PaperCut Flaws Exploited in AI-Powered Attacks
A Russian-speaking threat actor has leveraged AI to exploit two PaperCut vulnerabilities, compromising over 440 instances across 48 countries and targeting organizations in various sectors. The campaign involved automated exploitation, credential harvesting, and attempts to gain domain admin privileges, highlighting the increasing sophistication of attacks utilizing AI.
Two recent PaperCut NG/MF vulnerabilities, tracked as CVE-2026-82078 and CVE-2026-81578, were exploited in AI-powered attacks impacting hundreds of organizations worldwide, according to GreyNoise. These security defects allowed remote unauthenticated attackers to bypass authentication and execute arbitrary code on vulnerable PaperCut NG/MF instances.
Several days after the vulnerabilities were disclosed, WatchTowr threat intelligence head Jake Knott warned of intensifying activity, suggesting initial access brokers were likely behind the exploitation. GreyNoise subsequently revealed that a Russian-speaking threat actor utilized AI to build, test, and deploy exploits against these vulnerable instances.
The threat actor targeted 440 PaperCut NG/MF deployments in 48 countries, with 395 belonging to organizations in 28 identified countries. The campaign focused on remote code execution (RCE) and credential harvesting, with the attacker explicitly attempting to avoid targeting entities in 28 countries, though this restraint was not always successful.
The attacker employed three attack paths: harvesting LSASS process memory and registry secrets from domain members, mounting NoPac attacks against unpatched instances, and adding a new account to Domain Admins if the host was a Domain Controller. GreyNoise reported that the attacker harvested credentials from 280 compromised hosts and exfiltrated secrets from 137 of them, achieving domain admin privileges in 12 instances.
Specifically, 204 compromised deployments were located within organizations in the education sector, alongside entities in retail/professional services, real estate/hospitality, IT/MSP, non-profit/charity, library, and manufacturing/utilities sectors. The campaign underscored the potential for AI to accelerate and amplify exploitation efforts, raising concerns about the broader impact on organizations’ security posture.