Back to feed

Attackers plant SimpleHelp and AnyDesk on compromised PaperCut servers

2 min
Attackers plant SimpleHelp and AnyDesk on compromised PaperCut servers

This digest was compiled by AI from multiple sources — links to the originals are below.

Attackers exploiting two zero-day vulnerabilities in PaperCut MF and NG are installing SimpleHelp and AnyDesk remote access tools on compromised Application Servers. PaperCut Software released emergency patches on August 28 and a second round later that day. The vendor extended its indicators of compromise on August 30 after observing the post-compromise activity.

Key Facts

  • PaperCut Software first warned of in-the-wild compromises on August 27, 2026, urging customers to restrict web access to trusted IP addresses.
  • The attackers exploited CVE-2026-81578 and CVE-2026-82078, chaining them to bypass authentication and execute arbitrary Java bytecode.
  • Emergency patches were released on August 28, with a second round later that day containing additional hardening.
  • On August 30, PaperCut extended its indicators of compromise and shared a command sequence showing post-compromise activity.
  • The attackers download a malicious payload from sendit.sh, install SimpleHelp, and then install AnyDesk as a redundant remote access channel.

Zero-Day Exploitation

PaperCut Software first warned of in-the-wild compromises on August 27, 2026, urging customers using PaperCut NG and MF to immediately restrict web access to trusted IP addresses only. The vendor initially believed a previously unknown vulnerability was exploited, but later investigation revealed two zero-day flaws: CVE-2026-81578, an improper access control vulnerability in the web management interface, and CVE-2026-82078, an unsafe dynamic class loading vulnerability in database connection utilities. Chained together, the two flaws allowed an unauthenticated threat actor to bypass authentication, modify certain system configurations, and execute arbitrary Java bytecode under the security context of the PaperCut server process. With the help of a university customer's security and digital forensics teams, PaperCut reproduced the vulnerabilities and pushed out emergency patches on August 28. Later that same day, the vendor published a second round of emergency patches with additional hardening developed with internal security and external researchers.

Post-Compromise Activity

On August 30, PaperCut extended its initial list of indicators of compromise and shared a command sequence showing what attackers do after gaining access to Application Servers. The attackers list users and their privileges, enumerate domain controllers, and list logged-on user sessions. They download a malicious payload from the file-sharing host sendit.sh into C:\ProgramData, silently install and run it, which installs SimpleHelp remote access software and sets it to auto-start. The attackers then download AnyDesk to establish a second, redundant remote access channel. PaperCut noted that observed behaviour includes the pc-app.exe process launching child shell processes and running whoami and ver, with endpoint protection in some cases preventing further execution and isolating the machine.

1 source

Time · lag behind first