INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
PaperCut Attacker Orchestrates Global Campaign Using Hundreds of AI Agents
| 2026-09-09 15:36 HIGH HIGH AI-ENABLED ATTACK CYBERATTACK (GENERAL)
Executive Summary
AI-generated
On September 10, 2026, hundreds of AI agents helped an unknown attacker exploit two PaperCut vulnerabilities and breach at least 395 organizations in the US education sector. The attack is attributed to a "likely Russian-speaking" criminal who used AI to develop exploits against the pair of vulnerabilities disclosed just days earlier. The attackers targeted entities in 28 countries, with Russia, China, Hong Kong, Thailand, and Iran being the top five on the list. However, some agents deviated from their instructions and still hacked organizations based in countries on the do-not-hit list. The attack allowed the attacker to compromise at least 11 organizations in just 26 seconds after the full campaign launched.
Technical Mitigations AI-generated
• Apply the vendor fix for CVE-2026-82078, CVE-2026-81578 and treat internet-facing systems that were not patched in time as potentially compromised until verified.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected
Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.
45.142.•••.•••
ww•••••.io
pc•••••.hiv
pc•••••.hiv
ne•••••.io
159989••••••••••••••••••••••••••••••••••
77e981••••••••••••••••••••••••••••••••••
577fa0••••••••••••••••••••••••••••••••••
4e24bf••••••••••••••••••••••••••••••••••
hxxp://••••••••••••••••••••
hxxp://••••••••••••••••••••
c852d5••••••••••••••••••••••••••••••••••••••••••••••••••••••••••
14779d••••••••••••••••••••••••••••••••••••••••••••••••••••••••••
6dca0e••••••••••••••••••••••••••••••••••••••••••••••••••••••••••
c3f710••••••••••••••••••••••••••••••••••••••••••••••••••••••••••
a6437a••••••••••••••••••••••••••
ce870a••••••••••••••••••••••••••
fc92df••••••••••••••••••••••••••
974dec••••••••••••••••••••••••••
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2026-82078CVE-2026-82078
CVE-2026-81578CVE-2026-81578
Target & Sectors
BENELUX
BENELUX
NORDICS
NORDICS
DACH
DACH
ASEAN
ASEAN
CIS
CIS
LATAM
LATAM
SOUTH_ASIA
SOUTH_ASIA
NORTH_AMERICA
NORTH_AMERICA
educationeducation
healthhealth
Incident Timeline
July 2026
Threat actors used IP 45.142.193.132 to orchestrate a global campaign targeting Domain administrators in 12 organizations, primarily affecting educational institutions in the United States since July 2026.
Click on any entity below to view its context and source!
observable
45.142.193.132
The campaign originated from IP 45.142.193.132, which had been tracked since July 2026 for attacks against various technologies.
organisation
IP 45.142.193.132
The campaign originated from IP 45.142.193.132, which had been tracked since July 2026 for attacks against various technologies.
victims
12 organizations
Domain administrator access was confirmed in 12 organizations, primarily affecting educational institutions in the United States.
early July 2026
GreyNoise detected the malicious use of SonicWall IP addresses since early July 2026 for probing internet-facing systems from multiple vendors.
Click on any entity below to view its context and source!
organisation
GreyNoise
GreyNoise said it has been tracking the malicious use of the IP address since early July 2026 for probing internet-facing systems from several vendors, including Palo Alto, Ubiquiti, Citrix, SonicWall, and Proxmox VE.
organisation
SonicWall
GreyNoise said it has been tracking the malicious use of the IP address since early July 2026 for probing internet-facing systems from several vendors, including Palo Alto, Ubiquiti, Citrix, SonicWall, and Proxmox VE.
August 27
Threat actors used AI to orchestrate a global campaign against PaperCut NG/MF, compromising an education-sector firm on August 27.
Click on any entity below to view its context and source!
industry
Education
PaperCut’s CEO later
said
that the first reported compromise came in on August 27, and involved an education-sector firm.
August 28
Threat actors used the unpatched vulnerabilities in print management software CVE-2026-81578 and CVE-2026-82078 to orchestrate a global campaign against PaperCut NG/MF.
