PaperCut Attacker Uses Hundreds of AI Agents to Compromise 440+ Instances
GreyNoise and Blackpoint tracked an AI-assisted actor using OpenAI Codex and DeepSeek agents to exploit PaperCut flaws across 440+ instances in 48 countries.
A suspected Russian-speaking actor exploited the CVE-2026-81578 authentication bypass and CVE-2026-82078 RCE chain in PaperCut NG/MF, compromising at least 440 instances across 395 organizations in 48 countries, heavily targeting education in the US, UK, France, and elsewhere. The actor used hundreds of AI agents powered by OpenAI Codex and DeepSeek plus tools like Mimikatz, SharpHound, Certipy, Rubeus, and Impacket, reaching domain admin at 12 victims and full domain admin at a US high school within seven minutes. Post-exploitation included registry hive collection and Metasploit/Meterpreter payloads, with origin traced to IP 45.142.193.132.
- Exploits CVE-2026-81578 and CVE-2026-82078 in PaperCut NG/MF
- 440+ instances compromised across 395 organizations in 48 countries
- Hundreds of AI agents (OpenAI Codex, DeepSeek) drove the exploit pipeline
- Attack framework used Hindsight memory and AionUi workspace
- Post-exploitation used Mimikatz, SharpHound, Certipy, Rubeus, Impacket
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-82078 +1 in the same advisory: …81578 | Unsafe Reflection RCE in PaperCut NG/MF, Chained with Auth Bypass in Attacks CVE-2026-82078 is an unsafe dynamic class loading flaw (unsafe reflection, CWE-470) in the database connection utilities of PaperCut NG and PaperCut MF: the software instantiates a database driver class based on a configurable driver name without validating it against an allowlist of approved drivers. An attacker who can manipulate system configuration parameters can point that setting at classes of their choosing, causing the server to execute arbitrary Java bytecode residing on the application classpath in the security context of the PaperCut server process. On its own the issue is rated 9.4 (Critical) with high privileges required, but when chained with the companion authentication bypass CVE-2026-81578 it yields unauthenticated remote code execution on the print-management server. All PaperCut NG and MF deployments are in scope; affected version ranges were not specified in the available data, so administrators should consult PaperCut's advisory for fixed versions. The flaw is confirmed exploited in the wild as a zero-day: it was added to CISA's KEV catalog on 2026-08-31, and public reporting describes an AI-orchestrated campaign that compromised PaperCut servers at roughly 395 organizations (~440 servers), with EPSS currently at 1.7% (76th percentile). Do: Upgrade PaperCut NG and MF to the patched release specified in PaperCut's security advisory (exact fixed versions were not provided in this data), prioritizing internet-exposed print servers; the KEV listing means agencies must remediate per CISA BOD 26-04 or discontinue/mitigate per its cloud-service guidance. Restrict the PaperCut web interface from direct internet exposure (VPN/allowlist), review administrator accounts and database driver configuration for tampering, and hunt for post-exploitation activity, since this flaw is being actively chained with the authentication bypass CVE-2026-81578. | 9.4 group max | 2% | KEV |
| mass≈100,000+ organizations / plausibly millions of end users (vendor-cited install base); tens of thousands of on-prem servers with a smaller but significant… |
Full article1,016 words · extracted from thehackernews.com · click to collapse
A suspected Russian-speaking cyber actor has been attributed to the use of artificial intelligence (AI) to devise exploits targeting a recently disclosed pair of security flaws in PaperCut NG/MF and break into hundreds of instances.
According to independent reports from Blackpoint Cyber and GreyNoise, the activity originates from "45.142.193[.]132," an IP address that has been linked to unauthorized port scanning and brute-force attack attempts in recent weeks. It's worth noting the same IP address was also flagged by Arctic Wolf in connection with the same activity last week.
At its core, the opportunistic attacks exploit CVE-2026-81578 and CVE-2026-82078, a combination of an authentication bypass and remote code execution chain, to mainly target the education sector in the U.S., the U.K., France, Spain, Canada, Belgium, Portugal, Australia, Germany, and Switzerland.
"Observed post-exploitation activity included delivery of Windows registry hive collection tools, Metasploit/Meterpreter-related Java payloads, and commands used to identify hosts, users, processes, and sensitive configuration data," Arctic Wolf noted.
