Trinity Cyber
Preventing Active PaperCut Exploitation
Pages
8
Time to read
10 mins
Publication
Language
English
Pages
8
Time to read
10 mins
Publication
Language
English
This technical report details the discovery of anomalies in customer traffic related to a PaperCut server, specifically linked to the exploitation by the APT group FIN11. The report outlines the steps taken by Trinity Cyber to prevent a ransomware attack, including the development of automated detections and mitigations. It describes how attackers exploited an internet-facing PaperCut server despite previous patches, leading to the execution of custom JavaScript code that downloaded a Remote Monitoring and Management agent. The report provides a breakdown of the attack stages, including remote authentication bypass, enabling print scripting, and disabling script sandboxing. It emphasizes the importance of applying available patches to mitigate vulnerabilities. The document also includes technical details to assist detection engineering efforts, while explicitly stating that the use of this information for offensive purposes is not permitted. Overall, the report serves as a case study on the methods used by ransomware actors and the proactive measures taken to protect clients from such threats.