Russian Actor Uses AI to Exploit PaperCut Flaws at 440 Sites
Threat intelligence firm GreyNoise traces campaign that achieved domain admin access in minutes using AI-assisted exploit development.

AI-Accelerated Exploitation Campaign Hits Hundreds
A Russian-speaking threat actor has weaponized artificial intelligence to exploit two recently disclosed PaperCut vulnerabilities, compromising 440 deployments across 395 organizations in 48 countries, according to threat intelligence firm GreyNoise.
The campaign targeted CVE-2026-82078 and CVE-2026-81578, authentication bypass and remote code execution flaws in PaperCut NG/MF that were disclosed as zero-days on August 27 and patched the following day. The vulnerabilities allow remote unauthenticated attackers to bypass authentication mechanisms and execute arbitrary code on vulnerable instances.
Speed and Scale Through Automation
What distinguishes this campaign is the attacker's use of AI to build, test, and deploy exploits at unprecedented speed. GreyNoise reports that the threat actor compromised some environments in minutes—and in certain cases, seconds. This automation enabled the attacker to operate at a scale that would be difficult to achieve through manual exploitation.
The attacker achieved domain administrator privileges against 12 victim organizations, though success rates varied significantly across targets. The threat actor attempted to avoid entities in 28 identified countries, though GreyNoise observed that this geographic restraint failed in some instances.
Attack Methodology and Impact
GreyNoise identified three distinct attack paths deployed across the campaign. Attackers harvested credentials from the LSASS process memory and registry secrets on domain member hosts, executed NoPac attacks against unpatched instances, and in cases where the compromised host was a Domain Controller, added new accounts directly to Domain Admins groups.
Of the 440 compromised deployments, the attackers performed credential harvesting against 280 hosts and successfully exfiltrated secrets from 137 of them. The education sector bore the brunt of the campaign, with 204 compromised deployments. Additional victims spanned retail and professional services, real estate and hospitality, IT and managed service providers, non-profit organizations, libraries, and manufacturing sectors.
Why It Matters
This campaign represents a concrete example of AI lowering the barrier to large-scale exploitation. The ability to compromise hundreds of organizations within hours—achieving domain admin access in some cases within minutes—demonstrates how automation is fundamentally changing the economics of cyberattacks. For defenders, the window between vulnerability disclosure and mass exploitation continues to shrink, making rapid patch deployment increasingly critical.
Uncertain Objectives
GreyNoise notes that the threat actor's ultimate objectives remain unclear. The campaign may represent initial access development work intended for handoff to affiliated actors, or the attacker may directly leverage the access for follow-on operations such as data theft or ransomware deployment.
Jake Knott, head of threat intelligence at WatchTowr, had warned days after the vulnerability disclosure that exploitation activity was intensifying, suggesting initial access brokers might be involved.
These details were first reported by GreyNoise.
This is an original analysis by the Omega editorial team. Source reporting: AI Watch.
Want systems like this working for your business?
Book a Call

