Agents Gone Wild: An AI-Orchestrated Global Campaign Against PaperCut NG/MF
Agents Gone Wild: An AI-Orchestrated Global Campaign Against PaperCut NG/MF
GreyNoise
September 9, 2026
GreyNoise observes adversary activity through our Global Observation Grid (GOG), a network of sensors that draws attacker scanning and exploitation onto infrastructure we control. This lets us study adversary infrastructure, tooling, and tradecraft directly, without waiting for a victim investigation. GreyNoise has been tracking malicious use of 45.142.193.132 since early July 2026 due to its use for attacks against internet facing technologies and devices from Palo Alto, Ubiquiti, Citrix, SonicWall, and Proxmox VE.
On 31 August 2026, a likely Russian-speaking malicious cyber actor (MCA) used 45.142.193.132 and artificial intelligence (AI) to develop, test, and use exploits for PaperCut NG/MF (CVE-2026-81578 and CVE-2026-82078). PaperCut is print management software that enables organizations to track, charge, and manage printing, copying, and scanning jobs for organizations. PaperCut offers cloud and self-hosted versions. PaperCut NG and MF are self-hosted Java web applications that by default run with SYSTEM-level privileges on Windows and are usually domain-joined and integrated with Active Directory. As part of the adversary’s exploit development and testing, they built and attacked a lab environment that included the vulnerable PaperCut software and an Active Directory server. In parallel workflows, the adversary built target lists using an internet scanning service Netlas.io using an identified API key.
Once the adversary achieved remote code execution (RCE) and credential harvesting in its self-hosted lab environment, they used hundreds of AI Agents powered by OpenAI’s Codex (harness), a DeepSeek model (not OpenAI models), and various publicly available offensive security tools to opportunistically compromise at least 440 instances of PaperCut MF/NG hosted by 395 identified victim organizations in 48 countries. There are other real victims that could not be attributed to a named organization. The adversary did explicitly attempt to avoid targeting entities in 28 identified countries; however, our observed victimology shows the attempted restraint failed in some instances.
It’s clear that large language models (LLM) are enabling adversaries to move at greater speed and scale. The adversary went from an empty workspace to first achieving RCE against a real victim in just under four hours, first domain admin in an additional two hours, and once the full campaign launched, compromised at least 11 organizations in 26 seconds. In one instance, the adversary went from initial access to full domain administrator in seven minutes against a high school in the United States. However, the adversary did not experience success evenly across all victims. GreyNoise observed the adversary achieved domain admin against only 12 victim organizations.
The adversary did not immediately follow-up with all compromised victims, so there were multiple-day delays between initial access and achievement of domain admin but only due to a lack of action by the adversary. Where domain admin was achieved, the adversary’s fastest time was five minutes and the longest time was 144 minutes. At GreyNoise’s time of last observation, the adversary had not achieved domain admin against the other victims. In at least one instance of targeting a perceived vulnerable PaperCut instance, Cloudflare’s Web Application Firewall (WAF) defeated the adversary. Fundamental hardening of environments still matters against AI-enabled threats.
It is unclear if this actor is solely focused on access development to be handed off to other affiliated actors or if they will directly leverage their accesses to achieve follow-on objectives such as data theft or ransomware deployment. In the past, other intrusions involving exploitation of PaperCut have led to extortion. GreyNoise partnered with industry leading incident response services organizations to conduct victim notifications around the clock.
Incident timelineTLP:CLEAR
PaperCut mass exploitation by an AI agent
AI agents directed by a malicious cyber actor (MCA) used OpenAI's Codex with a DeepSeek model.
25 dated events on 4 daysUnauthorized accessSelect a date to read it.
From its orchestration host, the MCA downloads the advisory and pre- and post-patch versions of the software, then searches the internet for public proofs of concept and exploits.
Installer components for the vulnerable and patched versions are extracted and diffed. The exploits are tested against patched and unpatched servers in Africa.
Aug 31, 2026 · 16:04:42 UTC
MCA is prompted for permission to continue
Aug 31, 2026 · 16:09:31 UTC
Multi-threaded tool built
Built to operationalize the previous findings in furtherance of the attack.
1,005 potential target addresses resolved to countries
Using a downloaded IP2Location LITE DB1 country database.
Aug 31, 2026 · 16:35:10 UTC
Local lab built
An Active Directory server and a vulnerable PaperCut server.
Aug 31, 2026 · 16:46:47 UTC
Target list refined
Aug 31, 2026 · 16:58:46 UTC
Target list refined again
Aug 31, 2026 · 17:02:12 UTC
Lab gains 8 fake Active Directory users
Aug 31, 2026 · 18:39:39 UTCUnauthorized access
First remote code execution on a real target
Remote code execution and a shell on a real target in Australia.
Aug 31, 2026 · 19:14:46 UTC
Target list excludes 28 countries
The MCA lists them in order, from Russia, China and Hong Kong to Namibia, Nigeria and Zimbabwe.
Aug 31, 2026 · 20:50:00 UTC
Per-target intrusion kits assembled
Compartmentalized "Kali-ready" kits with post-exploitation connectivity scripts. A kit can also create an account and password and add it to Domain Admin.
Using a specific Application Programming Interface (API) key.
Sep 1, 2026 · 08:30:00 UTCUnauthorized access
Agents launch the campaign via a second execution host
Hundreds of SSH sessions to that host. Unauthorized access to 11 organizations in 26 seconds, credential harvesting within a minute, 78 in the first hour, 8 with Domain Admin.
Sep 1, 2026 · 17:01:00 UTC
Cloudflare's Web Application Firewall defeats the MCA
Targeting a host behind Cloudflare fails. The MCA also notices performance issues and adjusts thread usage for targets in the United States.
