logo

Attackers plant remote access tools on compromised PaperCut servers

ID: 575ed066-3096-5460-86a4-6aa73ff880f2

STIX ID: report--575ed066-3096-5460-86a4-6aa73ff880f2

Feed Name: Help Net Security

Threat Score
85/100

Date Published: 2026-08-31

Date Updated: 2026-09-01

Author: Zeljka Zorz

...
...

PaperCut disclosed active, in-the-wild exploitation of two zero-day vulnerabilities in PaperCut NG/MF that allowed unauthenticated attackers to bypass authentication and execute arbitrary Java bytecode on Application Servers; attackers used this access to enumerate domain information and silently install remote access software (SimpleHelp and AnyDesk). PaperCut issued emergency patches (multiple rounds), advised restricting web access to trusted IPs, preserving forensic evidence, and rebuilding compromised servers; observed IOCs include a Windows service named "Remote Access Service" running SimpleService.exe from C:\ProgramData\JWrapper-Remote Access\JWAppsSharedConfig\restricted and unexpected AnyDesk installations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.