AI Agents Used in PaperCut Attacks
- •Suspected Russian-speaking actor used hundreds of AI agents to compromise 440+ PaperCut instances
- •CVE-2026-81578 and CVE-2026-82078 attacks hit 395 organizations across 48 countries
- •GreyNoise says attacker reached real-victim remote code execution in just under four hours
A suspected Russian-speaking cyber actor used hundreds of AI agents to develop exploits for two PaperCut NG/MF flaws and compromise more than 440 instances across 395 identified victim organizations in 48 countries, according to reports from Blackpoint Cyber and GreyNoise published around Sep 10, 2026. The activity came from 45.142.193[.]132, an IP address that Blackpoint, GreyNoise and Arctic Wolf linked to unauthorized port scanning, brute-force attempts and PaperCut exploitation activity in recent weeks.
The attacks exploited CVE-2026-81578 and CVE-2026-82078, an authentication bypass and remote code execution chain (running code on a remote system), mainly against the education sector in the U.S., the U.K., France, Spain, Canada, Belgium, Portugal, Australia, Germany and Switzerland. Arctic Wolf said post-exploitation activity included Windows registry hive collection tools, Metasploit/Meterpreter-related Java payloads, and commands to identify hosts, users, processes and sensitive configuration data.
GreyNoise said it had tracked malicious use of 45.142.193[.]132 since early July 2026 against internet-facing systems from Palo Alto, Ubiquiti, Citrix, SonicWall and Proxmox VE. The firm said the attacker built and attacked a lab environment with vulnerable PaperCut software and an Active Directory server, while also building target lists through the internet scanning service Netlas.io using an identified API key.
After gaining remote code execution and harvesting credentials in the self-hosted lab, the attacker deployed hundreds of AI agents powered by OpenAI Codex, a DeepSeek model and offensive security tools including Mimikatz, SharpHound, Certipy, Rubeus and Impacket. GreyNoise said the operator explicitly tried to avoid entities in 28 identified countries, including Russia, China, Hong Kong, Thailand, Iran, Venezuela, Indonesia, Pakistan and Bangladesh, but observed victimology showed that restraint failed in some cases.
GreyNoise said the attacker moved from an empty workspace to remote code execution against a real victim in just under four hours, and compromised at least 11 organizations in 26 seconds once the campaign started in earnest. In one attack on a U.S. high school, the time from initial access to full domain administrator access was seven minutes. The adversary gained domain administrator access against only 12 victim organizations, and GreyNoise said the end goal remained unclear, including whether access would be handed off to affiliated actors or used for data theft or ransomware deployment.
Blackpoint traced the operation to exposed operator infrastructure showing an AI-assisted workflow from vulnerability research and exploit development to target filtering, failure analysis, code changes and repeated retry waves. The earliest recovered activity began on August 31, when the project compared patched and unpatched PaperCut builds; within hours, that work became a multi-threaded validation tool tested against progressively larger target sets.
Recovered source code showed a targeting pipeline that merged source lists, geolocated candidates, filtered by country, applied the exclusion policy and identified live PaperCut systems before later stages. Targets were sorted by operating system, environment and status, while Python scripts tracked administrator access, account verification, Active Directory collection, domain and network discovery, and proxy setup. Blackpoint said Hindsight provided persistent memory for AI agents, and AionUi provided a graphical workspace to run and view multiple AI agents concurrently.
Blackpoint said the strongest AI impact was not a novel exploit technique, but reduced human effort across research, development, debugging, classification, tracking, retries and continuous improvement across hundreds of real systems. The company described the operator’s process as AI-supported research, coding, testing, troubleshooting and campaign execution feeding one another as the project moved from vulnerability research to operational execution.