ZeroHour
GBHackerspublished ()ingested Divya1
Part of a story covered by 9 sources: “AI-powered attack exploited PaperCut flaws to hack 395 organizations” — merged summary and timeline →

Hackers Deploy Hundreds of AI Agents to Compromise 440 PaperCut Servers

AI summary · glm-5.3-flash

AI-agent campaign exploited PaperCut CVE-2026-81578 and CVE-2026-82078, compromising 440 servers at 395 organizations and reaching Domain Admin in 12.

GreyNoise tracked a likely Russian-speaking actor that used AI agents (OpenAI Codex, a DeepSeek model) to exploit an authentication bypass (CVE-2026-81578) and unsafe-reflection RCE (CVE-2026-82078) in PaperCut NG/MF starting August 31, 2026. At least 440 servers across 395 organizations in 48 countries were compromised, with one US high school going from initial access to Domain Admin in seven minutes. Escalation relied on LSASS and registry credential harvesting, pass-the-hash, the noPac technique (CVE-2021-42278/CVE-2021-42287), new Domain Admin accounts, and DCSync to steal NTDS.DIT data. Operators staged registry hives, used Ligolo tunneling and certutil Base64 encoding for exfiltration, and one attempt was blocked by Cloudflare WAF.

  • 440 PaperCut NG/MF servers compromised across 395 organizations in 48 countries since August 31, 2026
  • Actor validated exploits in a self-hosted lab and used OpenAI Codex plus DeepSeek to accelerate attack execution
  • Domain Admin reached in only 12 victims, with fastest escalation in five minutes; noPac and DCSync used
  • GreyNoise published IOCs including IPs 45.142.193.132 and 45.158.196.75, Rust LSA tools, and staged hive paths
  • Defenders urged to patch PaperCut, review Domain Admin group changes, and monitor DCSync, LSASS and certutil activity

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2021-42287
+1 in the same advisory: …42278
Privilege Escalation in Microsoft Active Directory Domain Services

CVE-2021-42287 is an elevation-of-privilege vulnerability in Microsoft Active Directory Domain Services (AD DS) affecting multiple supported Windows Server releases. An attacker with any low-privileged domain account can trigger it — commonly in combination with the related sAMAccountName spoofing flaw CVE-2021-42278 — by manipulating account name attributes so the Kerberos Key Distribution Center issues tickets that grant rights normally reserved for domain controllers. The result is escalation from a standard user to domain administrator, giving the attacker full control over the Windows domain, a capability that is directly useful for ransomware deployment and data theft. Any organization running Active Directory on the affected Windows Server versions is exposed, which amounts to essentially every enterprise Windows network. The flaw is actively exploited: it was added to CISA's Known Exploited Vulnerabilities catalog on 2022-04-11 with known ransomware use, and EPSS assigns it a 77.2% probability of exploitation within 30 days.

Do: Apply Microsoft's security updates to every domain controller — writable and read-only — as soon as possible (the fix shipped in Microsoft's November 2021 security releases), prioritizing internet-exposed and VPN-facing DCs. Hunt domain controller logs for anomalous Kerberos TGT requests by user accounts with domain-controller-style names (a hallmark of CVE-2021-42278/42287 abuse) and monitor for ransomware staging activity, given documented ransomware use.

7.577% KEV ransomware
  • microsoft windows server 2004 windows server 2004
  • microsoft windows server 2008 windows server 2008
  • microsoft windows server 2012 windows server 2012
  • +4 more
masswell over 100,000 Windows Server domain controllers and millions of domain users worldwide
CVE-2026-82078
+1 in the same advisory: …81578
Unsafe Reflection RCE in PaperCut NG/MF, Chained with Auth Bypass in Attacks

CVE-2026-82078 is an unsafe dynamic class loading flaw (unsafe reflection, CWE-470) in the database connection utilities of PaperCut NG and PaperCut MF: the software instantiates a database driver class based on a configurable driver name without validating it against an allowlist of approved drivers. An attacker who can manipulate system configuration parameters can point that setting at classes of their choosing, causing the server to execute arbitrary Java bytecode residing on the application classpath in the security context of the PaperCut server process. On its own the issue is rated 9.4 (Critical) with high privileges required, but when chained with the companion authentication bypass CVE-2026-81578 it yields unauthenticated remote code execution on the print-management server. All PaperCut NG and MF deployments are in scope; affected version ranges were not specified in the available data, so administrators should consult PaperCut's advisory for fixed versions. The flaw is confirmed exploited in the wild as a zero-day: it was added to CISA's KEV catalog on 2026-08-31, and public reporting describes an AI-orchestrated campaign that compromised PaperCut servers at roughly 395 organizations (~440 servers), with EPSS currently at 1.7% (76th percentile).

