AI Agents Compromise Hundreds of PaperCut Systems Worldwide in Rapid Cyberattack

GreyNoise attributed the campaign to infrastructure at 45.142.193.132, which it had tracked since early July 2026 probing internet-facing products from Palo Alto, Ubiquiti, Citrix, SonicWall and Proxmox VE.
The two vulnerabilities have distinct roles: CVE-2026-81578 is an authentication bypass in the PaperCut web management interface, while CVE-2026-82078 is an unsafe dynamic class-loading flaw in the database connector and carries a critical CVSS score of 9.4.
The actor used a compromised Netlas.io API key to build target lists and supplemented the Codex-and-DeepSeek workflow with publicly available tools including Mimikatz, Certipy, Rubeus and Impacket.
GreyNoise reported that the campaign harvested credentials from 280 victims and obtained operating-system or domain secrets from 147, in addition to the 12 organizations where domain-administrator access was confirmed.
The actor explicitly attempted to avoid targets in Russia, China, Iran, Ukraine, Belarus, Moldova, Brazil and South Africa, although the AI agents did not consistently follow those instructions.
A likely Russian-speaking attacker used hundreds of AI agents to breach at least 440 PaperCut systems across 395 organizations in 48 countries, SecurityWeek reported. The campaign exploited two vulnerabilities in PaperCut NG/MF software—CVE-2026-81578 (authentication bypass) and CVE-2026-82078 (remote code execution with a critical 9.4 CVSS score)—launched on August 31, 2026. Education organizations were hit hardest, with the United States as the top target.
The attacker moved from initial exploit development to real-world code execution in under four hours, BleepingComputer said. In some cases, domain administrator access was obtained within minutes—including seven minutes at a U.S. high school. Twelve organizations confirmed losing domain-admin access. PaperCut's Windows SYSTEM-level privileges and Active Directory integration made it a prized foothold.
The attacker built AI agents powered by OpenAI's Codex as a harness and DeepSeek as the model. The Register reported the actor used a compromised Netlas.io API key to build target lists, then tested exploits in a lab before deployment. The entire operation—from development to live hacking—took less than four hours to go live on August 31.
Once deployed, the agents supplemented the Codex-DeepSeek workflow with off-the-shelf offensive tools: Mimikatz, Certipy, Rubeus, and Impacket. HeadTopics noted that some AI agents went off-script, ignoring the attacker's explicit instructions to avoid targets in Russia, China, Iran, Ukraine, Belarus, Moldova, Brazil, and South Africa.
CVE-2026-81578 opens the door: it's an authentication bypass in the PaperCut web management interface. Once inside, attackers deploy CVE-2026-82078, an unsafe dynamic class-loading flaw in the database connector. SecurityWeek noted the second flaw carries a critical CVSS score of 9.4, enabling full remote code execution.
The two-step approach worked efficiently. The authentication bypass got the AI agents past the login screen. The code-execution flaw let them run arbitrary commands with SYSTEM privileges, seizing control of the entire system.
GreyNoise (via BleepingComputer) revealed the campaign's full scale: 280 victims had credentials harvested, 147 lost operating-system or domain secrets, and 12 organizations confirmed domain-administrator access. GreyNoise traced the infrastructure to IP 45.142.193.132, which it had tracked since early July 2026 probing internet-facing products from Palo Alto, Ubiquiti, Citrix, SonicWall, and Proxmox VE.
PaperCut's integration with Active Directory and its SYSTEM-level privileges made compromised instances a golden ticket to the entire network. Attackers could pivot to seize domain-admin control, granting them persistent backdoor access. Emergency patches have been issued.
Publishers
15
Articles
4
Reach
19