VMTech
Discuss a project

AI Agents Used in Campaign Against More Than 440 PaperCut Instances

AI Agents Used in Campaign Against More Than 440 PaperCut Instances

AI-assisted PaperCut campaign reaches hundreds of systems

A suspected Russian-speaking threat actor used hundreds of AI agents to compromise at least 440 PaperCut NG/MF instances belonging to 395 identified organizations in 48 countries. The activity exploited CVE-2026-81578 and CVE-2026-82078, described as an authentication-bypass and remote-code-execution chain affecting PaperCut products.

Independent reporting by Blackpoint Cyber and GreyNoise linked the activity to the IP address 45.142.193[.]132, which had also been associated with port scanning and brute-force attempts. Arctic Wolf flagged the same address in connection with the campaign. The attacks primarily targeted education-sector organizations in the United States, United Kingdom, France, Spain, Canada, Belgium, Portugal, Australia, Germany and Switzerland.

GreyNoise said the operator used a self-hosted lab containing vulnerable PaperCut software and an Active Directory server. It also observed the actor building target lists through Netlas.io with an identified API key before progressing to attacks on internet-facing systems.

Automation extended beyond exploit development

After obtaining remote code execution and harvesting credentials in the lab, the actor deployed AI agents powered by OpenAI Codex and a DeepSeek model. The workflow also incorporated publicly available offensive security tools including Mimikatz, SharpHound, Certipy, Rubeus and Impacket.

Arctic Wolf observed post-exploitation activity involving Windows registry-hive collection tools, Metasploit/Meterpreter-related Java payloads, and commands used to identify hosts, users, processes and sensitive configuration data. GreyNoise said the campaign compromised at least 11 organizations in 26 seconds after it began in earnest. In one attack against a U.S. high school, the time from initial access to full domain administrator access was seven minutes.

The actor gained domain administrator access at 12 victim organizations. Its final objectives remain unclear: GreyNoise said it could be developing access for affiliated actors or could later use that access for objectives such as data theft or ransomware deployment.

Persistent feedback loop reduced manual effort

Blackpoint Cyber traced recovered activity to August 31, when the project focused on comparing patched and unpatched PaperCut builds. Within hours, that work became a multi-threaded validation tool that was reviewed, tested and used against increasingly large target sets.

Recovered code merged target lists, geolocated candidates, applied country filtering and identified live PaperCut systems. Targets were then separated by operating system, environment and execution status, including active, unreachable, incomplete, post-exploitation eligible and retry categories. Python scripts tracked later tasks such as administrator access, account verification, Active Directory collection, domain and network discovery, and proxy setup.

Blackpoint Cyber identified Hindsight as the persistent-memory service for the agents and AionUi as the graphical workspace for running and viewing multiple agents concurrently. The key operational change was not a new exploit method, but reduced human effort for researching, debugging, classifying, tracking and improving attacks across many systems. Businesses running PaperCut should prioritize applying relevant fixes, reducing internet exposure and investigating signs of credential collection, account discovery or unexpected administrator activity.

#cybersecurity#papercut#aiagents#vulnerability
Open analytics
On the site 0 views
min read 4 10.09.2026
Instagram

AI Agents Used in Campaign Against More Than 440 PaperCut Instances

Open the post on Instagram ↗