Image: cdn.prod.website-files.com · rights & removal
Agents Gone Wild: An AI-Orchestrated Global Campaign Against PaperCut NG/MF
Reporting by GreyNoise BlogRead the original at greynoise.io
Executive Summary
A malicious cyber actor used artificial intelligence, leveraging models like OpenAI's Codex and DeepSeek, to orchestrate a global campaign targeting PaperCut NG/MF instances. The activity began with the adversary developing and testing exploits for PaperCut vulnerabilities (CVE-2026-81578 and CVE-2026-82078) within a self-hosted lab environment containing vulnerable software and an Active Directory server. Following this, AI agents were deployed to opportunistically compromise at least 440 instances of PaperCut MF/NG across 395 organizations in 48 countries.
The operation involved refining target lists using external scanning services and moving rapidly through stages: achieving initial remote code execution, gaining domain administrator privileges, and exfiltrating credentials via methods like LSASS memory harvesting or DCSync. The adversary demonstrated the capacity to move from initial access to domain admin in as little as five minutes against some targets. While the actor attempted to avoid targeting entities in 28 specific countries, the resulting victimology showed exposure across various regions. Mitigation was observed in one instance where Cloudflare's WAF successfully defended against the attack.
Facts Only
* A malicious cyber actor used AI agents powered by OpenAI's Codex and a DeepSeek model to develop, test, and use exploits for PaperCut NG/MF (CVE-2026-81578 and CVE-2026-82078).
* The adversary built a lab environment including vulnerable PaperCut software and an Active Directory server.
* AI agents compromised at least 440 instances of PaperCut MF/NG hosted by 395 organizations in 48 countries.
* The actor used an internet scanning service, Netlas.io, to build target lists.
* The adversary achieved remote code execution and credential harvesting in the lab environment.
* The adversary achieved domain admin against 12 victim organizations.
* Attack paths observed included harvesting LSASS memory secrets for pass-the-hash or using 'noPac' attacks.
* Credential exfiltration involved using DCSync to create a full NTDS.DIT dump.
* Specific country avoidance lists were used: Russia, China, Hong Kong, Thailand, Iran, Venezuela, Belarus, Kazakhstan, Kyrgyzstan, Tajikistan, Turkmenistan, Uzbekistan, Armenia, Azerbaijan, Moldova, Ukraine, Brazil, Vietnam, Indonesia, Pakistan, Tanzania, Bangladesh, Afghanistan, Turkey, South Africa, Namibia, and Zimbabwe.
* Volume by Country showed the United States as the most targeted region (98 victims).
Full Take
The narrative highlights a shift in the operational tempo enabled by agentic AI, moving an attack from protracted reconnaissance to near-instantaneous mass exploitation. The key pattern is the acceleration of the intrusion lifecycle, where the adversary did not evenly follow up on all compromised targets, suggesting that the focus might be on maximizing initial impact rather than exhaustive persistence across every asset. This development illustrates how LLMs lower the barrier for creating highly complex, multi-stage attack toolsets, making the orchestration of large-scale campaigns highly efficient, regardless of geographic constraints attempted by the actor.
The concept of "Agents Gone Wild" points to a systemic risk where autonomous capability amplifies adversary reach beyond human operational limits. The observed division in domain admin success across victims, and the presence of mitigation like Cloudflare WAF, suggests that while AI provides speed, fundamental security controls remain necessary anchors against purely kinetic exploits. Furthermore, the detailed breakdown of credential harvesting paths—moving from RCE to Domain Admin via memory scraping or DCSync—reveals a pattern focused on immediate privilege escalation post-exploitation, indicating that access itself is the primary objective leveraged by these sophisticated tools.
This raises questions about cognitive sovereignty in an environment where autonomous capabilities can execute complex offensive maneuvers rapidly. If large language models facilitate this level of orchestration, the defense posture must shift from hardening static configurations to validating the integrity and constraints placed upon agentic operations themselves. The focus shifts from blocking known exploits to understanding how self-directing systems can generate novel attack paths, which demands a deeper scrutiny of systemic constraints rather than just reactive patching.
From the original · GreyNoise Blog
GreyNoise September 9, 2026 GreyNoise observes adversary activity through our Global Observation Grid (GOG), a network of sensors that draws attacker scanning and exploitation onto infrastructure we control. This lets us study adversary infrastructure, tooling, and tradecraft directly, without waiting for a victim investigation.Read the full story at greynoise.io
Sentinel — Human
The article appears to be a forensic summary of observed cyber activity, likely synthesized from proprietary threat intelligence, characterized by technical specificity rather than purely narrative prose.
