AI Agents Used in PaperCut Exploitation Campaign Targeting Hundreds of Organizations
Tech
⚠ Single-source
31m ago

AI Agents Used in PaperCut Exploitation Campaign Targeting Hundreds of Organizations

AI-synthesized · Bias removed · Facts only
3 sources: 0 left · 3 center · 0 right
Image: Theregister

A threat actor, likely Russian-speaking, leveraged hundreds of AI agents to exploit vulnerabilities in PaperCut NG/MF servers, compromising at least 440 instances across 395 organizations in 48 countries. The campaign, which began in early July 2026, utilized AI models including OpenAI’s Codex and DeepSeek, alongside offensive security tools like Mimikatz and Metasploit, to develop and execute exploits targeting CVE-2026-81578 and CVE-2026-82078, an authentication bypass and remote code execution chain. While the actor attempted to exclude 28 countries from targeting, including Russia, China, and Iran, some instances of compromise occurred within those regions. Post-exploitation activity included the collection of Windows registry hives and the deployment of Java payloads. The actor built and tested exploits in a lab environment, utilizing an identified Netlas.io API key to build target lists. Blackpoint Cyber and GreyNoise independently reported the activity, originating from the IP address 45.142.193[.]132, which had previously been linked to port scanning and brute-force attacks. At this time, the ultimate goal of the campaign remains unconfirmed, though initial activity suggests a focus on initial access. Some sources note the actor attempted to avoid targeting entities in 28 identified countries, but this restraint was not fully successful.

What is not yet known

  • The ultimate goal of the threat actor’s campaign remains unconfirmed.
  • The exact number of victims beyond the 395 identified organizations is unknown.
Was this useful?

Read the original coverage

💬 Comments

📜 Comment Policy