A suspected Russian-speaking cyber actor has used artificial intelligence to automate the exploitation of two recently disclosed security flaws in PaperCut NG/MF, compromising at least 440 instances across 48 countries, according to new research from GreyNoise.

The campaign targeted CVE-2026-81578 and CVE-2026-82078, a combination of authentication bypass and remote code execution vulnerabilities. The attacker reportedly used the IP address 45.142.193.132, which GreyNoise has been tracking since July for suspicious scanning and attacks against internet-facing systems.

GreyNoise said the attacker first built a laboratory environment containing vulnerable PaperCut software and an Active Directory server. After developing and testing the exploit, the actor used hundreds of AI agents alongside tools such as Mimikatz, SharpHound, Certipy, Rubeus and Impacket to automate attacks against real organizations.

The campaign compromised at least 440 PaperCut NG/MF instances belonging to 395 identified organizations. Education was the most heavily affected sector, with 204 victims recorded in GreyNoise’s analysis. The United States, United Kingdom, France, Spain and Canada were among the countries with the highest number of affected organizations.

What makes the campaign particularly notable is how quickly the attacker moved from vulnerability research to large-scale exploitation. GreyNoise said the actor went from an empty workspace to remote code execution against a real victim in less than four hours. After the campaign was launched, at least 11 organizations were compromised within just 26 seconds. In one case involving a U.S. high school, the attacker reached full domain administrator access only seven minutes after gaining initial access.

READ
Plex Warns as 36,000+ Media Servers Remain Vulnerable

The attacker did not gain domain administrator access everywhere. GreyNoise observed that level of access at 12 victim organizations. In successful cases, attackers used several paths to harvest credentials and obtain deeper access to Windows and Active Directory environments.

The campaign also shows how AI is being incorporated into more than just exploit development. Researchers found evidence of automated workflows for identifying targets, filtering organizations by country, tracking successful and failed attacks, troubleshooting problems and retrying unsuccessful attempts.

GreyNoise said the actor attempted to avoid organizations in 28 countries, although that restriction did not always work. The research also found that the attacker used an internet scanning service to build lists of potentially vulnerable PaperCut systems.

The final objective remains unknown. Researchers have not determined whether the attacker was primarily collecting access to sell or hand over to other criminal groups, or whether the compromised systems could later be used for data theft, ransomware or other attacks.

The campaign highlights a growing concern in cybersecurity: AI can significantly reduce the amount of human work required to research vulnerabilities, write and test attack code, identify targets and manage large-scale exploitation. In this case, the technology appears to have helped turn what would normally be a labor-intensive process into a highly automated operation.


Buy ExpressVPN with PayPal or Credit Card

Organizations running PaperCut NG/MF should ensure the software is fully patched and that internet-facing systems are properly hardened. GreyNoise’s findings also demonstrate that traditional security measures can still make a difference, including controls that prevent exposed services from being directly exploited.

READ
IDScan Confirms Massive Breach After Hackers Stole More Than 150 Million Drivers’ Licenses
Advertisement