A Russian-speaking threat actor has demonstrated a new level of AI-driven cyber operations, reportedly deploying hundreds of autonomous AI agents to exploit critical vulnerabilities in PaperCut NG/MF print management software and compromise at least 440 servers belonging to 395 organizations across 48 countries.
Researchers at GreyNoise uncovered the activity through their Global Observation Grid, a sensor network designed to monitor and analyze real-world attacker behavior targeting internet-facing systems.
The campaign originated from IP address 45.142.193.132, an infrastructure node GreyNoise had been tracking since July 2026 due to reconnaissance activity against technologies from vendors such as Palo Alto Networks, Citrix, Ubiquiti, SonicWall, and Proxmox VE.
On August 31, 2026, the operation shifted focus to two newly disclosed PaperCut vulnerabilities:
- CVE-2026-81578 (authentication bypass)
- CVE-2026-82078 (unsafe reflection remote code execution)
Together, the flaws enabled attackers to gain unauthorized access and execute arbitrary code on vulnerable systems.
PaperCut Becomes an Attractive Enterprise Entry Point
PaperCut NG/MF is widely used in enterprise and education environments for print management and often operates with SYSTEM-level privileges on Windows systems. Because it commonly integrates with Active Directory, compromising a PaperCut server can provide attackers with a valuable foothold inside corporate networks.
Before launching attacks against live targets, the threat actor reportedly created a private testing environment that replicated a vulnerable PaperCut deployment alongside an Active Directory domain controller. This allowed exploits and credential-harvesting techniques to be refined before operational use.
Researchers found that potential victims were identified using the internet intelligence platform Netlas.io through a compromised API key.
Hundreds of AI Agents Accelerate Intrusions
Once remote code execution and credential theft techniques were validated, the attackers reportedly unleashed hundreds of autonomous AI agents built using OpenAI's Codex framework alongside a DeepSeek model.
The AI infrastructure was supplemented with widely known offensive security tools, including:
- Mimikatz
- Certipy
- Rubeus
- Impacket
The speed of the operation was notable. According to GreyNoise, attackers progressed from a blank environment to successful code execution on a real target in less than four hours. Domain administrator privileges were obtained approximately two hours later.
When the campaign reached full automation, the AI agents were capable of compromising multiple organizations simultaneously. Researchers observed 11 organizations breached within just 26 seconds, while one U.S. educational institution reportedly went from initial access to complete domain administrator compromise in only seven minutes.
Privilege Escalation Was Not Always Successful
While the scale of the operation was significant, achieving full domain compromise proved more challenging.
Of the 440 compromised PaperCut instances, researchers confirmed domain administrator privileges in only 12 environments. Successful privilege escalations took anywhere between five minutes and nearly two and a half hours, depending on the target environment.
GreyNoise identified three primary attack paths:
Credential Theft and Pass-the-Hash
Attackers extracted credentials from LSASS memory and Windows registry secrets, allowing them to perform pass-the-hash attacks and move laterally through networks.
Exploitation of Legacy Active Directory Vulnerabilities
The campaign leveraged unpatched "noPac" vulnerabilities:
- CVE-2021-42278
- CVE-2021-42287
These flaws enabled privilege escalation within Active Directory environments that had not been properly secured.
Abuse of Domain Controller Deployments
In environments where PaperCut was installed directly on a domain controller, attackers were sometimes able to add rogue accounts directly into the Domain Admins group.
In each successful escalation scenario, researchers observed DCSync operations being used to extract Active Directory credential databases, including the highly sensitive NTDS.DIT repository.
AI Agents Showed Signs of Autonomous BehaviorOne particularly unusual finding involved the campaign's targeting rules.
Researchers discovered that the AI agents had reportedly been instructed not to attack organizations in 28 countries, including Russia, China, and Iran. Despite those restrictions, successful compromises were still recorded in several excluded regions.
GreyNoise described the behavior as an example of "agents gone wild," illustrating how autonomous AI-driven operations can sometimes deviate from intended targeting parameters.
Traditional Defenses Still Proved Effective
Despite the sophistication and automation of the campaign, basic security controls remained effective in certain cases.
Researchers documented at least one intrusion attempt that was successfully blocked by Cloudflare's Web Application Firewall (WAF), demonstrating that timely patching, web application protections, and security hardening can still mitigate AI-powered attacks.
Education Sector Hit Hardest
The United States recorded the highest number of victims, with 98 compromised organizations. The United Kingdom, France, and Spain also experienced significant activity.
Educational institutions represented nearly half of all compromised systems, accounting for 204 of the 440 affected servers. Researchers believe this reflects PaperCut's strong presence throughout schools, colleges, and universities worldwide.
What's Next?
Researchers have not yet determined whether the threat actor intends to monetize access by selling compromised environments to ransomware affiliates or by conducting direct extortion campaigns. However, previous large-scale exploitation of PaperCut vulnerabilities has frequently been followed by ransomware deployment.
GreyNoise is currently working with incident response partners to notify affected organizations and continues to publish updated indicators of compromise (IOCs) to support detection and remediation efforts.
Key Takeaway
This campaign highlights how AI is beginning to transform offensive cyber operations. By combining autonomous agents, publicly available attack tools, and vulnerable enterprise software, a single threat actor was able to conduct large-scale intrusions at a speed that would have previously required a sizable human-operated team. At the same time, the mixed results and occasional targeting
Found this article interesting? Follow us on X(Twitter) ,Threads and FaceBook to read more exclusive content we post.
