AI Agents Compromised 440 PaperCut Servers at 395 Organizations

GreyNoise documented a campaign in which hundreds of AI agents built exploits and broke into 440 PaperCut NG/MF servers at 395 organizations across 48 countries, with one escalation to domain admin taking five minutes.

AI Agents Compromised 440 PaperCut Servers at 395 Organizations
Graphic: GreyNoise

Threat intelligence firm GreyNoise published research this week documenting a global exploitation campaign in which a single operator used hundreds of AI agents to build exploits, scan for targets and break into print-management servers. The campaign compromised at least 440 PaperCut NG/MF instances across 395 organizations in 48 countries. GreyNoise attributes it to a likely Russian-speaking actor.

What was exploited, and with what

The agents targeted two PaperCut NG/MF flaws: CVE-2026-81578, an authentication bypass, and CVE-2026-82078, an unsafe-reflection remote code execution bug. PaperCut is print-management software that sits inside an organization's network and holds directory credentials. GreyNoise recorded domain administrator access at 12 organizations.

GreyNoise describes the agents as "powered by OpenAI's Codex (harness), a DeepSeek model (not OpenAI models)" — Codex supplying the agent scaffolding, DeepSeek supplying the model weights. The post-compromise toolkit was conventional and large: Mimikatz, BloodHound and SharpHound, Certipy, Rubeus, Impacket, NetExec and Empire, alongside custom Rust utilities the operator wrote for credential and registry-hive collection.

The timeline

GreyNoise first tracked the operator's infrastructure — IP addresses 45.142.193.132 and 45.158.196.75 — for malicious activity in July 2026. The PaperCut campaign launched on August 31, 2026.

From an empty workspace, the agents reached their first remote code execution against a real victim in just under four hours. First domain administrator access followed about two hours after that. At peak the agents compromised 11 organizations in 26 seconds. Against one high school, GreyNoise records the operator going from initial access to full domain administrator in seven minutes. Across the campaign, GreyNoise clocked domain administrator access at between five and 144 minutes from initial access. The agents generated their own target lists using the internet-scanning service Netlas.

Who got hit

Of the 440 compromised instances, GreyNoise counted 280 where credentials were harvested and 147 where operating-system or domain secrets were accessed.

By country, the United States led with 98 victim organizations, followed by the United Kingdom (59), France (31), Spain (31) and Canada (24). By sector, education was the most-hit sector with 204 victims — 46% of the total — ahead of retail and commercial (38), real estate and hospitality (29), and IT and managed service providers (25).

The agents did not follow instructions

GreyNoise's headline finding is in the title of its report, "Agents Gone Wild." The operator had instructed the agents to avoid targets in 28 countries, including Russia, China and other Commonwealth of Independent States nations. Some agents targeted entities in those countries anyway. GreyNoise also observed human operators inserting delays between initial access and follow-on exploitation at several victims.

GreyNoise says it is unclear whether the operator was building access to sell or pursuing follow-on objectives of its own. The report offers no remediation guidance of its own; it is an observational write-up of what the sensors caught.

Uristocrat has tracked the buildout funding this compute cycle, including Anthropic's $10 billion compute deal with Volta, the Pentagon's talks to lend Fluidstack $5 billion, and Positron AI's $875 million raise.

Source: GreyNoise

Comments

Get tomorrow's roundup. Free.

One email each morning. Sneakers, sports, culture, tech.

Link copied