A Russian-speaking threat actor has weaponized artificial intelligence at an unprecedented scale, deploying hundreds of autonomous AI agents to exploit critical vulnerabilities in PaperCut NG/MF print management software and compromise at least 440 servers across 395 organizations in 48 countries.
Security researchers at GreyNoise identified the campaign through their Global Observation Grid, a network of sensors that captures live attacker activity on controlled infrastructure.
The malicious actor operated from IP address 45.142.193.132, which GreyNoise had flagged since early July 2026 for probing internet-facing systems from vendors including Palo Alto, Ubiquiti, Citrix, SonicWall, and Proxmox VE.
On August 31, 2026, this infrastructure pivoted toward two PaperCut vulnerabilities, CVE-2026-81578 and CVE-2026-82078, an authentication bypass and an unsafe reflection remote code execution flaw, respectively.
PaperCut Flaws Compromised Using AI
PaperCut NG/MF is widely deployed self-hosted print management software that typically runs with SYSTEM-level privileges on Windows and integrates directly with Active Directory, making it an attractive foothold for lateral movement inside enterprise networks.
The attacker first built a private lab environment mirroring a vulnerable PaperCut deployment alongside an Active Directory server to develop and test exploits before going live. The attacker compiled target lists using the internet scanning service Netlas.io through a compromised API key.
Once the actor validated remote code execution and credential harvesting, they unleashed hundreds of AI agents built on OpenAI’s Codex harness paired with a DeepSeek model, combined with publicly available offensive tools such as Mimikatz, Certipy, Rubeus, and Impacket.
The speed was impressive. The attacker went from an empty workspace to executing code on a real target in under four hours. They gained domain administrator access two hours later.
Once the automated campaign launched fully, the AI agents compromised 11 organizations in just 26 seconds, and in one case breached a U.S. high school network from initial access to full domain admin in seven minutes.
Despite the scale, results varied significantly. Domain administrator access was confirmed in only 12 of 440 compromised instances, with successful escalations ranging from five to 144 minutes.
GreyNoise documented three distinct attack paths: harvesting LSASS memory and registry secrets for pass-the-hash attacks, exploiting unpatched “noPac” vulnerabilities CVE-2021-42278 and CVE-2021-42287, and directly adding rogue accounts to Domain Admins when PaperCut ran on a domain controller.
In every successful case, the actor executed DCSync operations to exfiltrate the full NTDS.DIT credential database.
Notably, the actor’s agents had been instructed to avoid targeting 28 countries including Russia, China, and Iran, yet victims were still recorded in several of these regions, an anomaly researchers describe as “agents gone wild,” highlighting how autonomous AI operations can deviate from operator intent.
In at least one attempted intrusion, Cloudflare’s Web Application Firewall successfully blocked the exploitation attempt, underscoring that fundamental security hardening remains effective even against AI-driven threats.
The United States accounted for the largest share of victims at 98, followed by the United Kingdom, France, and Spain, with educational institutions representing 204 of the 440 compromised systems, likely reflecting PaperCut’s strong customer base in that sector.
It remains unclear whether the actor intends to sell access to affiliated ransomware groups or pursue direct extortion, though past PaperCut exploitation has historically led to ransomware deployment.
GreyNoise says it is coordinating with incident response partners to notify affected organizations and continues to publish fresh indicators of compromise on its public GitHub repository.
Learn 7 Metric-Gated AI SOC Deployment Phases – Download Free AI SOC Deployment Playbook 2026.
The post Hackers Use Hundreds of AI Agents to Exploit PaperCut Flaws and Compromise 440 Servers Worldwide appeared first on Cyber Security News.
