AI Agents Power PaperCut Exploitation Campaign Hitting 395 Organizations

A threat actor, likely Russian-speaking, deploys hundreds of AI agents to exploit vulnerabilities in PaperCut NG/MF print management software, compromising at least 440 server instances tied to 395 distinct organizations across 48 countries. According to attack intelligence firm GreyNoise, the campaign begins on August 31 and combines OpenAI's Codex and DeepSeek models with commodity offensive tools. The AI agents build, test, and refine exploits for CVE-2026-81578 and CVE-2026-82078, and generate target lists using the Netlas internet scanning platform.

The attackers harvest credentials from 280 victims, obtain operating system or domain secrets from 147, and gain administrator privileges at 12 organizations. Education accounts for roughly half of all breaches, with the United States the most targeted country, followed by the United Kingdom, France, Spain, and Canada. The threat actor specifies a list of countries to avoid, including Russia, China, Iran, and Ukraine, though the AI agents do not consistently follow these rules. GreyNoise warns that AI enables attacks at a pace that leaves defenders with extremely tight response margins.

The speed of the operation stands out: the adversary goes from an empty workspace to remote code execution against a real victim in under four hours, achieves first domain admin two hours later, and compromises at least 11 organizations in just 26 seconds once the campaign fully launches. In one case, the attacker moves from initial access to full domain administrator in seven minutes against a U.S. high school. Researchers observe three attack paths, including LSASS memory dumping with pass-the-hash attacks, the noPac technique against environments still vulnerable to older CVEs, and directly adding new accounts to the Domain Admins group.

Read More at the original source →