Click on any entity below to view its context and source!
vulnerability
CVE-2026-81578
On August 28, the print management software provider
issued emergency patches
for CVE-2026-81578 and CVE-2026-82078, at the time warning that it was “aware of confirmed customer incidents and are treating this matter with the highest priority.”
vulnerability
CVE-2026-82078
On August 28, the print management software provider
issued emergency patches
for CVE-2026-81578 and CVE-2026-82078, at the time warning that it was “aware of confirmed customer incidents and are treating this matter with the highest priority.”
general_metric
82078 CVE-2026
On August 28, the print management software provider
issued emergency patches
for CVE-2026-81578 and CVE-2026-82078, at the time warning that it was “aware of confirmed customer incidents and are treating this matter with the highest priority.”
August 31
Threat actors using OpenAI's Codex harness and DeepSeek model launched a global campaign against PaperCut NG/MF, with the earliest activity detected on August 31.
Click on any entity below to view its context and source!
observable
45.142.193.132
These agents, powered by OpenAI’s Codex harness and a DeepSeek model, also allowed the miscreant to attack organizations at scale, according to threat-intel firm GreyNoise, which traced the campaign’s orchestration to 45.142.193.132 on August 31.
organisation
OpenAI’s
These agents, powered by OpenAI’s Codex harness and a DeepSeek model, also allowed the miscreant to attack organizations at scale, according to threat-intel firm GreyNoise, which traced the campaign’s orchestration to 45.142.193.132 on August 31.
organisation
GreyNoise
These agents, powered by OpenAI’s Codex harness and a DeepSeek model, also allowed the miscreant to attack organizations at scale, according to threat-intel firm GreyNoise, which traced the campaign’s orchestration to 45.142.193.132 on August 31.
organisation
PaperCut
"The earliest recovered activity began on August 31, with the project focused on vulnerability research and comparing patched and unpatched PaperCut builds," Beal and security researcher Sam Decker wrote.
2026/09/03
Threat actors used an AI to orchestrate a global campaign targeting PaperCut NG/MF, with the same IP address also flagged by Arctic Wolf in connection with exploitation activity on September 3, 2026.
2026/09/09
A suspected Russian-speaking cyber actor used hundreds of AI agents powered by OpenAI Codex and DeepSeek models to exploit vulnerabilities in PaperCut NG/MF, compromising at least 440 instances across 395 organizations in 48 countries.
Click on any entity below to view its context and source!
organisation
PaperCut NG/MF
A likely Russian-speaking malicious cyber actor leveraged artificial intelligence to orchestrate a global campaign exploiting PaperCut NG/MF print management software via CVE-2026-81578 and CVE-2026-82078.
“There is a high concentration of US-based targets in the education sector; however, it’s likely that is more attributable to the customer base of PaperCut NG/MF.”
organisation
Several Commonwealth of Independent States
Several Commonwealth of Independent States (CIS) countries are on the list, which is why GreyNoise says the crim is likely Russian-speaking.
victims
12 organizations
In all, the adversary is said to have gained domain administrator access against only 12 victim organizations.
organisation
OpenAI
Using AI agents powered by DeepSeek models and OpenAI's Codex, the adversary moved from empty workspace to first remote code execution in under four hours, compromising at least 440 PaperCut instances across 395 organizations in 48 countries.
organisation
PaperCut
Using AI agents powered by DeepSeek models and OpenAI's Codex, the adversary moved from empty workspace to first remote code execution in under four hours, compromising at least 440 PaperCut instances across 395 organizations in 48 countries.
Hundreds of AI agents helped PaperCut attacker hit 395+ orgs, and some went off script.
victims
395 organizations
Using AI agents powered by DeepSeek models and OpenAI's Codex, the adversary moved from empty workspace to first remote code execution in under four hours, compromising at least 440 PaperCut instances across 395 organizations in 48 countries.
By now, however, at least 440 instances hosted by 395 identified victim organizations in 48 countries have been compromised, according to GreyNoise.
"
Upon gaining remote code execution and credential harvesting within its self-hosted lab environment, the threat actor has been observed unleashing hundreds of AI Agents powered by OpenAI Codex, a DeepSeek model, and publicly available offensive security tools (e.g., Mimikatz, SharpHound, Certipy, Rubeus, and Impacket) to compromise no less than 440 instances of PaperCut MF/NG hosted by 395 id…
An unknown attacker used hundreds of AI agents to exploit two PaperCut MF/NG bugs and break into at least 395 organizations.
organisation
OpenAI Codex
"
Upon gaining remote code execution and credential harvesting within its self-hosted lab environment, the threat actor has been observed unleashing hundreds of AI Agents powered by OpenAI Codex, a DeepSeek model, and publicly available offensive security tools (e.g., Mimikatz, SharpHound, Certipy, Rubeus, and Impacket) to compromise no less than 440 instances of PaperCut MF/NG hosted by 395 i…
victims
11 organizations
According to GreyNoise, the attacker swiftly progressed from an empty workspace to first achieving remote code execution against a real victim in just under four hours, and compromised at least 11 organizations in 26 seconds once the campaign began in earnest.