GreyNoise said it has been tracking the malicious use of the IP address since early July 2026 for probing internet-facing systems from vendors, including Palo Alto, Ubiquiti, Citrix, SonicWall, and Proxmox VE.
"As part of the adversary's exploit development and testing, they built and attacked a lab environment that included the vulnerable PaperCut software and an Active Directory server," the threat intelligence firm said. "In parallel workflows, the adversary built target lists using an internet scanning service Netlas.io using an identified API key."
Upon gaining remote code execution and credential harvesting within its self-hosted lab environment, the threat actor has been observed unleashing hundreds of AI Agents powered by OpenAI Codex, a DeepSeek model, and publicly available offensive security tools (e.g., Mimikatz, SharpHound, Certipy, Rubeus, and Impacket) to compromise no less than 440 instances of PaperCut MF/NG hosted by 395 identified victim organizations in 48 countries.
"There are other real victims that could not be attributed to a named organization," GreyNoise added. "The adversary did explicitly attempt to avoid targeting entities in 28 identified countries; however, our observed victimology shows the attempted restraint failed in some instances." Some of the countries added to the exclusion list include Russia, China, Hong Kong, Thailand, Iran, Venezuela, Indonesia, Pakistan, and Bangladesh.
The findings come at a time of considerable concern over how AI models are enabling bad actors to integrate agentic capabilities into various stages of an attack lifecycle, and help them accelerate and conduct attacks at scale.
According to GreyNoise, the attacker swiftly progressed from an empty workspace to first achieving remote code execution against a real victim in just under four hours, and compromised at least 11 organizations in 26 seconds once the campaign began in earnest. In one attack targeting a high school in the U.S., the duration between initial access and full domain administrator access was a mere seven minutes.
In all, the adversary is said to have gained domain administrator access against only 12 victim organizations. The attacker's end goals remain unclear at this stage.
"It is unclear if this actor is solely focused on access development to be handed off to other affiliated actors or if they will directly leverage their accesses to achieve follow-on objectives such as data theft or ransomware deployment," GreyNoise said.
More Details Emerge
Blackpoint, which shared additional details of the same activity, said it traced it back to an exposed operator infrastructure that depicts the AI-assisted workflow from vulnerability research and exploit development to execution through target filtering, failure analysis, code changes, and repeated retry waves.
"The earliest recovered activity began on August 31, with the project focused on vulnerability research and comparing patched and unpatched PaperCut builds," researchers Sam Decker and Nevan Beal said. "Within hours, that research had been turned into a multi-threaded validation tool that was reviewed, tested, and run against progressively larger target sets."
The threat actor's use of AI also extends to the targeting pipeline, with recovered source code acting as a funnel that merges multiple source lists, geolocating candidates and filtering them by country, applying the aforementioned exclusion policy, and identifying live PaperCut systems before moving to the next stage.
In the final stage, the targets are categorized by operating system and environment, as well as through separate lists for those that are active, unreachable, missing specific stages, eligible for post-exploitation actions, and waiting for a retry, as opposed to treating every unsuccessful attempt as the same problem.
Complementing these efforts are Python scripts that keep track of the later stages and ensure they have actually completed. These include tasks like administrator access, account verification, Active Directory collection, domain and network discovery, and proxy setup. Failures are recorded, allowing the attack framework to adapt its approach and move forward.
The project is best understood as one where AI is the fulcrum around which the entire system architecture revolves, transforming vulnerability research into an exploitation pipeline via a persistent feedback loop that informs every cycle. Supporting the system in this effort are two crucial open-source tools -
Hindsight, which provides a persistent memory service for AI agents AionUi, which provides a unified graphical workspace to run and view multiple AI agents concurrently
The campaign shows threat actors are using AI not just to assist with malware development, but also to troubleshoot failures, preserve project state, and augment other operational aspects, thereby bringing down the manual effort required to pull off such an attack. These changes have a significant impact on the economics of cyber attacks, according to the cybersecurity company.
"The strongest AI impact in this campaign was not a novel exploit technique," Blackpoint said. "It was the reduction of human effort required to research, develop, debug, classify, track, retry, and continuously improve exploitation across hundreds of real systems."
"The operator was using an iterative development process in which AI-supported research, coding, testing, troubleshooting, and campaign execution continuously informed one another. Context was preserved as the project moved from vulnerability research to exploit validation, tooling development, target expansion, and eventually operational execution."
Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.
Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2026/09/papercut-attacker-uses-hundreds-of-ai.html