Security1 publisher2 min readPublished
Hundreds of AI agents drove one IP into 440 PaperCut servers across 48 countries
GreyNoise and Blackpoint Cyber trace the new PaperCut auth-bypass chain to one scanning address running AI agents against schools, which turns an unpatched print server from a maintenance ticket into a credential incident.
The Watch · Security desk

What happened
- Blackpoint Cyber and GreyNoise independently attribute exploitation of the PaperCut NG/MF authentication bypass and remote code execution chain, CVE-2026-81578 and CVE-2026-82078, to a single IP address, 45.142.193[.]132.
- GreyNoise counts no less than 440 compromised PaperCut MF/NG instances hosted by 395 identified victim organizations across 48 countries.
- The targeting is opportunistic and concentrated on education, with victims in the US, UK, France, Spain, Canada, Belgium, Portugal, Australia, Germany and Switzerland.
- The operator ran hundreds of AI agents powered by OpenAI Codex and a DeepSeek model to drive the intrusions rather than working the target list by hand.
- GreyNoise says the suspected Russian-speaking actor kept an exclusion list of 28 countries including Russia, China and Iran, and that the restraint failed in some instances.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- exposure An internet-facing PaperCut server on a pre-fix build now sits in front of a working chain and a pre-built Netlas-derived target list, so the remediation clock is set by the operator's retry waves rather than by the next maintenance window.
- cost For the 383 organizations that kept their domain, the bill is credential rotation and Active Directory review on the assumption hives were read, which costs far more staff time than the update itself.
- capability Patch-diff to working mass-exploitation tool inside a day means the safe interval defenders assume after a fix ships no longer holds for any product whose builds can be compared.
- precedent With the objective unresolved, these accesses can be sold on or re-entered later, so a victim seeing no ransomware this month has no basis to close the case.
Twelve of the 395 named victim organisations lost domain administrator access [17]. That is about 3 percent [21]. The other 383 [23] were left with code execution on a print server and whatever was taken on the way through, and Arctic Wolf's list of observed post-exploitation says what that was: Windows registry hive collection tools, Metasploit and Meterpreter Java payloads, and commands to enumerate hosts, users, processes and sensitive configuration data [6]. Registry hives are credential material. A box in that 383 is a credential incident whether or not the domain fell.
The speed is what breaks existing response plans. GreyNoise clocks the operator moving from an empty workspace to remote code execution against a real victim in just under four hours [14], then compromising at least 11 organisations in 26 seconds once the campaign began in earnest [15], an average of one organisation every 2.4 seconds [22]. At one US high school, initial access to full domain administrator took seven minutes [16].
Blackpoint recovered the operator's exposed infrastructure and dates the earliest activity to August 31, when the project was comparing patched and unpatched PaperCut builds; researchers Sam Decker and Nevan Beal write that within hours that research had become a multi-threaded validation tool, reviewed, tested and run against progressively larger target sets [20]. The same infrastructure shows target filtering, failure analysis, code changes and repeated retry waves [19]. Target lists were merged using the internet scanning service Netlas.io with an identified API key [9], and the chain was rehearsed in a self-hosted lab holding vulnerable PaperCut and an Active Directory server [8]. The offensive tooling underneath is Mimikatz, SharpHound, Certipy, Rubeus and Impacket [10], which any operator would have used last year. What the agents changed is the throughput of the loop around it.
Neither firm publishes a disclosure date for CVE-2026-81578 or CVE-2026-82078 [2], so the interval from fix to mass exploitation cannot be stated here. The one anchor is that a patched build existed to diff by August 31 [24]. The objective is also open: GreyNoise says it is unclear whether the actor is developing access to hand to affiliated actors or intends to use it directly for data theft or ransomware [18].
The address itself has been on GreyNoise's radar since early July 2026, probing internet-facing systems from Palo Alto, Ubiquiti, Citrix, SonicWall and Proxmox VE [7], and Arctic Wolf flagged it for this campaign last week [4]. Blocking it is bookkeeping. The 440 figure is also a floor rather than a total, because GreyNoise says there are further real victims it could not tie to a named organisation [12].
What to watch
- A follow-on report tying any of the 440 accesses to data theft or ransomware would settle the handoff question GreyNoise left open.
- Vendor or scan-derived counts of PaperCut instances still exposed on pre-fix builds.
- Whether the same operator points the identical workflow at another edge product it has already been scanning.