PaperCut Attacker Uses Hundreds of AI Agents to Compromise 440+ Instances
AI Summary
A suspected Russian-speaking threat actor has exploited CVE-2026-81578 and CVE-2026-82078, a vulnerability chain in PaperCut NG/MF involving authentication bypass and remote code execution, to compromise at least 440 instances across 395 organizations in 48 countries. The attacker used AI agents powered by OpenAI Codex and DeepSeek, along with offensive tools like Mimikatz and Impacket, to automate exploitation and post-compromise activities including credential harvesting and domain reconnaissance. The campaign targeted primarily the education sector and demonstrated rapid lateral movement, with some attacks achieving domain administrator access in under seven minutes. The actor’s ultimate objectives remain unclear, though activity suggests potential initial access brokering or preparation for follow-on attacks such as data theft or ransomware.
AI-extracted · verify before operational use