AIO APEX

AI agents ran a PaperCut hacking campaign that hit 395 organizations in 48 countries

BleepingComputer
Share:
AI agents ran a PaperCut hacking campaign that hit 395 organizations in 48 countries

A likely Russian-speaking threat actor used hundreds of AI agents to build, test, and launch a global exploitation campaign against PaperCut print management servers, compromising at least 440 instances tied to 395 organizations across 48 countries, according to a new report from attack intelligence firm GreyNoise.

The campaign targeted two PaperCut NG/MF vulnerabilities, CVE-2026-81578 and CVE-2026-82078, both flagged as actively exploited earlier this month. GreyNoise says the operation began August 31 and combined OpenAI's Codex with DeepSeek models alongside commodity offensive security tools, with AI agents also generating target lists using the Netlas internet-scanning platform.

From empty workspace to domain admin in hours

The speed of the campaign is what distinguishes it from conventional exploitation waves. GreyNoise says the attacker went from an empty workspace to a first successful remote code execution against a real victim in under four hours, reached first domain admin two hours after that, and once the full campaign launched, compromised at least 11 organizations within a 26-second window. In one case involving a U.S. high school, the attacker moved from initial access to full domain administrator in seven minutes.

Education was the hardest-hit sector, accounting for roughly half of all breaches, with the United States the most targeted country, followed by the United Kingdom, France, Spain, and Canada. The attacker harvested credentials from 280 victims, obtained operating system or domain secrets from 147, and reached administrator privileges at 12 organizations. GreyNoise notes the operator had instructed its agents to avoid targets in Russia, China, Iran, Ukraine, Belarus, Moldova, Brazil, and South Africa — though the agents didn't consistently follow that instruction.

Three exploitation paths, one credential-theft endgame

Once inside, the AI-directed operation followed one of three paths: dumping LSASS memory and registry secrets from domain-joined PaperCut servers for pass-the-hash attacks, exploiting the older "noPac" flaws (CVE-2021-42278 and CVE-2021-42287) where still unpatched, or directly adding a new account to Domain Admins when PaperCut ran under a domain administrator service account. Every path converged on the same technique — a DCSync attack to pull a complete NTDS.DIT dump of domain credentials — using an attacker toolkit that included Mimikatz, Certipy, BloodHound, Rubeus, Impacket, and custom Rust-based credential collectors.

Why the speed matters more than the tooling

GreyNoise could not determine the campaign's ultimate objective — the access harvested could support data theft or a ransomware operation — but the firm's central warning is about tempo, not technique: AI-orchestrated attacks compress the gap between initial access and full compromise from days to minutes, leaving defenders with response windows that traditional detect-and-respond playbooks weren't built for. Administrators running PaperCut NG/MF are advised to apply the vendor's emergency security updates for both CVEs immediately. As first reported by BleepingComputer.

Originally reported by BleepingComputer. Read the original article for additional details.

View original source
Share: