PaperCut Attacker Uses Hundreds of AI Agents to Compromise 440+ Instances — SkimNews

Get the Tech newsletter
Daily tech — startups, AI labs, chips, the launches that shape the next decade. Free.
- A suspected Russian-speaking threat actor exploited CVE-2026-81578 and CVE-2026-82078 (an authentication bypass and remote code execution chain) in PaperCut NG/MF to compromise no less than 440 instances across 395 victim organizations in 48 countries, primarily hitting the education sector in the US, UK, France, Spain, Canada, Belgium, Portugal, Australia, Germany, and Switzerland.
- The attacker deployed hundreds of AI agents powered by OpenAI Codex and a DeepSeek model alongside offensive tools including Mimikatz, SharpHound, Certipy, Rubeus, and Impacket, supported by two open-source tools — Hindsight (a persistent memory service for AI agents) and AionUi (a unified workspace for running multiple AI agents concurrently).
- GreyNoise and Blackpoint Cyber traced the activity to IP address 45.142.193[.]132, which GreyNoise has tracked since early July 2026 for probing internet-facing systems from Palo Alto, Ubiquiti, Citrix, SonicWall, and Proxmox VE; Blackpoint's earliest recovered activity began August 31 with vulnerability research comparing patched and unpatched PaperCut builds.
- The campaign compressed attack timelines dramatically, with GreyNoise documenting progression from an empty workspace to remote code execution in under four hours, 11 organizations compromised in 26 seconds once the campaign began in earnest, and one US high school reaching full domain administrator access just seven minutes after initial access.
- The adversary added 28 countries to an exclusion list including Russia, China, Hong Kong, Iran, Pakistan, Bangladesh, and Venezuela, but GreyNoise noted the attempted restraint 'failed in some instances' against real victims.
- Post-exploitation activity included delivery of Windows registry hive collection tools, Metasploit/Meterpreter-related Java payloads, and commands to identify hosts, users, processes, and sensitive configuration data, with domain administrator access achieved against only 12 victim organizations whose end goals remain unclear.
Why it matters: The campaign collapses the manual labor of running cyber operations — vulnerability research, target filtering, exploit validation, and post-exploitation — into a continuous AI feedback loop, with Blackpoint concluding the strongest AI impact was reducing human effort, not novel exploit technique. For defenders at the 395 compromised organizations, the seven-minute path to domain admin at one US high school renders traditional detection windows obsolete, and the 12 organizations that lost full domain admin control face potential follow-on ransomware or data theft.
Ask SkimNews