Sep 1, 2026 · 17:15:00 UTC
Bug found and fixed automatically
The campaign continues harvesting credentials.
Sep 1, 2026 · 23:12:04 UTCUnauthorized access
Last remote code execution of Sep 1
Unauthorized access to more than 223 PaperCut systems.
Despite U.S. based frontier model guardrails, adversaries are using a variety of large language models to conduct intrusions globally
AI enables fast and efficient complex orchestration of cyber operations; however, unless properly constrained, agentic operations can deviate from expected behavior and pose operational risk
Organizations are not helpless against agentic attacks and traditional hardening does have a positive impact on the security posture of an organization
Intrusion Attack Lifecycle
Where domain admin was achieved, GreyNoise observed three attack paths:
Attack Path A.
If the compromised PaperCut host was a domain member, the adversary harvested LSASS process memory and registry secrets to recover privileged credentials to pass-the-hash to the domain controller.
Attack Path B.
In instances where the victim had not patched for CVE-2021-42278 and CVE-2021-42287, the adversary used a ‘noPac’ attack.
Attack Path C.
If the compromised PaperCut host was on the Domain Controller itself or running as a Domain-Admin service account, the adversary simply added its newly created account to Domain Admins.
In all Attack Paths, the adversary used DCSync to create a full NTDS.DIT dump to exfiltrate the organization’s credentials.
GreyNoise Community CTA
Free community account
Tell signal from noise, for free.
Create a free GreyNoise account and start telling internet noise apart from real threats. No credit card required.
50 IP lookups a week, plus live dashboards and up to 3 alerts
Weekly At The Edge Clear threat briefs and access to GreyNoise Experiments
Sign up with a work email for 10-day lookback, bulk lookups, and API access
Note that these IOCs are not exhaustive, the AI-enabled adversary continued to make necessary changes on the fly. GreyNoise will continue to add new IOCs on our GitHub.
The MCA had a library of publicly available offensive security tools used to expand access to the enterprise environment. Note that not all of these tools were observed in active use during this campaign.
This campaign appears to be opportunistic. There is a high concentration of U.S. based targets in the education sector; however, it’s likely that is more attributable to the customer base of PaperCut NG/MF.
The adversary used a list of defined countries to avoid that existed from previous campaigns. It’s currently uncertain why the MCA’s agents deviated, but it is a good example of Agents Gone Wild. The countries to avoid in order were: Russia, China, Hong Kong, Thailand, Iran, Venezuela, Belarus, Kazakhstan, Kyrgyzstan, Tajikistan, Turkmenistan, Uzbekistan, Armenia, Azerbaijan, Moldova, Ukraine, Brazil, Vietnam, Indonesia, Pakistan, Tanzania, Bangladesh, Afghanistan, Turkey, South Africa, Namibia, Nigeria, and Zimbabwe.
Volume by Country
Country
Victims
Credential Harvesting
OS / Domain Secrets
Domain Admin
United States
98
59
31
1
United Kingdom
59
40
20
3
France
31
23
12
1
Spain
31
20
8
—
Canada
24
10
8
3
Belgium
16
13
8
1
Portugal
16
9
5
1
Australia
15
8
4
—
Germany
15
8
2
1
Switzerland
14
9
1
—
Italy
13
8
7
—
Taiwan
12
11
10
—
Singapore
11
10
1
—
Netherlands
9
6
5
—
South Africa
9
2
1
1
Sweden
8
5
3
—
Brazil
5
2
0
—
Malaysia
5
4
3
—
Denmark
4
3
1
—
Ireland
4
3
2
—
New Zealand
4
3
1
—
Argentina
3
1
0
—
India
3
3
2
—
Cambodia
2
2
2
—
Chile
2
1
1
—
Finland
2
1
1
—
Greece
2
1
0
—
Japan
2
0
0
—
Puerto Rico
2
2
0
—
Austria
1
1
0
—
Botswana
1
1
1
—
Bulgaria
1
0
0
—
China
1
0
0
—
Colombia
1
0
0
—
Ecuador
1
0
0
—
Estonia
1
1
1
—
Kazakhstan
1
0
0
—
Lithuania
1
1
1
—
Mexico
1
1
1
—
Namibia
1
1
0
—
Nigeria
1
1
1
—
Pakistan
1
0
0
—
Philippines
1
1
0
—
Poland
1
1
1
—
Romania
1
1
1
—
Saudi Arabia
1
1
0
—
Sri Lanka
1
1
1
—
Zimbabwe
1
1
0
—
Total
440
280
147
12
Volume by Industry
Industry
Victims
Credential Harvesting
OS / Domain Secrets
Domain Admin
Education
204
129
67
7
Other / unclassified
51
32
18
1
Retail / Commercial / Professional services
38
28
16
2
Real estate / Coworking / Hospitality
29
20
6
—
IT / MSP / Print reseller
25
17
8
—
Non-profit / Religious / Charity
21
16
9
2
Unknown (unattributed)
15
6
3
—
Library / Archive
13
9
8
—
Manufacturing / Industrial / Energy / Utilities
13
7
3
—
Government / Public sector
9
6
3
—
Healthcare / Social care
8
3
2
—
Legal
8
3
2
—
Financial / Insurance
6
4
2
—
Total
440
280
147
12
GreyNoise will continue monitoring the situation and report updates as needed.
This article is a summary of the full, in-depth version on the GreyNoise Labs blog.
How it works
Once you click Generate, Ollama reads this article and crafts 5 comprehension questions. Your answers are graded against the article content — general knowledge won't be enough. Score 70+ to count toward your certificate.
Questions are cached — you'll always get the same 5 for this article.