A suspected Russian-speaking attacker used hundreds of AI agents to build and launch a worldwide campaign against vulnerable PaperCut servers. The operation compromised systems belonging to at least 395 organizations in 48 countries.
The PaperCut AI attack targeted two actively exploited vulnerabilities in PaperCut NG/MF. Researchers say the threat actor used AI models alongside widely available offensive security tools.
Moreover, the attacker moved from an empty workspace to remote code execution against a real victim in less than four hours.
AI Agents Developed and Tested the Exploits
According to threat intelligence company GreyNoise, the campaign began on August 31, 2026. The attacker used hundreds of AI agents powered by OpenAI’s Codex and DeepSeek models.
These agents helped build, test and refine exploits for CVE-2026-81578 and CVE-2026-82078. Both flaws affect PaperCut NG/MF servers and were already under active attack.
The attacker also instructed the agents to create lists of potential targets. For this task, they used information from the Netlas internet scanning and discovery platform.
GreyNoise identified at least 440 compromised PaperCut instances. Those servers belonged to 395 separate organizations across 48 countries.
Attackers Stole Credentials and Domain Secrets
The campaign harvested credentials from 280 victims. In addition, the attacker obtained operating system or domain secrets from 147 organizations.
The intruder reached administrator-level access at 12 organizations. However, the speed of some compromises gave defenders little time to respond.
After launching the full campaign, the attacker reportedly compromised at least 11 organizations in only 26 seconds. In another case, the threat actor gained full domain administrator access to a U.S. high school within seven minutes.
Education suffered the greatest impact and accounted for about half of all identified breaches. The United States recorded the most victims, followed by the United Kingdom, France, Spain and Canada.
AI Agents Ignored Some Geographic Restrictions
The threat actor instructed the AI agents to avoid several countries. The list included Russia, China, Iran, Ukraine, Belarus, Moldova, Brazil and South Africa.
However, the agents did not always follow those restrictions. This inconsistency shows that attackers may struggle to control large collections of autonomous tools during rapid campaigns.
Nevertheless, the PaperCut AI attack demonstrates how artificial intelligence can shorten the time between research and widespread exploitation. Instead of completing each step manually, attackers can distribute tasks across many agents.
As a result, vulnerable systems may face automated attacks shortly after exploit development begins.
Three Paths Led to Domain Compromise
GreyNoise observed three main attack paths after the initial exploitation of PaperCut servers.
In the first path, the attackers dumped LSASS memory and extracted secrets from the Windows registry. They then used recovered credential hashes to authenticate with domain controllers through pass-the-hash attacks.
The second path involved the noPac attack. This technique targeted environments that remained vulnerable to CVE-2021-42278 and CVE-2021-42287.
For the third path, attackers created a new account and added it directly to the Domain Admins group. This method worked when PaperCut operated on a domain controller or used a domain administrator service account.
In every observed path, the attackers eventually used DCSync. This post-exploitation technique allowed them to obtain a complete NTDS.DIT database containing domain credentials.
Campaign Used Common Offensive Tools
The attacker combined AI-generated work with an extensive collection of established offensive tools. The toolkit included Ligolo-ng, Mimikatz, Certipy, BloodHound, Rubeus, Impacket and NetExec.
The campaign also used custom Rust utilities for credential collection. Together, these tools supported network access, credential theft, Active Directory discovery and privilege escalation.
Therefore, the operation did not rely on AI alone. Instead, the threat actor used AI to coordinate and accelerate a conventional intrusion process.
This approach helped automate exploit development, target discovery and post-exploitation activity at a significant scale.
Final Objective Remains Unknown
GreyNoise could not determine the ultimate purpose of the campaign. However, the level of access obtained could support serious follow-up attacks.
For example, stolen credentials and domain administrator privileges could enable data theft. Attackers could also use the access to deploy ransomware throughout compromised networks.
The complete domain credential databases create an additional risk. Even after organizations secure the original PaperCut servers, stolen credentials may continue to provide access elsewhere.
Consequently, affected administrators must investigate more than the vulnerable application. They should also look for credential dumping, unexpected accounts and suspicious domain controller activity.
PaperCut Updates Should Be Installed Immediately
Administrators should install PaperCut’s emergency security updates for CVE-2026-81578 and CVE-2026-82078 immediately.
Organizations should also review PaperCut servers for signs of compromise. Since attackers may have obtained domain-wide privileges, simply patching the flaws may not remove an existing intrusion.
Security teams should examine stored credentials, service account permissions and authentication activity. Furthermore, they should reset exposed credentials and investigate any unexpected Domain Admin accounts.
The PaperCut AI attack highlights how quickly AI-assisted campaigns can move from exploit development to widespread compromise. As attackers automate more stages of an operation, organizations will have even less time to patch exposed systems.


0 responses to “AI-Powered PaperCut Attack Hacks 395 Organizations Worldwide”