Skip to main content
Emerging ThreatsMalware & Ransomware

Hackers Actively Exploit PaperCut Flaw in Zero-Day Attacks

Office workspace with printer, computer, and paper supplies, under ordinary indoor lighting.

"PaperCut Software security response team is investigating active exploitation of a vulnerability affecting PaperCut NG and PaperCut MF," PaperCut wrote in an urgent security advisory published Thursday, adding that it is "aware of confirmed customer incidents and are treating this matter with the highest priority."

Active zero-day exploitation of PaperCut NG and MF

PaperCut has warned that attackers are actively exploiting a vulnerability in all versions of its PaperCut NG and PaperCut MF print management software in zero-day attacks. The company said it is aware of confirmed attacks on customers but has not published technical details about the flaw or the exploitation method.

Emergency patches and network mitigations

PaperCut released emergency patches targeted at customers with public-facing PaperCut NG/MF servers. The advisory frames these patches as a stopgap for organizations that cannot immediately apply other mitigations. For all customers with Internet-exposed PaperCut Application Servers, the company urged immediate restriction of access to the product web interfaces to trusted IP addresses and recommended using firewall rules or other network access controls to limit exposure.

Indicators of compromise PaperCut provided

To help administrators detect possible intrusions, PaperCut published a set of indicators of compromise. They include:

  • suspicious activity originating from the legitimate PaperCut process pc-app.exe;
  • server.log files that have been modified, deleted, or are missing;
  • specific error messages appearing in server.log such as "ERROR No suitable driver found for jdbc:no:x" and "ERROR DatabaseUtils - Database error looking up cardID: VALUES CAST".

PaperCut cautioned that the absence of these indicators does not guarantee a server has not been compromised.

Recent history: April 2023 vulnerabilities and downstream ransomware incidents

PaperCut's advisory placed the current alert against a backdrop of prior incidents. In April 2023, attackers exploited a critical PaperCut vulnerability tracked as CVE-2023-27350, which allowed unauthenticated attackers to bypass authentication and execute code remotely on vulnerable servers. Microsoft later linked some of those 2023 intrusions to the Clop ransomware operation and observed intrusions that led to LockBit ransomware attacks. The exploitation of CVE-2023-27350 was used by multiple actors; Microsoft reported that Iranian state-backed groups also exploited that flaw. In May 2023, CISA and the FBI issued a joint advisory warning that the Bl00dy Ransomware Gang was exploiting vulnerable PaperCut servers in attacks against the education sector.

PaperCut's Print Archiving feature can retain documents sent through a server, but Clop told BleepingComputer during the previous incident that it had used the vulnerabilities primarily for initial access to victim networks rather than to steal archived documents directly from PaperCut servers.

What this means for administrators, procurement leaders, and security teams

  • Administrators and security teams: Treat Internet-exposed PaperCut Application Servers as high priority. Apply the emergency patches if servers are public-facing and implement network restrictions that limit access to trusted IP addresses. Review server.log for the specific error messages PaperCut published and monitor activity of the pc-app.exe process.
  • Procurement and IT decision-makers: Review public-facing deployments and procurement configurations that allow server exposure. Where immediate patching or network controls are impractical, consider isolating or taking affected Application Servers offline until mitigations are in place.
  • Incident response teams: Do not rely solely on the published indicators; PaperCut explicitly warns that lack of those indicators does not prove absence of compromise. Prepare to investigate modified or missing server.log files and to treat confirmed incidents with urgency.

PaperCut said it reproduced the vulnerability using information provided by a University customer and that it will continue to update its advisory with additional indicators and remediation guidance as the investigation continues. BleepingComputer contacted PaperCut with questions about the exploitation and said it would update its story when PaperCut responds. At this time PaperCut has not disclosed the identity of the attackers, the post-compromise actions observed, or whether data exfiltration has occurred.

The episode underscores a persistent pattern: published vulnerabilities in PaperCut software have previously been weaponized quickly and broadly, with subsequent criminal ransomware operations exploiting those access points. For organizations running PaperCut NG or MF with any Internet exposure, the company’s immediate guidance is simple and stark — restrict access to trusted IPs, apply emergency patches where needed, and hunt for the indicators PaperCut has shared while recognizing those indicators may not tell the whole story.

Original story