AI-Powered Attacker Compromises 440+ PaperCut Servers Worldwide
Security researchers at Blackpoint Cyber, GreyNoise and Arctic Wolf have linked a wave of attacks against PaperCut NG/MF print management software to a single IP address, 45.142.193.132, tied to a suspected Russian-speaking actor. The attacker exploits two vulnerabilities, CVE-2026-81578 and CVE-2026-82078, which together allow authentication bypass followed by remote code execution. The education sector has been hit hardest, with victims identified in the US, UK, France, Spain, Canada, Belgium, Portugal, Australia, Germany and Switzerland.
According to GreyNoise, the attacker built and tested exploits in a private lab containing a vulnerable PaperCut instance and an Active Directory server before scaling the campaign using the Netlas.io scanning service to build target lists. Once inside a network, the actor deployed hundreds of AI-driven agents powered by OpenAI Codex and DeepSeek models alongside well-known post-exploitation tools such as Mimikatz, SharpHound, Certipy, Rubeus and Impacket. This combination has enabled the compromise of at least 440 PaperCut instances across 395 organisations in 48 countries, with post-exploitation activity including registry data collection and credential harvesting.
Researchers say it is not yet clear whether the actor intends to sell access to compromised networks or use it directly, but the methodology strongly resembles initial-access broker activity.