Do: Upgrade PaperCut NG and MF to the patched release specified in PaperCut's security advisory (exact fixed versions were not provided in this data), prioritizing internet-exposed print servers; the KEV listing means agencies must remediate per CISA BOD 26-04 or discontinue/mitigate per its cloud-service guidance. Restrict the PaperCut web interface from direct internet exposure (VPN/allowlist), review administrator accounts and database driver configuration for tampering, and hunt for post-exploitation activity, since this flaw is being actively chained with the authentication bypass CVE-2026-81578.

9.4
group max
2% KEV
  • PaperCut NG
  • PaperCut MF
mass≈100,000+ organizations / plausibly millions of end users (vendor-cited install base); tens of thousands of on-prem servers with a smaller but significant…

Indicators of compromiseAll →

TypeIndicatorContext
domainnetlas.ioCut software and an Active Directory server. They also used Netlas.io to compile lists of potential targets. After validating the
ipv445.142.193.132he actors utilized infrastructure, including the IP address 45.142.193.132, which GreyNoise had tracked since early July for attacks a
ipv445.158.196.75paign orchestration and execution infrastructure IP address 45.158.196.75 Infrastructure used to execute campaign activity File hash
md5528cd4e69ecfa5191adbcf6ef28667bfInfrastructure used to execute campaign activity File hash 528cd4e69ecfa5191adbcf6ef28667bf lsa_read.exe — Rust LSA secret reader File hash ce870a91e8d
md5974decb9ff4c8f9ccb0937c96d513347sa_collect_small.exe — Rust LSA bootkey collector File hash 974decb9ff4c8f9ccb0937c96d513347 certipy.exe — Active Directory Certificate Services abuse t
md5a6437ac3d6798090a218520985d36a3f687abc60b04 save_hives.exe — registry hive dumper File hash a6437ac3d6798090a218520985d36a3f collect_custom.exe — Rust custom collection tool File hash
md5ce870a91e8d27e8f663f0687abc60b04f6ef28667bf lsa_read.exe — Rust LSA secret reader File hash ce870a91e8d27e8f663f0687abc60b04 save_hives.exe — registry hive dumper File hash a6437ac3d67
md5fc92dfafa7aa741c5f2b9cbcf75d1d19collect_custom.exe — Rust custom collection tool File hash fc92dfafa7aa741c5f2b9cbcf75d1d19 lsa_collect_small.exe — Rust LSA bootkey collector File has
urlhttp://45.142.193[ing followed by Base64 encoding using certutil Download URL hxxp://45.142.193[.]132:8000/lsa_collect.exe Download location for LSA bootkey
Full article813 words · extracted from gbhackers.com · click to collapse

Threat intelligence firm GreyNoise has identified an AI-driven intrusion campaign, likely orchestrated by a Russian-speaking threat actor, that compromised at least 440 PaperCut NG/MF servers across 395 organizations in 48 countries.

This campaign began on August 31, 2026, exploiting two vulnerabilities in PaperCut: CVE-2026-81578, an authentication bypass flaw, and CVE-2026-82078, a vulnerability that allows unsafe reflection of remote code execution.

The actors utilized infrastructure, including the IP address 45.142.193.132, which GreyNoise had tracked since early July for attacks against internet-facing systems from Palo Alto, Ubiquiti, Citrix, SonicWall, and Proxmox VE.

Hackers Deploy AI Agents

PaperCut NG and MF are attractive targets because they are commonly used domain-joined Java web applications that run with SYSTEM-level privileges on Windows.

In enterprise environments, these applications are often integrated with Active Directory, which could provide a pathway from a print management server to a broader domain compromise.

According to GreyNoise, the threat actor developed and tested exploits in a self-hosted lab that included vulnerable PaperCut software and an Active Directory server.

They also used Netlas.io to compile lists of potential targets. After validating their remote code execution and credential-harvesting techniques, the actor launched a global campaign using OpenAI Codex, a DeepSeek model, and publicly available offensive security tools.

The operation showed that agentic workflows can significantly accelerate attack execution. GreyNoise reported that the actor moved from an empty workspace to achieving remote code execution against a legitimate victim in less than four hours.

