
AI Agent Swarm Exploits PaperCut CVEs to Breach 440 Instances in 48 Countries
Russian-speaking actor leveraged hundreds of AI agents to exploit two PaperCut CVEs, hitting 440 instances. Evidence from GreyNoise, Blackpoint, and Arctic Wolf ties the campaign to one IP and public offensive tools. End goal and attribution remain unconfirmed beyond initial-access patterns.
The actor built a lab with vulnerable PaperCut and Active Directory, then used Netlas.io API scans to generate target lists while testing authentication bypass plus RCE. Post-exploitation delivered registry hive tools, Meterpreter Java payloads, Mimikatz, SharpHound, Certipy, Rubeus, and Impacket. Domain administrator access was achieved in 12 organizations, including a U.S. high school where full compromise occurred in seven minutes. GreyNoise telemetry shows the IP probed Palo Alto, Citrix, and SonicWall instances since July 2026; Blackpoint and Arctic Wolf independently linked the same address to the PaperCut activity. The actor explicitly excluded 28 countries including Russia and China yet still struck victims in several excluded jurisdictions, indicating control failures rather than disciplined targeting. Technical evidence is limited to IP correlation, tool hashes, and agent-generated commands; no malware samples or C2 infrastructure have been publicly shared to confirm state affiliation. The speed from empty workspace to 11 organizations in 26 seconds demonstrates agentic AI collapsing reconnaissance-to-execution timelines previously measured in days. Initial access broker activity remains the working hypothesis, but the same infrastructure could pivot to ransomware or data exfiltration. Defenders should audit PaperCut instances for the two CVEs and monitor for anomalous registry collection or SharpHound activity within the next 30 days.
GreyNoise: At least 100 additional PaperCut victims will be publicly attributed to the same IP within 45 days.
Sources (2)
- [1]GreyNoise PaperCut AI Campaign Report(https://greynoise.io/blog/papercut-ai-agents-2026)
- [2]Blackpoint MDR Analysis(https://blackpointcyber.com/threat-reports/papercut-440-instances)