“The adversary went from an empty workspace to first achieving RCE against a real victim in just under four hours, first domain admin in an additional two hours, and once the full campaign launched, compromised at least 11 organizations in 26 seconds,” GreyNoise notes.
How GreyNoise tracked an AI-driven campaign that began August 31
Security researchers at GreyNoise attribute a rapid, automated global exploitation effort that started on August 31 to a likely Russian-speaking threat actor. The campaign used “hundreds of AI agents” combining OpenAI’s Codex and DeepSeek models with commodity offensive tools to build, test, refine and launch exploits against PaperCut NG/MF servers affected by two recently flagged flaws: CVE-2026-81578 and CVE-2026-82078. GreyNoise reported that the AI agents also relied on the Netlas internet scanning and discovery platform to generate target lists.
Exploited vulnerabilities and three clear attack paths
The operation exploited the two 2026 PaperCut vulnerabilities and, after initial code execution, followed one of three post-exploitation paths observed by GreyNoise:
- Dumping LSASS memory and registry secrets from domain-joined PaperCut servers, then passing recovered credential hashes to domain controllers in a “pass-the-hash” maneuver.
- Using a “noPac” attack against environments still vulnerable to CVE-2021-42278 and CVE-2021-42287.
- Directly adding a newly created account to Domain Admins when PaperCut was running on a domain controller or under a domain administrator service account.
In all cases, the attackers used the DCSync post-exploitation technique to obtain a complete NTDS.DIT dump containing domain credentials.

Nobody's watching your logs at 2 AM.
Full SOC coverage without building one. Nubivance deploys and manages Rapid7 InsightIDR and MDR for organizations that need detection and response, not another dashboard.
Get coverageScope: 440 PaperCut instances, 395 organizations, 48 countries
GreyNoise’s data indicates the campaign compromised at least 440 PaperCut instances linked to 395 distinct organizations across 48 countries. Most victims were in the education sector, which accounted for roughly half of all breaches. The United States was the most targeted country, followed by the United Kingdom, France, Spain, and Canada.
Credential harvesting and privilege escalation tallies reported by GreyNoise include credentials taken from 280 victims, operating system or domain secrets obtained from 147 victims, and administrator privileges attained at 12 organizations. The company could not determine the campaign’s objective, but noted the access could be used for data theft or ransomware operations.
Toolkit, automation limits, and geographic targeting quirks
GreyNoise documented a mix of off-the-shelf and bespoke tooling used by the attackers. The toolkit included Ligolo-ng, Mimikatz, Certipy, BloodHound, Rubeus, Impacket, NetExec and custom Rust credential-collection utilities. The researchers also observed that, while the actor specified a list of countries to avoid — including Russia, China, Iran, Ukraine, Belarus, Moldova, Brazil and South Africa — the AI agents did not consistently follow those rules.
GreyNoise emphasized the speed enabled by AI: the adversary moved from nothing to remote code execution in under four hours in a measured example, reached first domain admin two hours later, and then, in the full campaign’s initial burst, compromised at least 11 organizations in 26 seconds. In a separate instance, researchers recorded a progression from initial access to full domain administrator in seven minutes against a high school in the United States.
What this means for system administrators, education institutions, and policymakers
System administrators: Apply PaperCut’s emergency security updates for CVE-2026-81578 and CVE-2026-82078 immediately and follow the vendor’s bulletin recommendations. GreyNoise warns that “overall prevention scores can hide what happens after initial access,” and once attackers operate with valid credentials, prevention drops sharply.
Education institutions: With roughly half of the breaches affecting the education sector and at least one fast-moving compromise targeting a U.S. high school, schools should treat the PaperCut fixes as urgent. The observed paths include direct elevation to Domain Admins where PaperCut runs under high privilege, creating an especially acute risk for domain-joined environments common in education networks.
Policymakers and defenders: The campaign demonstrates how AI can accelerate exploit development and coordination with commodity tooling. GreyNoise’s Blue Report 2026 — cited in the advisory — measures defenses technique by technique across 338 million simulations run in customer production environments, underscoring the challenge of defending not only against initial exploits but against rapid, credential-based lateral movement that follows.
The record compiled by GreyNoise is stark and specific: automated agents using modern language models and scanning platforms can turn public vulnerabilities into broad compromises in hours or minutes. For administrators and organizations running PaperCut NG/MF, the immediate step is simple and binary — install the emergency updates and implement the vendor’s mitigations — while defenders and policymakers digest what rapid, AI-assisted exploitation means for response time, detection, and the protection of domain credentials.