They reportedly escalated privileges to Domain Admin level two hours later. At their peak, the campaign compromised at least 11 organizations in just 26 seconds. One U.S. high school reportedly moved from initial access to full domain administrator compromise in just seven minutes.

Papercut Exploit (Source: Greynoise)
Papercut Exploit (Source: Greynoise)

However, the campaign’s success was inconsistent. While at least 440 PaperCut instances were compromised, GreyNoise observed that Domain Admin privileges were only obtained in 12 victim organizations.

The fastest escalation occurred in five minutes, while the longest took up to 144 minutes. In some instances, adversary actions stalled because operators did not proceed with post-exploitation activities promptly. Additionally, GreyNoise noted at least one attempt that Cloudflare’s Web Application Firewall thwarted.

Where the actor achieved Domain Admin access, it used three primary methods. They harvested LSASS process memory and registry secrets from domain-joined PaperCut servers to recover privileged credentials and conducted pass-the-hash attacks.

For organizations that had not patched for CVE-2021-42278 and CVE-2021-42287, they used the noPac privilege escalation technique. In other scenarios, particularly when PaperCut ran on a domain controller or under a Domain Admin service account, the attackers created a new account. They added it to the Domain Admins group.

Overall, the attackers utilized DCSync to obtain NTDS.DIT data, enabling them to steal Active Directory credential information. GreyNoise indicated that it remains unclear whether the campaign’s objective is focused solely on access brokering or if the actor intends to engage in data theft, extortion, or ransomware attacks directly.

Organizations are advised to immediately patch any affected PaperCut deployments, restrict administrative exposure, review changes to the Domain Admin group, investigate staged registry hives and Ligolo artifacts, and monitor for DCSync, LSASS access, suspicious registry save, and certutil activity.

IoC

TypeIndicatorDescription / Hunting Context
IP address45.142.193.132Campaign orchestration and execution infrastructure
IP address45.158.196.75Infrastructure used to execute campaign activity
File hash528cd4e69ecfa5191adbcf6ef28667bflsa_read.exe — Rust LSA secret reader
File hashce870a91e8d27e8f663f0687abc60b04save_hives.exe — registry hive dumper
File hasha6437ac3d6798090a218520985d36a3fcollect_custom.exe — Rust custom collection tool
File hashfc92dfafa7aa741c5f2b9cbcf75d1d19lsa_collect_small.exe — Rust LSA bootkey collector
File hash974decb9ff4c8f9ccb0937c96d513347certipy.exe — Active Directory Certificate Services abuse tool
AccountAdministrator17Account reportedly created by the adversary
File pathC:\Windows\Temp\pc-sys.hivStaged SYSTEM registry hive
File pathC:\Windows\Temp\pc-sec.hivStaged SECURITY registry hive
File pathC:\Windows\Temp\pc-security.hivStaged SECURITY registry hive
File pathC:\Windows\Temp\pc-system.hivStaged SYSTEM registry hive
File pathC:\ProgramData\pc-sys-reg.hivAlternate location for staged SYSTEM hive
File patternC:\Windows\Temp\pc-*.b64Base64-encoded registry hive chunks prepared for HTTP exfiltration
File pathC:\ProgramData\ligolo-agent.exeLigolo tunneling agent used for persistent or remote access
Exploitation artifact...\PaperCut MF\server\custom\web\pcp_<10rand>.txtPotential evidence of successful PaperCut exploitation
Command behaviorreg save HKLM\SYSTEMSYSTEM hive dumping followed by Base64 encoding using certutil
Command behaviorreg save HKLM\SECURITYSECURITY hive dumping followed by Base64 encoding using certutil
Download URLhxxp://45.142.193[.]132:8000/lsa_collect.exeDownload location for LSA bootkey collector
Download URLhxxp://45.142.193[.]132:8089/agent5.exeLigolo-ng payload location
File pathC:\ProgramData\LegitSvc\legit-svc.exeLigolo-ng executable masquerading as a legitimate service
File pathC:\ProgramData\LegitSvc\legit-svc-backup.exeAlternate Ligolo-ng service-related payload path

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Keep your SOC up to date on active malware & phishing within 24h of their emergence. Try ANYRUN to prevent incidents with early detection

Divya

Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.

Text extracted automatically; images, tables and formatting may be missing. Original: https://gbhackers.com/hackers-deploy-hundreds-of-ai-agents/