{"id":621705,"date":"2026-09-11T19:08:23","date_gmt":"2026-09-11T19:08:23","guid":{"rendered":"https:\/\/www.newsbeep.com\/ie\/621705\/"},"modified":"2026-09-11T19:08:23","modified_gmt":"2026-09-11T19:08:23","slug":"hundreds-of-ai-agents-helped-papercut-attacker-hit-395-orgs-and-some-went-off-script","status":"publish","type":"post","link":"https:\/\/www.newsbeep.com\/ie\/621705\/","title":{"rendered":"Hundreds of AI agents helped PaperCut attacker hit 395+ orgs, and some went off script"},"content":{"rendered":"<p class=\"kicker above\" style=\"\">\n        security\n    <\/p>\n<p class=\"subtitle below\" style=\"\">\n        Human operator: don&#8217;t touch CIS orgs. AI agents: look a squirrel!\u00a0\n    <\/p>\n<p>An unknown attacker used hundreds of AI agents to exploit two PaperCut MF\/NG bugs and break into at least 395 organizations. The victims were concentrated in the US education sector, and the intrusions moved fast. In one case, an American high school went from initial access to domain admin in seven minutes.<\/p>\n<p>These agents, powered by OpenAI\u2019s Codex harness and a DeepSeek model, also allowed the miscreant to attack organizations at scale, according to threat-intel firm GreyNoise, which traced the campaign\u2019s orchestration to 45.142.193.132 on August 31.<\/p>\n<p>\u201cThe adversary went from an empty workspace to first achieving RCE against a real victim in just under four hours, first domain admin in an additional two hours, and once the full campaign launched, compromised at least 11 organizations in 26 seconds,\u201d GreyNoise analysts said in a Wednesday <a href=\"https:\/\/www.greynoise.io\/blog\/ai-orchestrated-campaign-against-papercut-ng-mf\" rel=\"nofollow noopener\" target=\"_blank\">report<\/a>.<\/p>\n<p>The security provider attributes these intrusions to a \u201clikely Russian-speaking\u201d criminal who used AI to develop exploits against the pair of PaperCut vulnerabilities disclosed just days earlier.\u00a0<\/p>\n<p>On August 28, the print management software provider <a href=\"https:\/\/www.theregister.com\/security\/2026\/08\/28\/print-management-outfit-papercut-is-under-0-day-attack-and-its-drawing-customers-blood\/5293168\" rel=\"nofollow noopener\" target=\"_blank\">issued emergency patches<\/a> for CVE-2026-81578 and CVE-2026-82078, at the time warning that it was \u201caware of confirmed customer incidents and are treating this matter with the highest priority.\u201d The flaws affect PaperCut NG and MF, which are self-hosted Java web applications that by default run with SYSTEM-level privileges on Windows.<\/p>\n<p>PaperCut\u2019s CEO later <a href=\"https:\/\/www.papercut.com\/blog\/news\/behind-the-scenes-august-security-incident\/\" rel=\"nofollow noopener\" target=\"_blank\">said<\/a> that the first reported compromise came in on August 27, and involved an education-sector firm.<\/p>\n<p>On Thursday, PaperCut <a href=\"https:\/\/www.papercut.com\/kb\/Main\/security-bulletin-27-aug-2026-urgent-security-advisory\/\" rel=\"nofollow noopener\" target=\"_blank\">published<\/a> security maintenance releases, which replace the earlier emergency fixes.<\/p>\n<p>By now, however, at least 440 instances hosted by 395 identified victim organizations in 48 countries have been compromised, according to GreyNoise. \u201cThere are other real victims that could not be attributed to a named organization,\u201d the threat signals team wrote.<\/p>\n<p>The human attacker told the agents to avoid targeting entities in 28 countries with the top five being Russia, China, Hong Kong, Thailand, and Iran. Several Commonwealth of Independent States (CIS) countries are on the list, which is why GreyNoise says the crim is likely Russian-speaking.\u00a0<\/p>\n<p>It\u2019s typical for ransomware and other cybercrime operations to expressly <a href=\"https:\/\/www.theregister.com\/cyber-crime\/2026\/06\/02\/dumbass-criminal-breaks-the-first-rule-of-ransomware-club\/5250380\" rel=\"nofollow noopener\" target=\"_blank\">avoid attacking Russia and other CIS countries<\/a>, whose governments often provide safe harbor for extortionists and financially motivated crims &#8211; especially if they also happen to work day jobs as state-sponsored hackers. Plus, local cops tend to ignore the digital break-ins unless the gangs infect any in-country organizations.<\/p>\n<p>However, the agents in the PaperCut attacks didn\u2019t always follow these instructions, and in some cases still hacked organizations based in countries on the do-not-hit list. \u201cIt\u2019s currently uncertain why the [attacker&#8217;s] agents deviated,\u201d GreyNoise said. \u201cBut it is a good example of agents gone wild.\u201d<\/p>\n<p>The US and the UK were the countries with the highest victim count, at 98 and 59, respectively. Schools and other education-industry organizations were, by far, the hardest hit with 204 victims. For comparison, the No. 2 industry (other\/unclassified) had 51, while retail\/commercial\/professional services ranked third with 38 victims.<\/p>\n<p>After using AI to develop exploits, achieve remote code execution, and harvest credentials in a self-hosted lab, the baddie set hundreds of AI agents loose on the open internet to find and attack public-facing, vulnerable instances. \u201cThis campaign appears to be opportunistic,\u201d according to GreyNoise. \u201cThere is a high concentration of US-based targets in the education sector; however, it\u2019s likely that is more attributable to the customer base of PaperCut NG\/MF.\u201d<\/p>\n<p>Interestingly, the attacker did not immediately set to work on post-compromise evil deeds with all of the victims. GreyNoise noted \u201cmultiple-day delays\u201d between gaining initial access and achieving domain admin \u201cbut only due to a lack of action by the adversary.\u201d The fastest time was five minutes, while the longest was 144 minutes.<\/p>\n<p>It\u2019s also unclear if the criminal is only focused on gaining access to compromised organizations &#8211; and then plans to hand the attack off to affiliates or other data-theft, extortion, and ransomware groups &#8211; or if they plan to use this access for follow-on nefarious activities of their own.<\/p>\n<p>GreyNoise does note that, in at least one case, Cloudflare\u2019s Web Application Firewall (WAF) blocked the attacker. \u201cFundamental hardening of environments still matters against AI-enabled threats,\u201d they wrote.<\/p>\n<p>It\u2019s also worth noting that GreyNoise has been tracking malicious use of <a href=\"https:\/\/viz.greynoise.io\/ips\/45.142.193.132\" rel=\"nofollow noopener\" target=\"_blank\">45.142.193.132<\/a> since early July, and says this IP has been used in attacks against internet facing technologies and devices from Palo Alto, Ubiquiti, Citrix, SonicWall, and Proxmox VE. \u00ae<\/p>\n","protected":false},"excerpt":{"rendered":"security Human operator: don&#8217;t touch CIS orgs. AI agents: look a squirrel!\u00a0 An unknown attacker used hundreds of&hellip;\n","protected":false},"author":2,"featured_media":621706,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[20],"tags":[220,218,219,61,60,80],"class_list":["post-621705","post","type-post","status-publish","format-standard","has-post-thumbnail","category-artificial-intelligence","tag-ai","tag-artificial-intelligence","tag-artificialintelligence","tag-ie","tag-ireland","tag-technology"],"_links":{"self":[{"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/posts\/621705","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/comments?post=621705"}],"version-history":[{"count":0,"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/posts\/621705\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/media\/621706"}],"wp:attachment":[{"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/media?parent=621705"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/categories?post=621705"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/tags?post=621705"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}