“The adversary went from an empty workspace to first achieving RCE against a real victim in just under four hours, first domain admin in an additional two hours, and once the full campaign launched, compromised at least 11 organizations in 26 seconds,” GreyNoise analysts said in a Wednesday
report
.
organisation
PaperCut Attacker Uses Hundreds
PaperCut Attacker Uses Hundreds of AI Agents to Compromise 440+ Instances.
organisation
PaperCut MF
An unknown attacker used hundreds of AI agents to exploit two PaperCut MF/NG bugs and break into at least 395 organizations.
organisation
SharpHound
…ential harvesting within its self-hosted lab environment, the threat actor has been observed unleashing hundreds of AI Agents powered by OpenAI Codex, a DeepSeek model, and publicly available offensive security tools (e.g., Mimikatz, SharpHound, Certipy, Rubeus, and Impacket) to compromise no less than 440 instances of PaperCut MF/NG hosted by 395 identified victim organizations in 48 countries.
organisation
PaperCut MF/NG
…ential harvesting within its self-hosted lab environment, the threat actor has been observed unleashing hundreds of AI Agents powered by OpenAI Codex, a DeepSeek model, and publicly available offensive security tools (e.g., Mimikatz, SharpHound, Certipy, Rubeus, and Impacket) to compromise no less than 440 instances of PaperCut MF/NG hosted by 395 identified victim organizations in 48 countries.
organisation
IP
It’s also worth noting that GreyNoise has been tracking malicious use of
45.142.193.132
since early July, and says this IP has been used in attacks against internet facing technologies and devices from Palo Alto, Ubiquiti, Citrix, SonicWall, and Proxmox VE.
According to independent reports from
Blackpoint Cyber
and
GreyNoise
, the activity originates from "
45.142.193[.]132
," an IP address that has been linked to unauthorized port scanning and brute-force attack attempts in recent weeks.
organisation
SonicWall
It’s also worth noting that GreyNoise has been tracking malicious use of
45.142.193.132
since early July, and says this IP has been used in attacks against internet facing technologies and devices from Palo Alto, Ubiquiti, Citrix, SonicWall, and Proxmox VE.
victims
204 victims
Schools and other education-industry organizations were, by far, the hardest hit with 204 victims.
victims
38 victims
For comparison, the No. 2 industry (other/unclassified) had 51, while retail/commercial/professional services ranked third with 38 victims.
infrastructure
Windows
The flaws affect PaperCut NG and MF, which are self-hosted Java web applications that by default run with SYSTEM-level privileges on Windows.
"Observed post-exploitation activity included delivery of Windows registry hive collection tools, Metasploit/Meterpreter-related Java payloads, and commands used to identify hosts, users, processes, and sensitive configuration data," Arctic Wolf noted.
organisation
PaperCut NG
The flaws affect PaperCut NG and MF, which are self-hosted Java web applications that by default run with SYSTEM-level privileges on Windows.
organisation
MF
The flaws affect PaperCut NG and MF, which are self-hosted Java web applications that by default run with SYSTEM-level privileges on Windows.
organisation
RCE
“The adversary went from an empty workspace to first achieving RCE against a real victim in just under four hours, first domain admin in an additional two hours, and once the full campaign launched, compromised at least 11 organizations in 26 seconds,” GreyNoise analysts said in a Wednesday
report
.
organisation
Cloudflare’s Web Application Firewall
GreyNoise does note that, in at least one case, Cloudflare’s Web Application Firewall (WAF) blocked the attacker.
organisation
MDR
"At this time, we cannot confirm the exact end goal of this campaign," Nevan Beal, principal MDR analyst at Blackpoint, told The Hacker News.
organisation
The Hacker News
"At this time, we cannot confirm the exact end goal of this campaign," Nevan Beal, principal MDR analyst at Blackpoint, told The Hacker News.
