AI-Driven Campaign Exploits PaperCut Zero-Days
A Russian-speaking actor used AI to exploit two PaperCut NG/MF zero-days, compromising 440 deployments and harvesting credentials from 280 hosts, GreyNoise reports.
A Russian-speaking threat actor used artificial intelligence to build, test and deploy exploits for two PaperCut NG/MF zero-days, tracked as CVE-2026-82078 and CVE-2026-81578. The vulnerabilities allowed unauthenticated remote attackers to bypass authentication and execute arbitrary code. GreyNoise reported 440 PaperCut deployments were compromised and credentials were harvested from 280 hosts.
The flaws were disclosed on August 27 and patched by the vendor on August 28. Security teams observed exploitation soon after public disclosure. Days later, a threat intelligence team warned that activity around the two flaws had intensified and initial access brokers were likely involved in early attacks.
GreyNoise found the actor targeted the vulnerable PaperCut instances of 395 organizations across 48 countries. The firm noted some additional victims could not be attributed to named organizations. The attacker attempted to exclude targets in 28 countries, but the restraint did not always succeed.
The campaign used AI to speed development and deployment of exploits, enabling some compromises to occur in minutes or seconds. GreyNoise identified three primary attack paths: on domain-member hosts the adversary harvested LSASS process memory and registry secrets to obtain credentials; on unpatched PaperCut instances the attackers mounted NoPac-style attacks to achieve remote code execution; and when a vulnerable host was a domain controller the actor tried to add an account to the Domain Admins group.
GreyNoise reported credential harvesting on 280 compromised hosts, exfiltration of secrets from 137 hosts, and domain admin privileges gained in 12 instances. Sector impact was concentrated in education, with 204 of the compromised deployments belonging to educational organizations. Other affected sectors included retail, professional services, real estate, hospitality, IT and managed service providers, non-profits, libraries, manufacturing and utilities.
GreyNoise wrote, “The use of AI to orchestrate the campaign allowed the threat actor to compromise some environments in minutes and even seconds.” The firm added, “There are other real victims that could not be attributed to a named organization. The adversary did explicitly attempt to avoid targeting entities in 28 identified countries; however, our observed victimology shows the attempted restraint failed in some instances.”
Organizations running PaperCut NG/MF were urged to confirm they installed the August 28 patches and to inspect logs for signs of the attack behaviors described, including unusual account creation, LSASS memory dumps and unexpected registry exports. Researchers continue to monitor whether compromised access is being sold through initial access brokers or used for follow-on intrusions such as data theft or ransomware.







