AI Agents Used by Hackers to Compromise 440 PaperCut Servers

An autonomous intrusion campaign leveraging hundreds of AI agents has successfully compromised at least 440 PaperCut NG and MF servers across 395 organizations in 48 countries. Tracked by threat intelligence firm GreyNoise, the attacks exploited two critical vulnerabilities—CVE-2026-81578 and CVE-2026-82078—to bypass authentication and achieve remote code execution under SYSTEM privileges.

According to threat intelligence reports from GreyNoise, the campaign began on August 31, 2026, utilizing infrastructure anchored by the IP address 45.142.193.132. This same infrastructure had been monitored since early July targeting internet-facing systems from vendors like Palo Alto, Ubiquiti, Citrix, SonicWall, and Proxmox VE.

Why target print management software? In modern enterprise architectures, applications like PaperCut NG and MF are frequently overlooked Java web applications running with absolute SYSTEM-level privileges on Windows. Crucially, they are often integrated directly into Active Directory domains, presenting an inviting lateral highway straight to a wider domain compromise.

From Empty Workspace to Domain Admin in Under Seven Minutes

The operational velocity of this campaign marks a stark departure from traditional human-led attacks. The threat actor, assessed to be a Russian-speaking group, built and tested exploits in a dedicated lab containing vulnerable PaperCut software alongside a live Active Directory controller. They compiled target lists via Netlas.io.

Armed with OpenAI Codex, a DeepSeek model, and standard open-source offensive tooling, the attackers engineered agentic workflows that obliterated the traditional reconnaissance-to-exploitation timeline. GreyNoise observed that the threat actor moved from an empty workspace to achieving remote code execution against an initial victim in less than four hours, escalating to Domain Admin privileges two hours later.

At the campaign’s peak throughput, autonomous workflows compromised at least 11 organizations in a staggering 26 seconds. In one documented instance at a U.S. high school, the pipeline hurtled from initial access to full domain administrator takeover in just seven minutes.

Fragmented Execution and Post-Exploitation Stalls

Despite the blistering speed of the AI-driven initial access phase, the campaign experienced distinct operational bottlenecks during post-exploitation. While at least 440 PaperCut instances fell to the initial exploit chain, GreyNoise confirmed that Domain Admin privileges were ultimately secured in only 12 victim organizations.

Escalation times varied wildly, ranging from five minutes to a protracted 144 minutes. Analysts noted that adversary actions occasionally stalled simply because the autonomous operators—or their human minders—failed to execute subsequent post-exploitation tasks promptly. Furthermore, automated defenses occasionally bit back; Cloudflare’s Web Application Firewall successfully intercepted and thwarted at least one vector attempt.

AI Agents Used by Hackers to Compromise 440 PaperCut Servers
Photo: gbhackers.com

Where attackers did secure Domain Admin rights, they relied on three well-worn adversary techniques:

  • Harvesting LSASS process memory and registry secrets directly from domain-joined PaperCut servers to execute pass-the-hash attacks.
  • Leveraging the noPac privilege escalation technique against organizations that had failed to patch CVE-2021-42278 and CVE-2021-42287.
  • Creating rogue accounts and appending them directly to the Domain Admins group, particularly when PaperCut was hosted on a domain controller or executed under a Domain Admin service account.

Following these steps, the actors utilized DCSync to pull NTDS.DIT database contents, securing complete Active Directory credential maps. Security analysts emphasize that the ultimate objective—whether data extortion, ransomware deployment, or long-term access brokering—remains opaque.

Immediate Defensive Posture and Indicators of Compromise

Security teams managing enterprise print infrastructure must act immediately. Mitigation requires patching all vulnerable PaperCut deployments, restricting administrative exposure, and auditing the Domain Admin group for unauthorized additions. Defenders should also hunt for staged registry hives, Ligolo artifacts, DCSync traffic, suspicious LSASS memory dumping, and abnormal certutil execution.

Key infrastructure indicators associated with the orchestration of this campaign include the IP addresses 45.142.193.132 and 45.158.196.75, alongside file hash 528cd4e69ecfa5191adbcf6ef2.

ShieldCrash zero day breaks Microsoft's newest patch, AI agents compromise 440 school print servers
Photo of author

Sophie Lin - Technology Editor

Sophie is a tech innovator and acclaimed tech writer recognized by the Online News Association. She translates the fast-paced world of technology, AI, and digital trends into compelling stories for readers of all backgrounds.

Pakistan Debutant Razaullah Lights Up Edgbaston With Stunning Innings Against England

Leave a Comment

This site uses Akismet to reduce spam. Learn how your comment data is processed.