Article

    Cyber News / Article / Attackers Exploit PaperCut Flaws to Steal Credentials From Schools and Universities

    Attackers Exploit PaperCut Flaws to Steal Credentials From Schools and Universities
    in
    [email protected] (The Hacker News)-6 days ago

    Attackers Exploit PaperCut Flaws to Steal Credentials From Schools and Universities

    Threat actors are exploiting the newly disclosed PaperCut flaws to facilitate credential theft in attacks targeting the education sector in the U.S. and Europe.

    The Arctic Wolf Adversary Research Teamsaidit observed attackers exploitingCVE-2026-81578 and CVE-2026-82078– an authentication bypass and remote code execution chain – to conduct command execution and reconnaissance, as well as create privileged accounts.

    "Observed post-exploitation activity included delivery of Windows registry hive collection tools, Metasploit/Meterpreter-related Java payloads, and commands used to identify hosts, users, processes, and sensitive configuration data," Arctic Wolf said.

    The cybersecurity company told The Hacker News that the activity has targeted vulnerable PaperCut servers across the education sector, impacting organizations ranging from K-12 schools to major universities in the U.S. and Europe.

    Some of the identified malicious activity includes -

    Arctic Wolf said it also detected "lsa_collect.exe" in a sandbox that extracted specific registry keys to reconstruct the system BootKey, which can then grant the attacker access to the SAM database.

    "The concern is that those stolen logins could give attackers a pathway into other critical systems across the environment. Post-compromise activity included deployment of Windows registry," Arctic Wolf said in a statement.

    Users are advised to restrict PaperCut servers from being exposed to the internet and monitor for the execution of cmd.exe, powershell.exe, or other scripting and command interpreters, along with commands containing whoami, tasklist, ver, or uname -a with pc-app.exe as the parent process.

    Original source