AI-powered attack exploited PaperCut flaws to hack 395 organizations

A massive global cyberattack has been unfolding over the past week, targeting PaperCut NG/MF servers in at least 395 organizations across 48 countries. The attack, which began on August 31, was carried out by a threat actor likely of Russian origin, using hundreds of AI agents to develop and launch a sophisticated exploitation campaign.

The attackers focused on exploiting two security flaws: CVE-2026-81578 and CVE-2026-82078, both of which were flagged as actively exploited earlier this month. The AI-powered attack used OpenAI’s Codex and DeepSeek models in combination with commodity offensive tools to build, test, and refine exploits. The agents also generated target lists through the Netlas internet scanning and discovery platform.

The scope of the attack is staggering: GreyNoise data indicates that at least 440 PaperCut instances were compromised, with 280 victims having their credentials harvested, 147 obtaining operating system or domain secrets, and 12 organizations gaining administrator privileges. The majority of affected organizations are in the education sector, accounting for roughly half of all breaches.

The United States was the most targeted country, followed by the United Kingdom, France, Spain, and Canada. Notably, the threat actor specified a list of countries to avoid, including Russia, China, Iran, Ukraine, Belarus, Moldova, Brazil, and South Africa. However, the agents did not consistently follow these rules.

The speed at which this attack was executed is a concerning aspect. GreyNoise notes that the attacker went from initial access to full domain administrator in just seven minutes against a high school in the United States. This rapid pace of attack leaves defenders with extremely tight response margins, emphasizing the need for swift and effective incident response.

GreyNoise observed three primary attack paths after exploiting the PaperCut flaws:

* Dumping LSASS memory and registry secrets from domain-joined PaperCut servers, then passing recovered credential hashes to domain controllers.

* Using the “noPac” attack against environments still vulnerable to CVE-2021-42278 and CVE-2021-42287.

* Directly adding a newly created account to Domain Admins when PaperCut ran on a domain controller or under a domain administrator service account.

In all cases, the attackers used the DCSync post-exploitation technique to obtain a complete NTDS.DIT dump with domain credentials. The attacker’s toolkit includes Ligolo-ng, Mimikatz, Certipy, BloodHound, Rubeus, Impacket, NetExec, and custom Rust credential-collection utilities.

While GreyNoise could not determine the attacker’s campaign objective, the access gained by the attackers could be used for data theft or ransomware operations. System administrators are advised to apply PaperCut’s emergency security updates addressing CVE-2026-81578 and CVE-2026-82078 immediately and follow the vendor’s recommendations in their bulletin.

This attack serves as a stark reminder of the increasing sophistication of cyber threats and the importance of staying vigilant in the face of AI-powered attacks. As defenders, it is crucial to focus on prevention and incident response, rather than relying solely on post-breach detection and remediation. By doing so, we can minimize the impact of such attacks and protect our organizations from these types of threats.


Source: Bleeping Computer — 2026-09-10