVE-2026-81578) against an education customer, leading to a web shell, a trojanized Microsoft Copilot binary, and deployment of an AdaptixC2 implant. The intrusion progressed to domain controller compromise, credential dumping, NTDS.dit extraction, and pass-the-hash movement across the Active Directory environment. #PaperCutMF #CVE-2026-82078 #CVE-2026-81578 #AdaptixC2 #MicrosoftCopilot
Keypoints
- eSentire TRU observed exploitation of two newly disclosed PaperCut MF zero-day vulnerabilities on an internet-facing print server.
- Attackers used SQL injection and a multi-stage Java loader to deploy an in-memory web shell on the PaperCut server.
- The web shell was used to launch a trojanized Microsoft Copilot binary containing an AdaptixC2 implant.
- AdaptixC2 was used for discovery, token theft, lateral movement, and execution on a domain controller.
- After reaching the domain controller, attackers dumped credentials, enabled Windows Restricted Admin mode, and used pass-the-hash RDP access.
- Threat actors extracted NTDS.dit to obtain password hashes for domain accounts, enabling broader compromise of Active Directory.
- The report highlights evidence cleanup, log tampering, and defensive recommendations such as patching PaperCut MF/NG and restricting server access.
MITRE Techniques
- [T1190] Exploit Public-Facing Application – Threat actors exploited an internet-facing PaperCut MF print server to gain initial access through zero-days and SQL injection (‘threat actors exploited an internet-facing print server running a vulnerable version of PaperCut MF’).
- [T1059.005] Command and Scripting Interpreter: Visual Basic – Not mentioned.
- [T1059.007] Command and Scripting Interpreter: JavaScript – The web shell supported arbitrary JavaScript execution in memory (‘eval / jsEvaluates arbitrary JavaScript via the Nashorn ScriptEngine’).
- [T1059.006] Command and Scripting Interpreter: Python – Not mentioned.
- [T1106] Native API – The implant resolved Windows APIs directly and used them through indirect calls (‘resolved APIs by hash’ and ‘calls the resolved WideCharToMultiByte function through qword [rax+0x290]’).
- [T1055] Process Injection – The trojanized binary embedded the AdaptixC2 payload in a modified Microsoft Copilot executable and loaded it in process (‘a legitimate Microsoft Copilot binary was modified to embed an obfuscated AdaptixC2 implant’).
- [T1027] Obfuscated Files or Information – The implant used control flow flattening, XOR-encrypted configuration, and hashed API resolution to hinder analysis (‘control flow flattening’, ‘Encrypted Configuration’, ‘API Resolution’).
- [T1562.001] Impair Defenses: Disable or Modify Tools – The web shell deleted server.log lines and cleaned up .bin and loader files to remove evidence (‘deletes lines in server.log’ and ‘clean up files’).
- [T1070.001] Indicator Removal on Host: Clear Windows Event Logs – Not explicitly mentioned.
- [T1070.004] Indicator Removal on Host: File Deletion – Threat actors deleted .bin chunk files, loader class files, and other artifacts (‘deleting itself and all .bin files’).
- [T1036] Masquerading – The payload was delivered as a trojanized Microsoft Copilot binary and used a Chrome-like User-Agent to blend in (‘changed from the default … to Mozilla/5.0 (Windows NT 10.0; Win64; x64)… Chrome/126.0.0.0’).
- [T1219] Remote Access Software – AdaptixC2 provided remote shell access, file management, proxying, and post-compromise capabilities (‘provides a broad set of capabilities, including remote shell access’).
- [T1003.001] OS Credential Dumping: LSASS Memory – Attackers attempted to dump LSASS memory to recover credentials (‘an attempt to dump the process memory of LSASS’).
- [T1003.002] OS Credential Dumping: Security Account Manager – They saved a copy of the SAM registry hive to obtain the service account’s NTLM hash (‘saving a copy of the SAM registry hive’).
- [T1098] Account Manipulation – Not mentioned.
- [T1485] Data Destruction – The web shell wiped rows from PaperCut’s internal Derby database to destroy evidence (‘wipeDeletes rows from TBL_APPLICATION_LOG’).
- [T1021.001] Remote Services: Remote Desktop Protocol – Attackers remoted into the domain controller over RDP using NTLM hash authentication (‘authenticated to the domain controller over RDP in a pass-the-hash attack’).
- [T1550.002] Use Alternate Authentication Material: Pass the Hash – They enabled Restricted Admin mode and used an NTLM hash to authenticate (‘allows RDP authentication using only an NTLM hash’).
- [T1078] Valid Accounts – The intrusion leveraged a domain-privileged service account already present on the compromised host (‘duplicated its token’ and ‘impersonated a domain-privileged service account’).
- [T1134.001] Access Token Manipulation: Token Impersonation/Theft – Attackers duplicated a token from a process running as a domain-privileged service account (‘they duplicated its token’).
- [T1087.002] Account Discovery: Domain Account – They enumerated Domain Admins and active domain computers (‘net group “Domain Admins” /domain’ and ‘Enumerate active domain computers’).
- [T1018] Remote System Discovery – They used nslookup and nltest to find domain controllers and trust relationships (‘Scan for domain controllers, potential lateral movement targets’).
- [T1021.002] Remote Services: SMB/Windows Admin Shares – The implant and dependency were copied to a target host using the C$ administrative share (‘copied to the domain controller via C$ admin share’).
- [T1543.003] Create or Modify System Process: Windows Service – Attackers hijacked the PlugPlay service binary path and started the service to execute the implant (‘config PlugPlay binpath=…’).
- [T1057] Process Discovery – They ran tasklist /svc to enumerate local services (‘Local service reconnaissance’).
- [T1005] Data from Local System – They extracted NTDS.dit and archived it for exfiltration (‘writing a copy of NTDS.dit’).
- [T1074.001] Data Staged: Local Data Staging – They compressed NTDS.dit and IFM output into a 7z archive before exfiltration (‘7z.exe a c:microsoft.office3651.7z c:nbak’).
Indicators of Compromise
- [URL] Download locations for the trojanized AdaptixC2 payload – hxxps://taibeianmo.oss-cn-hongkong.aliyuncs[.]com/mscopilot.exe, hxxps://uneedcargo.oss-accelerate.aliyuncs[.]com/65722.txt
- [IPv4] Download and C2 infrastructure – 47.79.64[.]225, 156.227.0[.]13
- [File hashes] Trojanized binaries and loaders – d2e55213a02fd16a077298c986130522eb63196bdf8a8c1aec0eed6ef318b222, cf6dd15baf5ef66432a95b5a2ec64ba5c6de565b3fb9e10ae01b1a91612a1c2c, and 2 more hashes
- [File hashes] Java bytecode stages and decompiled artifacts – bc5fd75b307c2a11a602fbedb8275e0836ddf81cdd43af00a6bf0d850ff6cf58, 9c8760f8b973360701774bc56c7c97295eb42d49a02a281cbaadc32c973bd8b2, and 4 more hashes
- [File names] Payload and staging filenames used on disk – mscopilot.exe, msedge_elf.dll, and 1.7z
- [Processes / services] Executed tools and service names – pc-app.exe, PlugPlay, ntdsutil.exe, sc.exe
- [Paths] Staging and exfiltration locations – C:microsoft.office365mscopilot.exe, C:microsoft.office365msedge_elf.dll, C:nbakActive Directoryntds.dit