RAT Malware Is Targeting Small Businesses: Your Printer Network Could Be the Entry Point
Three major RAT malware campaigns are hitting small businesses in early 2026. Learn how Remote Access Trojans can infiltrate through your printer network and what to do about it.
In the first weeks of 2026, cybersecurity researchers have identified three separate RAT (Remote Access Trojan) campaigns actively targeting small and medium businesses. If the term "RAT" is new to you, it should scare you — and here's why your office printer makes it worse.
What Is a RAT?
A Remote Access Trojan gives an attacker complete control of your computer — as if they were sitting at your desk. They can:
- Watch your screen in real-time
- Log every keystroke (including passwords)
- Access files and databases
- Turn on your webcam and microphone
- Use your computer to attack other devices on your network
- Install ransomware when they're done
For a detailed breakdown of how RATs work and how to protect yourself, the team at RAT Warning has put together comprehensive guides specifically for small businesses.
The Three Active RAT Campaigns in Early 2026
1. Amnesia RAT (January 2026)
This campaign uses GitHub and Dropbox — services your company probably trusts and allows through your firewall — to deliver malware. The attack flow:
- Employee receives a phishing email with a link to a GitHub repository
- The link downloads a script that disables Microsoft Defender
- Once defenses are down, Amnesia RAT is deployed
- The RAT enables credential theft, session hijacking, and eventually ransomware
Why printers matter: Once Amnesia RAT is on any device on your network, it scans for other connected devices. Printers are typically the least secured devices on any network — no endpoint protection, default passwords, outdated firmware. A compromised printer becomes a persistent foothold that's nearly invisible to standard security monitoring.
2. Remcos RAT via SHADOW#REACTOR (January 2026)
This campaign uses multi-stage attack chains specifically designed to evade detection on Windows systems. The initial payload arrives via email, then:
- Deploys through a series of obfuscated scripts
- Establishes persistence through Windows registry modifications
- Installs Remcos RAT for full remote access
3. NetSupport RAT via Bloody Wolf (February 2026)
The Bloody Wolf threat group is targeting manufacturing, finance, and IT sectors with spear-phishing emails deploying NetSupport RAT. About 50 businesses have been confirmed as victims so far.
How Your Printer Makes RAT Attacks Worse
Most people think of their printer as an output device. In reality, a modern multifunction printer is a Linux or embedded Windows computer with:
- A hard drive or SSD (storing copies of every document printed/scanned)
- Network connectivity (wired and wireless)
- Email capabilities (scan-to-email, fax-to-email)
- Web server (the admin interface)
- Sometimes Bluetooth
When a RAT compromises any device on your network, here's how the printer becomes a liability:
The Printer as Pivot Point
An attacker with a RAT on an employee's workstation can use the printer to:
- Intercept documents — Monitor everything being printed or scanned
- Steal stored data — Access documents cached on the printer's storage
- Establish persistence — Install a backdoor on the printer's embedded OS that survives workstation cleanup
- Exfiltrate data — Use the printer's email capabilities to send data out, bypassing standard DLP monitoring
- Move laterally — Use the printer's network connections to reach other network segments
The Printer as Initial Foothold
Even scarier: if your printer has a web-facing admin interface (and many do, especially if remote management is enabled), it can be the first device compromised — before the RAT even reaches a workstation.
5 Steps to Protect Your Printer Network from RATs
1. Network Segmentation
Put your printers on their own VLAN (virtual network segment). This means that even if a workstation is compromised, the attacker can't easily reach the printers — and vice versa. Your router or managed switch should support this; if it doesn't, it's time for an upgrade.
2. Disable Unnecessary Services
Turn off: - Remote management (unless you absolutely need it) - FTP services - Telnet - SNMPv1/v2 (use v3 with authentication if needed) - Unused protocols (IPX, AppleTalk, etc.)
3. Update Firmware and Change Default Passwords
This sounds basic, but only 36% of IT teams are patching printer firmware promptly according to CIO Dive. Set a quarterly reminder to check for firmware updates.
4. Monitor Printer Network Traffic
Your printer should only communicate with: - Devices that need to print to it - Your email server (for scan-to-email) - The manufacturer's update server
If it's talking to anything else — especially external IP addresses — you have a problem.
5. Enable Printer Access Controls
Most business-grade printers support: - PIN-based printing (pull printing) - User authentication via Active Directory - Print job encryption - Secure print release
These features prevent a RAT from intercepting documents in the print queue.
---
Want to know if your printer network is vulnerable to RAT-based attacks? Valley Printer Pros offers security assessments for San Fernando Valley businesses. We'll check your network segmentation, printer configuration, and firmware status. For deeper cybersecurity guidance, Wisetechy Solutions provides comprehensive IT security audits, and RAT Warning has free resources on protecting against Remote Access Trojans.
Call us at (818) 574-8240 — your printers shouldn't be the weakest link in your security chain.
---
Sources: The Hacker News, Securonix SHADOW#REACTOR Analysis, CIO Dive Printer Security Report, Quocirca Print Security Landscape 2024
About Valley Printer Pros Team
Our team of printer industry experts brings decades of experience helping small businesses optimize their printing operations. We provide unbiased advice and practical solutions that save money and improve productivity.
Get Expert AdviceServing San Fernando Valley Businesses
We provide on-site printer consulting, setup, and lease escape support across the Valley:
Related Articles
On September 17, HP Wolf Security reported phishing emails with PDF "invoices" blurred behind a QR code that tells staff to scan it with their phone, leading to a fake Microsoft sign-in page. Tell accounts-payable staff never to scan QR codes in unexpected invoices, verify invoices by phone, and protect Microsoft 365 with MFA.
Microsoft's September 8, 2026 Patch Tuesday fixed a Critical (CVSS 9.8) Windows HTTP Print Provider flaw, CVE-2026-69769, that needs no sign-in or click, plus Print Spooler privilege bugs. None were exploited, and the month's zero-days weren't print-related. Test the September cumulative update on one PC, then install it everywhere.
On August 27, PaperCut warned that attackers were exploiting flaws in its NG and MF print-management software, and on August 31 CISA listed both chained bugs as actively exploited. Ask your copier dealer whether you run PaperCut, restrict its admin page to trusted addresses, patch versions 24 to 26, and upgrade anything older.
Need Help with Your Printer Decisions?
Don't navigate printer purchases, leases, or problems alone. Our experts provide unbiased advice tailored to your specific business needs.