On August 31, 2026, attackers broke into a school’s print server and ended up owning its entire Windows domain. eSentire’s Threat Response Unit (TRU) traced the intrusion to a PaperCut zero-day chain. According to eSentire’s detailed write-up, the attackers hid an AdaptixC2 implant inside a tampered copy of Microsoft Copilot.
At a Glance
| Malware family | In-memory Java loader, custom web shell, AdaptixC2 implant |
| Threat actor | Unknown; no attribution made |
| Target | One eSentire customer in the education sector |
| Delivery vector | Exploitation of PaperCut MF flaws CVE-2026-82078 and CVE-2026-81578 |
| Key capabilities | Log wiping, token theft, credential dumping, pass-the-hash, AD database theft |
| Sources | eSentire TRU; Arctic Wolf |
TL;DR
Attackers chained two PaperCut MF flaws to run code on an internet-facing print server. They planted a web shell, then dropped an AdaptixC2 implant disguised as Microsoft Copilot. Within days, they reached a domain controller and copied the password hashes for every account.
Delivery
The victim ran PaperCut MF version 24.0.2 on a server open to the internet. Arctic Wolf explains the two bugs. CVE-2026-81578 is an authentication bypass rated 8.8. CVE-2026-82078 is a class-loading flaw rated 9.4. Together, they allow code execution as SYSTEM without a login.
Attackers began exploiting the pair around August 26, according to Arctic Wolf. PaperCut shipped three emergency patch releases over the next week. Meanwhile, CISA added both bugs to its Known Exploited Vulnerabilities list on August 31.
Infection Chain

Stage 1: Java Loader
The attackers used SQL injection through a card ID lookup field. This planted chunks of Java code on the server. A small loader then joined the chunks and ran them in memory. Afterward, it deleted itself and every chunk file.
Stage 2: A Self-Cleaning Web Shell
The second stage acts as a web shell. Operators send it commands through a custom HTTP header. It can run JavaScript, execute system commands, and read PaperCut settings. It also scrubs server logs and deletes database rows that reveal the break-in.
Notably, the web shell also blocks other attackers. It filters requests to the flawed endpoint, so rivals cannot reuse the same exploit.
Stage 3: Fake Copilot, Real Implant
Next, the attackers downloaded a trojanized Microsoft Copilot binary. They replaced part of its code with an obfuscated AdaptixC2 implant. AdaptixC2 is an open-source post-exploitation framework with modules for credential theft and lateral movement.
The fake binary needs a legitimate Microsoft Edge DLL to run. As eSentire notes, it “fails to run in public sandboxes due to a missing legitimate DLL dependency.” The implant also uses control flow flattening and a changed API hashing seed to dodge static detection.
Lateral Movement and Domain Takeover
After check-in, the implant went quiet for roughly a day. Then the operators returned for hands-on-keyboard work. First, they found domain controllers through DNS lookups. Next, they stole a token from a process running as a privileged service account.
With that token, they copied the implant to a domain controller. They ran it by briefly hijacking the built-in PlugPlay service, then restored its settings to hide the change. On the controller, they dumped credentials from memory and the registry.
The attackers then enabled Windows Restricted Admin mode. This let them log in over RDP with only a password hash. Finally, they copied the Active Directory database, “achieving full compromise of the Active Directory environment,” eSentire says.
Command-and-Control and Data Theft
The AdaptixC2 implant talks to its server over HTTP. Its first check-in sends RC4-encrypted host details, including the computer name, username, domain, and internal IP. Later traffic uses a session key from that check-in. The attackers also changed default headers so the traffic looks like Google Chrome.
At the end, the operators packed the AD database and registry files into one 7-Zip archive. eSentire describes this archive as staged “for exfiltration.” The report does not confirm that the file left the network.
Attribution
eSentire has not linked this intrusion to any known group. No attribution, confirmed or suspected, appears in the report. The case involved one confirmed victim.
Defense and Detection Guidance
Any organization running PaperCut should act on this PaperCut zero-day now:
- Upgrade PaperCut NG/MF to 24.1.10, 25.0.13, or 26.0.5 or later.
- Keep the PaperCut admin interface off the internet.
- Review PaperCut server logs for SQL statements carrying large encoded Java blobs.
- Alert when the PaperCut process writes or launches new executables.
- Watch for Copilot binaries in unusual folders, especially next to Edge DLLs.
- Flag changes that enable Restricted Admin mode and edits to service binary paths.
- Monitor domain controllers for NTDS.dit backups and new archive files.
If you find signs of compromise, assume the whole domain is exposed. Reset privileged accounts, including the KRBTGT account, and rebuild trust from clean systems.
Support Our Threat Intelligence
Find our threat intelligence and malware analysis helpful? Support our work today and unlock a 100% ad-free reading experience!