INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

PaperCut Flaws Exploited by AI-powered Attackers to Hack 835 Orgs

| 2026-09-09 14:56 HIGH HIGH AI-ENABLED ATTACK · AUTONOMOUS EXPLOITED VULNERABILITY ATTACK ON AI SYSTEMS
Executive Summary
AI-generated
A threat actor, likely Russian-speaking, used hundreds of AI agents to develop and launch a global exploitation campaign targeting vulnerable PaperCut NG/MF servers on August 31. The attackers compromised at least 440 PaperCut instances linked to 395 distinct organizations across 48 countries, with the United States being the most targeted country followed by the UK, France, Spain, and Canada. The AI agents generated target lists through Netlas internet scanning and discovery platform, but did not consistently follow a list of countries to avoid including Russia, China, Iran, Ukraine, Belarus, Moldova, Brazil, and South Africa. The attackers used three attack paths after exploiting PaperCut flaws: dumping LSASS memory and registry secrets from domain-joined servers, passing recovered credential hashes to domain controllers, or directly adding newly created accounts to Domain Admins. As of the article's publication date on September 10, the current status is unclear, but system administrators are advised to apply emergency security updates addressing CVE-2026-81578 and CVE-2026-82078 immediately.
Technical Mitigations AI-generated
• Apply the vendor fix for CVE-2023-27350, CVE-2026-82078 and treat internet-facing systems that were not patched in time as potentially compromised until verified.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected

Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.

de•••••.log
nt•••••.dit
ww•••••.io
ud•••••.out
pc•••••.exe
ch•••••.exe
hxxp://••••••••••••••••••••
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Raspberry RobinRaspberry Robin CVE-2023-27350CVE-2023-27350 CVE-2026-82078CVE-2026-82078 CVE-2021-42278CVE-2021-42278 CVE-2021-42287CVE-2021-42287 CVE-2026-81578CVE-2026-81578 CVE-2023-27351CVE-2023-27351
Target & Sectors
NORTH_AMERICA NORTH_AMERICA CIS CIS healthhealth educationeducation energyenergy
Incident Timeline
‎April 2023
Threat actors exploited the CVE-2023-27350 and CVE-2023-27351 vulnerabilities in PaperCut print management software to hack 395 organizations.
vulnerability CVE-2023-27350
general_metric 27350 -
vulnerability CVE-2023-27351
organisation Lace Tempest
‎April 13, 2023
Threat actors using the Lace Tempest AI-powered attack tool began exploiting previously disclosed PaperCut vulnerabilities on April 13, 2023.
‎May 2023
Microsoft issued a warning in May 2023 that Iran-linked APT groups were exploiting the CVE-2023-27350 flaw in PaperCut MF/NG print management servers.
organisation Microsoft
source_region Iran, Islamic Republic of
organisation CVE-2023-27350
organisation APT
industry Education
tactic Ransomware
attribution FBI
‎August 27
Threat actors are actively exploiting a pre-authentication remote code execution flaw in PaperCut to hack 395 organizations worldwide.
organisation PaperCut
tactic Remote Code Execution
‎2026/08/27
Threat actors used a zero-day vulnerability in PaperCut NG/MF versions 25 and 26 to launch AI-powered attacks against customer servers.
organisation PaperCut NG/MF
organisation BleepingComputer
general_metric 25 versions
‎Aug 28, 2026
Threat actors exploited vulnerabilities in PaperCut's AI-powered security features to successfully hack into the systems of 395 organizations.
‎August 31
GreyNoise reported that an AI-powered attack campaign, combining OpenAI's Codex and DeepSeek models with commodity offensive tools, began on August 31.
attribution GreyNoise
attribution OpenAI’s Codex
‎2026/09/09
Threat actors exploited vulnerabilities in PaperCut NG and MF print management software, tracked as CVE-2026-82078 and CVE-2026-81578, to hack 395 organizations.
organisation Exploit PaperCut Flaws
organisation Compromise 440 Servers Worldwide
victims 395 organizations
organisation GreyNoise
organisation PaperCut NG/MF
organisation LockBit
organisation CVE-2023-27350
organisation Lace Tempest
organisation NG
organisation CVSS
organisation Microsoft
organisation CVE-2026
infrastructure 8.8
organisation MF
organisation PaperCut NG
organisation PaperCut MF
organisation CVE-2021-42278
organisation BloodHound
organisation NetExec
organisation PaperCut
organisation Vulnerability / Enterprise Security
organisation RCE
victims 11 organizations
infrastructure Windows
infrastructure Linux
infrastructure Macos
organisation Domain Admins
organisation NFL
organisation CHANEL
victims 280 victims
victims 12 organizations
organisation LinkedIn
organisation the PaperCut Application
organisation Hackers Are Probing PaperCut Servers
infrastructure 2,500 PaperCut installations
organisation Udydn.out
organisation PaperCut NG/MF Application
organisation IP
organisation Huntress
organisation Hutress
organisation Derby
organisation SecurityAffairs
organisation Patch Released
organisation Xerox
organisation PaperCut Application Servers
organisation BleepingComputer
organisation The Blue Report 2026
organisation PaperCut Zero-Day
organisation SetupCompleted
organisation University
organisation Application Servers
Tactical Metrics
Metrics
victims
395
Organizations
Metrics
victims
11
Organizations
Metrics
victims
280
Victims
Metrics
victims
12
Organizations
Metrics
infrastructure
‎Windows
Affected Product
Metrics
infrastructure
2,500
Papercut Installations
Metrics
infrastructure
‎8.8
Software Version
Metrics
infrastructure
‎Linux
Affected Product
Metrics
infrastructure
‎Macos
Affected Product