Cybersecurity researchers at Arctic Wolf report that threat actors are actively exploiting critical PaperCut vulnerabilities to steal credentials and compromise educational institutions across the United States and Europe.
Key Points
- Attackers are chaining CVE-2026-81578 and CVE-2026-82078 to bypass authentication and execute remote code on vulnerable PaperCut servers.
- Malicious activity includes creating privileged accounts, deploying credential-harvesting tools like lsa_collect.exe, and extracting sensitive system registry data.
- Researchers identified malicious traffic originating from IP addresses 45.142.193.132 and 194.180.48.134 to facilitate data exfiltration and establish Meterpreter sessions.
- Compromised systems are being searched for configuration files containing passwords, LDAP credentials, and security tokens.
- Security teams are advised to restrict internet exposure for PaperCut servers and monitor for suspicious command-line activity originating from the pc-app.exe process.