A global cyberattack campaign has been unleashed by a threat actor utilizing hundreds of AI agents to target vulnerable PaperCut NG/MF servers. The operation, which began on August 31, exploited two critical security flaws (CVE-2026-81578 and CVE-2026-82078) affecting the software, compromising at least 440 instances linked to 395 distinct organizations across 48 countries.
The AI agents employed OpenAI’s Codex and DeepSeek models in combination with commodity offensive tools, generating target lists through the Netlas internet scanning and discovery platform. The attackers’ tactics were multifaceted, using various techniques such as credential harvesting, obtaining operating system or domain secrets, and gaining administrator privileges at 12 organizations.
The most affected sector was education, accounting for roughly half of all breaches, with the United States being the primary target country followed by the UK, France, Spain, and Canada. Notably, the attackers specified a list of countries to avoid but failed to consistently adhere to these rules.
GreyNoise, the attack and threat intelligence company behind the discovery, highlights the alarming speed at which this campaign unfolded. “The adversary went from an empty workspace to first achieving RCE against a real victim in just under four hours, first domain admin in an additional two hours, and once the full campaign launched, compromised at least 11 organizations in 26 seconds,” notes GreyNoise.
This campaign showcases the devastating potential of AI-powered attacks, enabling rapid exploitation with minimal response time for defenders. According to GreyNoise, once attackers gain valid credentials, only 37% of their subsequent actions are blocked by existing prevention measures.
The researchers identified three primary attack paths:
1. Dumping LSASS memory and registry secrets from domain-joined PaperCut servers, then passing recovered credential hashes to domain controllers.
2. Utilizing the “noPac” attack against environments still vulnerable to CVE-2021-42278 and CVE-2021-42287.
3. Directly adding a newly created account to Domain Admins when PaperCut ran on a domain controller or under a domain administrator service account.
The attacker’s toolkit includes Ligolo-ng, Mimikatz, Certipy, BloodHound, Rubeus, Impacket, NetExec, and custom Rust credential-collection utilities. While the campaign’s objective remains unclear, access to sensitive information could be used for data theft or ransomware operations.
To mitigate this threat, system administrators are advised to apply PaperCut’s emergency security updates addressing CVE-2026-81578 and CVE-2026-82078 immediately and follow the vendor’s recommendations in their bulletin. This incident serves as a stark reminder of the importance of proactive security measures and staying vigilant against emerging threats, especially those leveraging AI capabilities.
For readers, this incident underscores the need for ongoing vigilance and adherence to best practices for securing sensitive systems and networks. It is crucial to stay informed about known vulnerabilities and apply necessary patches in a timely manner.
Source: Bleeping Computer — 2026-09-10