Original image source: bleepstatic.com
A threat actor, presumably Russian-speaking, has launched an unprecedented global exploitation campaign, using hundreds of artificial intelligence (AI) agents to compromise vulnerable PaperCut NG/MF servers. The campaign, detected by threat intelligence company GreyNoise, highlights the speed and scale that AI tools can give cyber attackers.
Origin and Methodology of the Attack
The campaign began on August 31, combining AI models such as OpenAI’s Codex and DeepSeek with commercial offensive tools. The AI agents were programmed to build, test and refine exploits for the CVE-2026-81578 and CVE-2026-82078 vulnerabilities, both affecting the PaperCut software and listed as actively exploited earlier this month. Additionally, AI agents generated target lists using the Netlas internet scanning platform.
Impact of the Campaign
According to data from GreyNoise, the operation has compromised at least 440 PaperCut instances, linked to 395 different organizations in 48 countries. The attackers managed to:
- Collect credentials from 280 victims.
- Obtain operating system or domain secrets from 147 victims.
- Acquire administrator privileges in 12 organizations.
The education sector was the most affected, accounting for approximately half of all gaps. The United States was the most targeted country, followed by the United Kingdom, France, Spain and Canada. Interestingly, the threat actor specified a list of countries to avoid (including Russia, China, Iran, Ukraine, Belarus, Moldova, Brazil, and South Africa), although the agents did not always follow these guidelines.
AI-Driven Speed
GreyNoise emphasizes how AI enables rapid attacks, leaving defenders with extremely tight response margins. The researchers observed astonishing efficiency:
- The adversary went from an empty workspace to achieving remote code execution (RCE) on a real victim in less than four hours.
- Obtained domain administrator privileges in an additional two hours.
- Once the full campaign was launched, it engaged at least 11 organizations in just 26 seconds.
- In one case, the attacker went from initial access to becoming a full domain administrator in seven minutes against a high school in the United States.
Post-Exploitation Tactics
After exploiting the PaperCut vulnerabilities, researchers observed three main attack paths:
- Dumping of LSASS memory and registry secrets: From domain-joined PaperCut servers, using pass-the-hash attacks with recovered credentials to access domain controllers.
- “noPac” attack: Targeted at environments still vulnerable to CVE-2021-42278 and CVE-2021-42287.
- Direct account addition: When PaperCut was running on a domain controller or under a domain administrator service account, the attacker would directly add a newly created account to the domain administrators.
In all cases, the attackers used the DCSync post-exploitation technique to obtain a full dump of NTDS.DIT with domain credentials.
Attacker’s Tools
The toolkit used by the threat actor included well-known offensive tools such as Ligolo-ng, Mimikatz, Certipy, BloodHound, Rubeus, Impacket, NetExec, and custom credential harvesting utilities developed in Rust.
Objective and Recommendations
Although GreyNoise could not determine the ultimate objective of the campaign, the access obtained could be used for data theft or ransomware operations.
System administrators are strongly recommended to immediately apply PaperCut emergency security updates that address the CVE-2026-81578 and CVE-2026-82078 vulnerabilities, and to follow the vendor’s recommendations in its official bulletin.
Confidence
What would we do in these cases?
Defensive Cybersecurity | Protection and Response to Threats - Comfidentia
Defensive cybersecurity services: digital forensics, secure software development, vulnerability management, threat intelligence and incident response. Protect your networks and servers with our defensive security solutions.
Protect your business from digital threats with Defensive Cybersecurity from Comfidentia. Our comprehensive services provide you with robust protection against cyberattacks, helping you ensure the security of your sensitive data.
Forensic Analysis
Discover the truth hidden in the data with our Forensic Analysis service. We collect, examine and thoroughly analyze every digital trace to reveal the root cause of any incident. Our team of experts follows the key steps: Identification, Acquisition, Analysis and Presentation of solid evidence. Don’t waste any more time searching for answers, trust our experience to reveal the evidence you need.
Vulnerability Management
Don’t risk the security of your company! With our Vulnerability Management solutions, you won’t just get a simple scan or risk assessment, but a complete assessment together with your team. Our approach goes further by proposing real and lasting solutions, adapted to the specific capabilities and needs of your business and systems.
Protect your Brand from Cyber Threats
Protect your business today with Brand Intelligence! Our specialized service provides you with valuable information about possible malicious actors trying to impersonate your brand or domain. By detecting these threats, you can take quick and effective measures to safeguard your company’s reputation. Don’t let cybercriminals damage your image, trust Brand Intelligence to keep your business safe at all times.
Secure Software Development
With our specialized tools and skills, you can create vulnerability-proof applications and programs from start to finish. Our approach is based on a robust model that includes secure design, development process, vulnerability management and information security. This ensures that your software is protected at every stage of the process. Source: See more at Comfidentia
Other related pages:
Schedule a presentation with Comfidentia
References
Original source: See original article
- CVE-2026-81578
- CVE-2026-82078
- CVE-2021-42278
- CVE-2021-42287
- GreyNoise
Conclusion
The PaperCut NG/MF exploitation campaign powered by AI agents marks a worrying milestone in the cyber threat landscape. It demonstrates how artificial intelligence can be used to accelerate and escalate attacks, dramatically shortening reaction time for defenders. The unprecedented speed achieved by these AI agents underscores the urgency of adopting proactive security measures and rigorous patch management to protect critical infrastructure.