Threat Advisory

Russian-speaking MCA Exploits PaperCut NG/MF for RCE and Credential Harvesting

Threat: Vulnerability
Threat Actor Name: Russian-speaking malicious cyber actor (MCA)
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

An AI-orchestrated cyber campaign targeted vulnerable PaperCut NG/MF print-management servers. The campaign involved exploitation of vulnerabilities that enabled attackers to gain remote code execution. Attackers established a laboratory environment to test exploitation and credential-harvesting techniques. AI agents were then used to automate exploit development, testing, and large-scale target discovery. The campaign affected hundreds of PaperCut instances across organizations in multiple countries. Compromised systems provided opportunities for credential theft and further Active Directory attacks. The activity demonstrates how AI-assisted automation can significantly accelerate cyberattack operations.

The attackers exploited vulnerable PaperCut servers and subsequently performed credential harvesting and privilege escalation. Techniques included LSASS memory and registry-secret extraction to obtain privileged credentials. Attackers also used pass-the-hash techniques to access domain controllers and connected systems. In some environments, they exploited weaknesses involving Active Directory account and privilege management. Tools including Mimikatz, SharpHound, Certipy, BloodHound, Rubeus, Impacket, and NetExec were observed. DCSync activity was used to obtain domain credential information from Active Directory. The campaign demonstrated automated chaining of exploitation, credential access, discovery, and lateral movement.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

An AI-orchestrated cyber campaign targeted vulnerable PaperCut NG/MF print-management servers. The campaign involved exploitation of vulnerabilities that enabled attackers to gain remote code execution. Attackers established a laboratory environment to test exploitation and credential-harvesting techniques. AI agents were then used to automate exploit development, testing, and large-scale target discovery. The campaign affected hundreds of PaperCut instances across organizations in multiple countries. Compromised systems provided opportunities for credential theft and further Active Directory attacks. The activity demonstrates how AI-assisted automation can significantly accelerate cyberattack operations.

The attackers exploited vulnerable PaperCut servers and subsequently performed credential harvesting and privilege escalation. Techniques included LSASS memory and registry-secret extraction to obtain privileged credentials. Attackers also used pass-the-hash techniques to access domain controllers and connected systems. In some environments, they exploited weaknesses involving Active Directory account and privilege management. Tools including Mimikatz, SharpHound, Certipy, BloodHound, Rubeus, Impacket, and NetExec were observed. DCSync activity was used to obtain domain credential information from Active Directory. The campaign demonstrated automated chaining of exploitation, credential access, discovery, and lateral movement.[emaillocker id="1283"]

The campaign highlights the increasing use of AI to automate and accelerate complex cyberattack workflows. Attackers were able to move from vulnerability testing to successful exploitation within a short period. However, the level of compromise varied between targeted organizations and did not always result in domain-admin access. Security controls such as web application firewalls were capable of preventing some exploitation attempts. Organizations should prioritize vulnerability management for internet-facing PaperCut NG/MF deployments. Active Directory hardening, credential protection, segmentation, and monitoring can reduce post-exploitation opportunities. Continuous detection of abnormal authentication, credential-dumping, and lateral-movement activity is also important.

RECOMMENDATION:

We recommend you to refer below link: https://www.papercut.com/kb/Main/security-bulletin-27-aug-2026-urgent-security-advisory/

THREAT PROFILE:

Tactic Technique Id Technique Sub-technique
Initial access T1190 Exploit Public Facing Application-
Credential access T1555.003 Credentials from Password Stores Credentials from Web Browsers
Collection T1005 Data from Local System -
Exfiltration T1041 Exfiltration Over C2 Channel -
Impact T1486 Data Encrypted for Impact -

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu