A suspected Russian-speaking operator used hundreds of AI agents, built on OpenAI's Codex and a DeepSeek model alongside commodity offensive tooling (Mimikatz, SharpHound, Certipy, Rubeus, Impacket), to research, build and validate exploits against PaperCut NG/MF and compromise at least 440 instances across 395 named victim organisations in 48 countries. Education was the dominant target vertical at roughly half of all victims. The entry vector was CVE-2026-81578 (authentication bypass) chained with CVE-2026-82078 (remote code execution), both patched in PaperCut's 27โ28 August 2026 releases and already being exploited when disclosed. Australia appears on the list of targeted countries, and the vendor PaperCut Software is Melbourne-headquartered.
| Attribute | Detail |
|---|---|
| First observed | 2026-08-31 (recovered operator infrastructure) |
| Victims | 440+ instances / 395 organisations / 48 countries |
| Attribution | Suspected Russian-speaking operator; overlap with the IP 45.142.193[.]132 |
| Entry vector | CVE-2026-81578 + CVE-2026-82078 |
| Reporting | GreyNoise and Blackpoint (independent), Arctic Wolf (prior week) |
| Targeted AU | Yes โ Australia named among targeted countries |
GreyNoise recorded the operator moving from an empty workspace to real-world remote code execution in under four hours, then compromising at least 11 organisations in 26 seconds once the campaign launched; against one US high school, initial access to full domain administrator took seven minutes. Post-exploitation yielded credential dumps from 280 victims, OS or domain secrets from 147, and domain administrator access at 12 organisations, achieved via LSASS memory dumping, pass-the-hash, noPac and DCSync NTDS.dit extraction. The operator's own infrastructure shows an AI-assisted pipeline: comparing patched and unpatched PaperCut builds, generating target lists through the Netlas internet-scanning service, filtering candidates by country against an exclusion list of 28 jurisdictions (Russia, China, Iran and others โ restraint that GreyNoise found the agents did not consistently apply), then categorising targets by OS and environment and running repeated retry waves. The end goal is unconfirmed; Blackpoint assesses the methodology as consistent with initial-access activity but has not established whether the operator is acting as an access broker.
This is an escalation of the PaperCut exploitation first covered in the 2026-09-09/10 digests (see attackers-exploit-papercut-flaws-to-steal-credentials-from-schools-and-universit.md and papercut-warns-of-ng-mf-flaw-actively-exploited-in-zero-day-attacks.md), adding agentic AI orchestration, the victim count and the measured attack tempo.