Skip to main content
Emerging ThreatsMalware & Ransomware

AI Agents Fuel PaperCut Attacks at Scale

Empty office print room with multifunction printers and scattered papers.

At least 440 instances of PaperCut MF/NG were compromised after a suspected Russian‑speaking actor unleashed "hundreds of AI Agents" to automate exploit development, targeting and post‑exploit operations, according to independent reporting by Blackpoint Cyber and GreyNoise.

The exploited vulnerabilities: CVE-2026-81578 and CVE-2026-82078

The campaign centers on a two‑part chain: CVE-2026-81578 and CVE-2026-82078, described in the reporting as an authentication bypass followed by remote code execution against PaperCut NG/MF. The attacks primarily hit the education sector across the U.S., the U.K., France, Spain, Canada, Belgium, Portugal, Australia, Germany and Switzerland, with victims ultimately identified in 48 countries.

AI agents, open-source tools, and a persistent feedback loop

GreyNoise and Blackpoint detail an architecture in which AI sat at the center of an end‑to‑end exploitation pipeline. After gaining initial remote code execution in a lab, the actor launched "hundreds of AI Agents powered by OpenAI Codex, a DeepSeek model," alongside publicly available offensive security tools such as Mimikatz, SharpHound, Certipy, Rubeus and Impacket. Arctic Wolf observed "delivery of Windows registry hive collection tools, Metasploit/Meterpreter‑related Java payloads, and commands used to identify hosts, users, processes, and sensitive configuration data."

Blackpoint emphasized that the most consequential AI impact was operational: automating research, debugging, classification, retry logic and continuous improvement so that fewer humans were required to scale exploitation. The project preserved context across cycles, converting vulnerability research into validated exploits, then into target expansion and operational execution through an iterative development process.

Infrastructure and attribution: the 45.142.193[.]132 pivot

Multiple vendors linked the activity to a single IP, 45.142.193[.]132, which GreyNoise says it tracked since early July 2026 for probing internet‑facing systems from vendors including Palo Alto, Ubiquiti, Citrix, SonicWall and Proxmox VE. Arctic Wolf also flagged the same IP in relation to the activity, while Blackpoint traced an exposed operator infrastructure that shows an AI‑assisted workflow from vulnerability research to repeated retry waves.

GreyNoise attributed the operator as "suspected Russian‑speaking" based on the evidence presented in its reporting. The firm further reported the attacker built and attacked a lab environment that included the vulnerable PaperCut software and an Active Directory server to validate exploits and harvest credentials.

Tempo, scale and measured restraint

The campaign moved quickly. GreyNoise reported the attacker went from an empty workspace to first achieving remote code execution against a real victim in just under four hours; once the campaign began in earnest it compromised at least 11 organizations in 26 seconds. In one case targeting a U.S. high school, the firm observed the time from initial access to full domain administrator access was seven minutes.

Overall, GreyNoise and Blackpoint say the actor compromised no less than 440 PaperCut instances hosted by 395 identified victim organizations. The adversary gained domain administrator access against 12 victim organizations. GreyNoise noted the attacker explicitly attempted to avoid targeting entities in 28 identified countries — including Russia, China, Hong Kong, Thailand, Iran, Venezuela, Indonesia, Pakistan and Bangladesh — but that "the attempted restraint failed in some instances." The actor also used Netlas.io with an identified API key to build target lists and applied geolocation and exclusion filters during targeting.

What this means for technologists, policymakers, and affected organizations

  • Technologists and security teams: The operation shows AI can automate not only exploit generation but entire campaign management — from filtering and geolocation to retry logic and post‑exploit workflows — reducing human labor and increasing scale. Blackpoint noted the campaign used tools such as Hindsight (a persistent memory service for AI agents) and AionUi (a unified graphical workspace) to preserve state and run multiple agents concurrently.
  • Procurement and affected organizations in education: The campaign's focus on PaperCut MF/NG and education customers underlines the need to inventory exposed PaperCut instances and prioritize timely patching or mitigation for CVE-2026-81578 and CVE-2026-82078. Blackpoint documented an iterative validation tool that quickly scaled attacks after comparing patched and unpatched builds beginning August 31.
  • Policymakers and incident response leaders: The actor's speed — from lab validation to broad exploitation — and use of widely available AI models raises questions about automated attribution, cross‑border targeting policies, and how to interrupt AI‑driven exploit pipelines before they move from access development to follow‑on objectives such as data theft or ransomware.

The attacker's apparent end goals remain unclear. As GreyNoise put it: "It is unclear if this actor is solely focused on access development to be handed off to other affiliated actors or if they will directly leverage their accesses to achieve follow‑on objectives such as data theft or ransomware deployment." That question — whether the compromised access points are a commodity to sell, a staging ground for extortion, or both — is the next concrete risk to monitor as defenders trace recovery and containment efforts.

Source: The Hacker News