ATTACKERS chained two PaperCut MF flaws to gain initial access from an internet-facing server and deploy a trojanised Microsoft Copilot binary, concealing an AdaptixC2 implant inside the fake Copilot. The intrusion, attributed to an in-scope incident reported by eSentire Threat Response Unit, began on or around 26 August as the attackers exploited CVE-2026-81578 (authentication bypass) and CVE-2026-82078 (class-loading flaw) on PaperCut MF version 24.0.2.
PaperCut subsequently released three emergency patches, and CISA added both CVEs to the Known Exploited Vulnerabilities list on 31 August. The operation culminated in the implant reaching a Windows domain controller and enabling broad credential access.
Infection and movement proceeded in three stages. Stage 1 used SQL injection via a card ID lookup to plant in-memory Java chunks, which a small loader assembled and executed before deleting its artifacts. Stage 2 deployed a self-cleaning web shell that accepts commands via a custom HTTP header, can run JavaScript, and scrubs logs and related entries to hinder discovery; it also blocks other attackers from reusing the exploit.
Stage 3 involved dropping a trojanised Microsoft Copilot binary with an obfuscated AdaptixC2 implant that relies on a legitimate Edge DLL to run and employs anti-detection techniques, including API hashing changes and control-flow flattening. Lateral movement targeted domain controllers by token theft and a brief hijack of the PlugPlay service, enabling Active Directory data exfiltration and enabling Restricted Admin mode for RDP.
The article notes the operation exfiltrated the AD database and registry into a 7-Zip archive, though it does not confirm external data departure. No attribution was assigned to a named group.