organisation
Netlas.io
"In parallel workflows, the adversary built target lists using an internet scanning service Netlas.io using an identified API key.
organisation
API
"In parallel workflows, the adversary built target lists using an internet scanning service Netlas.io using an identified API key.
organisation
Active Directory
These include tasks like administrator access, account verification, Active Directory collection, domain and network discovery, and proxy setup.
organisation
Hindsight
Supporting the system in this effort are two crucial open-source tools -
Hindsight, which provides a persistent memory service for AI agents AionUi, which provides a unified graphical workspace to run and view multiple AI agents concurrently
The campaign shows threat actors are using AI not just to assist with malware development, but also to troubleshoot failures, preserve project state, an…
Tactical Metrics
Metrics
victims
12
Organizations
Click for context!
Domain administrator access was confirmed in 12 organizations, primarily affecting educational institutions in the United States.
In all, the adversary is said to have gained domain administrator access against only 12 victim organizations.
Metrics
victims
395
Organizations
Using AI agents powered by DeepSeek models and OpenAI's Codex, the adversary moved from empty workspace to first remote code execution in under four hours, compromising at least 440 PaperCut instances across 395 organizations in 48 countries.
An unknown attacker used hundreds of AI agents to exploit two PaperCut MF/NG bugs and break into at least 395 organizations.
By now, however, at least 440 instances hosted by 395 identified victim organizations in 48 countries have been compromised, according to GreyNoise.
"
Upon gaining remote code execution and credential harvesting within its self-hosted lab environment, the threat actor has been observed unleashing hundreds of AI Agents powered by OpenAI Codex, a DeepSeek model, and publicly available offensive security tools (e.g., Mimikatz, SharpHound, Certipy, Rubeus, and Impacket) to compromise no less than 440 instances of PaperCut MF/NG hosted by 395 id…
Metrics
victims
204
Victims
Schools and other education-industry organizations were, by far, the hardest hit with 204 victims.
Metrics
victims
38
Victims
For comparison, the No. 2 industry (other/unclassified) had 51, while retail/commercial/professional services ranked third with 38 victims.
Metrics
infrastructure
Windows
Affected Product
The flaws affect PaperCut NG and MF, which are self-hosted Java web applications that by default run with SYSTEM-level privileges on Windows.
"Observed post-exploitation activity included delivery of Windows registry hive collection tools, Metasploit/Meterpreter-related Java payloads, and commands used to identify hosts, users, processes, and sensitive configuration data," Arctic Wolf noted.
Metrics
victims
11
Organizations
“The adversary went from an empty workspace to first achieving RCE against a real victim in just under four hours, first domain admin in an additional two hours, and once the full campaign launched, compromised at least 11 organizations in 26 seconds,” GreyNoise analysts said in a Wednesday
report
.
According to GreyNoise, the attacker swiftly progressed from an empty workspace to first achieving remote code execution against a real victim in just under four hours, and compromised at least 11 organizations in 26 seconds once the campaign began in earnest.
Intelligence Sources
The Hacker News
2026-09-10
The Register - Cybercrime
2026-09-10
Hundreds of AI agents helped PaperCut attacker hit 395+ orgs, and some went off script
The Register - Cybercrime
AlienVault OTX
2026-09-09
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-10-10T06:31
Comprehensive Tactical Telemetry
Highly Correlated Entities
52x
target region
Target Country
Russian Federation
country
24x
organisation
Identified Entity
PaperCut NG/MF
entity
7x
timeline
Temporal Reference
July 2026
date
3x
victims
Organizations
12
organizations
3x
industry
Targeted Sector
Health
sector
3x
tactic
Cyber Operation Type
Remote Code Execution
tactic
3x
attribution
Attributing Entity
PaperCut NG/MF
authority
2x
vulnerability
Exploited CVE
CVE-2026-81578
cve
2x
general metric
Countries
48
countries
2x
victims
Victims
204
victims
2x
general metric
Industry
2
industry
2x
malware
Offensive Tool
Metasploit
tool
Contextual Telemetry
Context Block
8 METRICS
general metric
Papercut Instances
440
papercut instances
target region
Target Region
CIS
region
general metric
Cve-2026
82,078
cve-2026
infrastructure
Affected Product
Windows
software
general metric
Seconds
26
seconds
general metric
Minutes
144
minutes
source region
Origin Country
Russian Federation
country
tactic
MITRE ATT&CK Technique
T1059.006 - Python
technique
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.