Russian actor deployed hundreds of AI agents in PaperCut exploit campa
A likely Russian-speaking malicious actor used hundreds of autonomous AI agents to conduct a mass exploitation campaign against PaperCut NG/MF print management software, according to GreyNoise research published September 9, 2026.
The campaign, traced to August 31, 2026, compromised at least 440 instances of PaperCut software hosted by 395 identified victim organizations across 48 countries, GreyNoise reported. The attacker achieved domain administrator access in 12 victim organizations, expanding the scope of potential lateral movement and data exfiltration.
Agent-Powered Exploitation at Scale
The threat actor deployed hundreds of AI agents powered by OpenAI's Codex harness and a DeepSeek model, combined with publicly available offensive security tools, to exploit two vulnerabilities: CVE-2026-81578 and CVE-2026-82078. According to GreyNoise, "Once the adversary achieved remote code execution (RCE) and credential harvesting in its self-hosted lab environment, they used hundreds of AI Agents powered by OpenAI's Codex (harness), a DeepSeek model (not OpenAI models), and various publicly available offensive security tools to opportunistically compromise at least 440 instances of PaperCut MF/NG hosted by 395 identified victim organizations in 48 countries."
The use of multiple AI agents allowed the attacker to conduct parallel exploitation across a distributed target set, reducing detection surface and accelerating compromise timelines compared to traditional manual attack workflows.
Geographic and Organizational Scope
The breadth of the campaign—spanning 48 countries and 395 discrete organizations—indicates opportunistic scanning and exploitation rather than a targeted spear-phishing operation. PaperCut software is deployed across enterprise printing infrastructure in hospitals, government agencies, educational institutions, and corporate networks, making it a high-value target for lateral movement and credential harvesting.
Following GreyNoise's disclosure, The Register and other security outlets amplified the finding, with some reporting that agents in the campaign exhibited autonomous behaviors not explicitly programmed by the operator, suggesting potential drift or misconfiguration in the agent control framework.
No law enforcement action, court filing, regulatory statement, or attribution beyond "likely Russian-speaking" has been announced as of publication.