AI Orchestrated Campaign Targets PaperCut Vulnerabilities
This time, the theoretical threat of agentic hacking unequivocally escaped the confines of the laboratory. GreyNoise meticulously detailed a terrifying, real-world campaign launched against PaperCut NG/MF, where a solitary human operator commanded hundreds of artificial intelligence agents. During the absolute peak of the assault, these autonomous agents compromised a staggering minimum of 11 distinct organizations in a mere 26 seconds. The comprehensive attack ultimately impacted no fewer than 440 servers belonging to 395 organizations spanning 48 countries. Analysts reconstructed this alarming AI orchestrated campaign against PaperCut NG/MF utilizing the expansive GreyNoise sensor network.
Exploiting Critical Vulnerabilities for Domain Access
This aggressive campaign commenced on August 31. According to GreyNoise intelligence, the malicious actor ruthlessly exploited two recently disclosed PaperCut vulnerabilities: CVE-2026-81578, which carries a severe 8.8 rating on the CVSS 4.0 scale, and CVE-2026-82078, boasting a catastrophic 9.4 rating. The former vulnerability permits unauthorized configuration alterations without an account, while the latter facilitates the execution of arbitrary Java code directly within the server context. When weaponized in tandem, this lethal combination completely bypasses any preliminary authentication requirements.
Security experts had previously analyzed the dangerous synergy of these two flaws following the initial waves of real-world attacks against PaperCut infrastructures. Crucially, NG and MF servers frequently operate within Windows environments possessing elevated SYSTEM privileges and maintain direct connections to Active Directory. Consequently, remote code execution rapidly evolves from a localized print server takeover into a direct pathway for harvesting domain credentials and executing lateral network movement. This intrinsic architectural design renders the print server an exceptionally convenient entry point for total domain subjugation.
The Terrifying Scale of AI Automation
The astonishing scale of this campaign did not stem from a revolutionary new hacking technique, but rather from unprecedented automation. The operator meticulously constructed a testing laboratory featuring a vulnerable PaperCut instance integrated with Active Directory. Subsequently, they compiled an extensive target list utilizing Netlas and rigorously verified their attack chain. Following this preparation, the operator unleashed hundreds of AI agents, utilizing Codex as the overarching command shell, the DeepSeek model for cognitive processing, and an arsenal of publicly available offensive tools. These agents autonomously executed numerous complex tasks simultaneously.
Autonomous Exploitation and Lateral Movement
Upon successfully breaching the perimeter, the agents autonomously selected their lateral movement path based precisely upon the victim’s specific configuration. They extracted sensitive LSASS secrets, executed sophisticated pass-the-hash techniques, and deployed the legacy noPac exploit chain against unprotected systems. Alternatively, they immediately forged a completely new Domain Administrator account if the compromised PaperCut instance happened to operate directly on a domain controller or utilized a highly privileged service account. The devastating finale invariably involved a DCSync attack to covertly download the entire NTDS.DIT database.
However, blinding speed did not guarantee universal success. GreyNoise observed the successful acquisition of Domain Admin privileges in only 12 organizations. The absolute fastest path from initial access to total domain control required a mere five minutes; astonishingly, the compromise of an American school required just seven minutes. In one documented instance, a Cloudflare WAF successfully repelled the automated assault. Curiously, the agents occasionally malfunctioned, violating the operator’s explicitly defined list of restricted countries they were ordered to avoid.
Mitigation and Remediation Efforts
By September 10, PaperCut had proactively released versions 26.0.5, 25.0.13, and 24.1.10, completely superseding all previous emergency hotfixes. The company reports that the volume of new compromises has decreased significantly; nevertheless, publicly accessible, unpatched servers remain under relentless attack. Security professionals strongly urge administrators to immediately transition to the current software release, decisively isolate the Application Server from the public internet, and rigorously audit their networks for the unexpected presence of SimpleHelp or AnyDesk remote management tools.
Support Our Threat Intelligence
If you find our technology report and cybersecurity news helpful, consider supporting our work.