Recent reports indicate that cybercriminals are actively exploiting vulnerabilities in PaperCut software to steal credentials from educational institutions in the United States and Europe. These attacks capitalize on newly revealed flaws to infiltrate systems within schools and universities, posing significant security threats.
Identifying the Vulnerabilities
The Arctic Wolf Adversary Research Team has identified that attackers are utilizing two specific vulnerabilities, CVE-2026-81578 and CVE-2026-82078. These vulnerabilities enable an authentication bypass and remote code execution, allowing unauthorized command execution and reconnaissance activities. The hackers are reportedly creating privileged accounts to further their illegal operations.
Arctic Wolf’s findings highlight post-exploitation activities that include deploying Windows registry hive collection tools and using Metasploit/Meterpreter-related Java payloads. These actions aim to gather detailed information about hosts, users, and sensitive configuration data.
Impact on Educational Institutions
The scope of this cyber threat affects various entities within the education sector, from K-12 schools to major universities across the U.S. and Europe. Vulnerable PaperCut servers have become prime targets for these malicious activities. Specific actions observed include the execution of discovery commands, creation of privileged accounts, and the delivery of credential-harvesting tools.
Additionally, attackers are making inbound requests to compromised hosts to access specific files containing harvested system and user data. They also retrieve Meterpreter Java payloads to establish unauthorized sessions, further compromising the security of these educational institutions.
Preventative Measures and Recommendations
In response to these vulnerabilities, Arctic Wolf advises users to implement several protective measures. These include not exposing PaperCut servers to the internet and monitoring for the execution of certain command-line interpreters and scripts. Specifically, institutions should watch for commands containing whoami, tasklist, ver, or uname -a, particularly when executed by the pc-app.exe process.
The broader concern is that compromised credentials could provide attackers with access to critical systems beyond the initially targeted PaperCut servers. Arctic Wolf’s analysis indicates that post-compromise activities often involve deploying additional Windows registry tools to reinforce their hold on the system.
As educational institutions continue to be a target for cyber threats, it is crucial to stay informed about potential vulnerabilities and take proactive measures to safeguard sensitive information.
