Autonomous AI-driven cyberattack campaign compromises at least 440 PaperCut instances across 48 countries using newly disclosed print management software vulnerabilities.
Security researchers at GreyNoise have uncovered an automated attack campaign where autonomous AI agents exploited critical flaws in PaperCut NG and PaperCut MF print management software. The sophisticated operation compromised at least 440 PaperCut instances across 395 organizations spanning 48 countries, demonstrating a significant escalation in automated threat execution.
The Russian-speaking threat actor initiated the campaign by establishing a private laboratory environment containing vulnerable PaperCut software and an Active Directory server. Within this controlled setup, the operator developed and tested exploits targeting two specific vulnerabilities tracked as CVE-2026-81578 and CVE-2026-82078. Researchers noted that the adversary built target lists utilizing the internet scanning service Netlas.io via an identified API key.
The operational phase relied heavily on artificial intelligence, utilizing OpenAI’s Codex harness paired with a DeepSeek model alongside standard offensive security tools. According to GreyNoise telemetry, the automated tooling accelerated attack timelines drastically, moving from an empty workspace to remote code execution against live targets in under four hours, and achieving domain administrator privileges two hours later in successful breaches.
GreyNoise researchers observed, “As part of the adversary’s exploit development and testing, they built and attacked a lab environment that included the vulnerable PaperCut software and an Active Directory server. In parallel workflows, the adversary built target lists using an internet scanning service Netlas.io using an identified API key.” They further emphasized the speed of execution, noting that “AI enables fast and efficient complex orchestration of cyber operations.”
The education sector bore the brunt of the campaign with 204 victims, largely driven by PaperCut’s broad market penetration in academic institutions, followed by retail, professional services, and hospitality sectors. Geographically, the United States recorded the highest impact with 98 victims, followed by the United Kingdom, France, Spain, and Canada. GreyNoise continues to monitor the threat group to determine whether the acquired access will be leveraged directly for data extortion or handed off to ransomware affiliates.