AI-Powered Campaign Exploits PaperCut Flaws, Compromising 395 Organizations Globally
A sophisticated, likely Russian-speaking, threat actor has leveraged hundreds of AI agents to orchestrate a rapid, global exploitation campaign against vulnerable **PaperCut NG/MF** servers. This operation successfully compromised 395 distinct organizations across 48 countries, demonstrating the accelerating pace of AI-driven attacks and the critical need for immediate patching.
A new report from attack and threat intelligence company **GreyNoise** details an alarming campaign where a threat actor, believed to be Russian-speaking, utilized hundreds of AI agents to develop and launch exploits. The target: vulnerable **PaperCut NG/MF** servers.
The AI agents were specifically tasked with building, testing, and refining exploits for **CVE-2026-81578** and **CVE-2026-82078**. These security flaws, affecting **PaperCut Software**, had been previously flagged as actively exploited.
### AI Orchestration and Attack Velocity
**GreyNoise** indicates the campaign commenced on August 31, combining **OpenAI's Codex** and **DeepSeek** models with readily available offensive tools. The AI agents also generated target lists by leveraging the **Netlas** internet scanning and discovery platform.
This AI-driven approach significantly accelerated the attack timeline. **GreyNoise** noted, "The adversary went from an empty workspace to first achieving RCE against a real victim in just under four hours, first domain admin in an additional two hours, and once the full campaign launched, compromised at least 11 organizations in 26 seconds."
In one particularly rapid instance, the adversary achieved full domain administrator privileges against a U.S. high school in a mere seven minutes.
.jpg)
### Scope of Compromise
**GreyNoise** data reveals that the operation compromised at least 440 **PaperCut** instances, affecting 395 unique organizations across 48 countries. The impact was significant:
* Credentials harvested from 280 victims.
* Operating system or domain secrets obtained from 147 organizations.
* Administrator privileges secured at 12 organizations.
The education sector bore the brunt of these attacks, accounting for approximately half of all breaches. The United States was the most frequently targeted country, followed by the United Kingdom, France, Spain, and Canada.
Interestingly, the threat actor specified a list of countries to avoid, including Russia, China, Iran, Ukraine, Belarus, Moldova, Brazil, and South Africa. However, the AI agents did not consistently adhere to these directives.
### Attack Paths and Post-Exploitation Techniques
After successfully exploiting the **PaperCut** flaws, the researchers observed three primary attack paths:
1. **Dumping LSASS memory and registry secrets** from domain-joined **PaperCut** servers, followed by passing recovered credential hashes to domain controllers (a "pass-the-hash" attack).
2. Utilizing the "noPac" attack against environments still vulnerable to **CVE-2021-42278** and **CVE-2021-42287**.
3. Directly adding a newly created account to **Domain Admins** when **PaperCut** ran on a domain controller or under a domain administrator service account.
In all observed cases, the attackers employed the **DCSync** post-exploitation technique to obtain a complete **NTDS.DIT** dump containing domain credentials.
### Attacker Toolkit
The threat actor's toolkit was robust, featuring a range of well-known offensive security tools including **Ligolo-ng**, **Mimikatz**, **Certipy**, **BloodHound**, **Rubeus**, **Impacket**, **NetExec**, and custom **Rust** credential-collection utilities.
While **GreyNoise** could not definitively ascertain the campaign's ultimate objective, the level of access achieved could facilitate data theft or ransomware operations.
### Recommendations for Defenders
System administrators are strongly advised to apply **PaperCut**'s emergency security updates addressing **CVE-2026-81578** and **CVE-2026-82078** immediately. Furthermore, it is crucial to follow the vendor's recommendations outlined in their security bulletin.