Home ยท Wiki ยท Incidents & Campaigns
type: incident ยท created: 2026-09-11 ยท updated: 2026-09-11 ยท tags: [incident, papercut, ai-orchestrated, education, exploitation, russia, agentic-ai] ยท confidence: high ยท severity: critical ยท affected_sectors: [education, government, technology] ยท au_impact: true

A suspected Russian-speaking operator used hundreds of AI agents, built on OpenAI's Codex and a DeepSeek model alongside commodity offensive tooling (Mimikatz, SharpHound, Certipy, Rubeus, Impacket), to research, build and validate exploits against PaperCut NG/MF and compromise at least 440 instances across 395 named victim organisations in 48 countries. Education was the dominant target vertical at roughly half of all victims. The entry vector was CVE-2026-81578 (authentication bypass) chained with CVE-2026-82078 (remote code execution), both patched in PaperCut's 27โ€“28 August 2026 releases and already being exploited when disclosed. Australia appears on the list of targeted countries, and the vendor PaperCut Software is Melbourne-headquartered.

Attribute Detail
First observed 2026-08-31 (recovered operator infrastructure)
Victims 440+ instances / 395 organisations / 48 countries
Attribution Suspected Russian-speaking operator; overlap with the IP 45.142.193[.]132
Entry vector CVE-2026-81578 + CVE-2026-82078
Reporting GreyNoise and Blackpoint (independent), Arctic Wolf (prior week)
Targeted AU Yes โ€” Australia named among targeted countries

GreyNoise recorded the operator moving from an empty workspace to real-world remote code execution in under four hours, then compromising at least 11 organisations in 26 seconds once the campaign launched; against one US high school, initial access to full domain administrator took seven minutes. Post-exploitation yielded credential dumps from 280 victims, OS or domain secrets from 147, and domain administrator access at 12 organisations, achieved via LSASS memory dumping, pass-the-hash, noPac and DCSync NTDS.dit extraction. The operator's own infrastructure shows an AI-assisted pipeline: comparing patched and unpatched PaperCut builds, generating target lists through the Netlas internet-scanning service, filtering candidates by country against an exclusion list of 28 jurisdictions (Russia, China, Iran and others โ€” restraint that GreyNoise found the agents did not consistently apply), then categorising targets by OS and environment and running repeated retry waves. The end goal is unconfirmed; Blackpoint assesses the methodology as consistent with initial-access activity but has not established whether the operator is acting as an access broker.

This is an escalation of the PaperCut exploitation first covered in the 2026-09-09/10 digests (see attackers-exploit-papercut-flaws-to-steal-credentials-from-schools-and-universit.md and papercut-warns-of-ng-mf-flaw-actively-exploited-in-zero-day-attacks.md), adding agentic AI orchestration, the victim count and the measured attack tempo.