A newly emerging threat landscape has been highlighted as a suspected Russian-speaking cyber actor has reportedly utilized artificial intelligence (AI) to exploit vulnerabilities in PaperCut NG/MF, a widely used print management solution. This exploitation has compromised hundreds of instances of the software, predominantly affecting organizations within the education sector across several countries, including the U.S., U.K., France, Spain, Canada, Belgium, Portugal, Australia, Germany, and Switzerland.
Investigations conducted by cybersecurity firms Blackpoint Cyber and GreyNoise identified that the operations trace back to an IP address (45.142.193[.]132) known for its connections to unauthorized port scanning and brute-force attempts. This IP address was also implicated in previous exploitation activities reported by Arctic Wolf, indicating a persistent and coordinated attack effort.
The primary malicious activity centers on two critical vulnerabilities, CVE-2026-81578 and CVE-2026-82078, which involve an authentication bypass and a remote code execution exploit. The attackers have demonstrated a sophisticated approach, using AI-driven methodologies to conduct reconnaissance and assess potential targets before launching their attacks. Blackpoint’s principal MDR analyst Nevan Beal indicated that while the methodology aligns with initial access operations, the definitive intentions behind these attacks remain unclear.
The attackers’ post-exploitation behavior has been telling; they have employed tools for Windows registry hive collection, payloads related to Metasploit/Meterpreter, and commands tailored to identify hosts, users, processes, and sensitive configuration data. It was further noted that the adversary actively probed various internet-facing systems from reputable vendors, enhancing their ability to exploit vulnerabilities effectively.
The threat actors have constructed a self-hosted lab environment that mimics their targets, including the vulnerable PaperCut software. This setup has allowed them to rapidly develop and refine their exploitation techniques, moving from initial system scanning to achieving remote code execution within mere hours. The use of AI has facilitated the automation of these processes, significantly reducing the manual effort and time needed to execute these types of attacks.
Reports reveal that the actor has utilized hundreds of AI agents powered by models such as OpenAI Codex to systematically compromise no fewer than 440 instances of PaperCut MF/NG across 395 victim organizations spanning 48 countries. Although the attackers endeavored to avoid targeting entities in 28 specified countries—such as Russia, China, and Iran—their efforts to restrict their attack vector have occasionally faltered, resulting in unintended breaches.
GreyNoise has indicated that the adversaries quickly transitioned from empty infrastructure to breaching real victims within hours, demonstrating a concerning level of efficiency. A notable case included an attack on a U.S. high school where administrators were compromised within just seven minutes of initial access.
In terms of tactics employed, the attackers illustrate a clear alignment with several techniques outlined in the MITRE ATT&CK framework, including initial access via phishing or exploiting known vulnerabilities, followed by privilege escalation through credential harvesting and gaining domain administrator status.
As the cybersecurity community grapples with the implications of AI-assisted attacks, it raises critical questions regarding the evolving nature of cyber threats and the capabilities that adversaries are developing. The integration of AI into their operational frameworks not only enables more efficient attacks but also underscores the necessity for organizations to bolster their defenses against such sophisticated methodologies.