Russian Actor Uses AI to Exploit PaperCut, Hits 440+ Organizations

Russian threat actor deployed hundreds of AI agents to exploit PaperCut vulnerabilities, compromising 395-440+ organizations between August 15 and September 8.
Table of Contents
    Add a header to begin generating the table of contents

    A suspected Russian-speaking threat actor used hundreds of AI agents to autonomously develop and deploy exploits targeting recently disclosed PaperCut NG/MF vulnerabilities, compromising between 395 and 440 organizations worldwide between August 15 and September 8. Independent security firms Blackpoint Cyber and GreyNoise confirmed the campaign, which PaperCut addressed with new maintenance releases on September 11.

    AI-Powered Exploit Development at Scale

    The threat actor used AI to build, test, and deploy exploits autonomously against vulnerable PaperCut NG/MF print management servers. Security researchers tracked the attack activity to IP address 45.142.193[.]132, which has been previously linked to malicious operations. The campaign demonstrates AI’s capability to accelerate exploit development and deployment at a scale that would be difficult to achieve manually, with hundreds of AI agents conducting parallel exploitation attempts across global networks.

    Blackpoint Cyber and GreyNoise published independent analyses that converged on the same findings: an AI-driven exploitation campaign operating at unprecedented speed and scale. The use of hundreds of AI agents allowed the threat actor to test exploit variations, adapt to different PaperCut configurations, and deploy successful attacks across hundreds of targets without the time constraints that would limit human-operated campaigns.

    How the Campaign Targeted 395-440+ PaperCut Instances

    The exploitation activity spanned nearly a month, from August 15 through September 8. Attackers targeted two recently disclosed vulnerabilities in PaperCut NG/MF, widely used print management software deployed in enterprise and educational environments across government, education, and corporate sectors. The compromised servers potentially exposed document access and network credentials stored within the print management infrastructure.

    Print management servers handle authentication for printer access, store copies of documents submitted for printing, and maintain user credentials for print job authorization. Compromise of these systems creates multiple vectors for further attack: credentials can be harvested for lateral movement, document content can reveal sensitive organizational information, and the print server itself can serve as a pivot point into networks that trust authenticated print traffic.

    PaperCut Maintenance Releases 26.0.5, 25.0.13, and 24.1.10 Replace Emergency Patches

    PaperCut released maintenance versions 26.0.5, 25.0.13, and 24.1.10 on September 11, replacing earlier emergency patches issued to contain the exploitation wave. The new releases address the vulnerabilities exploited in the AI-powered campaign and provide organizations with stable, tested fixes.

    Broader Threat Landscape Implications

    The campaign reflects a pattern security practitioners have documented across multiple sectors: AI tools enabling threat actors to compress the timeline between vulnerability disclosure and widespread exploitation. The autonomous nature of the attack — building, testing, and deploying exploits without continuous human oversight — points to a shift in how adversaries can conduct operations at scale. Where traditional exploitation campaigns might compromise dozens of targets over weeks through manual effort, this AI-powered operation reached hundreds of organizations within the same timeframe.

    The scale of compromise, ranging from 395 to 440 organizations according to independent reports, indicates successful exploitation across diverse network configurations and security postures. The threat actor’s AI agents adapted to variations in PaperCut deployments, overcoming differences in network architecture, patch levels, and defensive controls that would have blocked more rigid, scripted attacks.

    Organizations with PaperCut NG/MF deployments face immediate risk if running versions prior to the September 11 maintenance releases. Network credentials and document metadata stored on compromised print servers create downstream exposure for lateral movement and data theft. Security teams should treat these patches as urgent, apply them outside normal change windows, and audit print server access logs for indicators of compromise tied to the tracked IP address 45.142.193[.]132.

    The Russian-speaking attribution, combined with the sophistication of the AI-powered exploitation methodology, suggests state-sponsored or well-resourced cybercriminal operations. Organizations in sectors historically targeted by Russian threat actors — government, critical infrastructure, defense industrial base — should prioritize PaperCut patching and conduct thorough compromise assessments if indicators of exploitation are detected. The month-long exploitation window from mid-August through early September means potentially compromised systems have been accessible to attackers for weeks before vendor patches became available.

    Related Posts