Hundreds of AI agents turned two PaperCut flaws into a fast-moving global attack.
GreyNoise found that the campaign compromised at least 440 PaperCut NG/MF instances across 48 countries. Nearly half were tied to educational organizations, with 204 compromised systems in the sector.
Attackers reached that scale only after first developing the intrusion. Evidence from the campaign shows a tested process that moves from preparation to real-world exploitation, then spreads across multiple environments within seconds.
Attackers tested the intrusion before scaling it
GreyNoise linked the operation to a likely Russian-speaking threat actor. Researchers found the operator had built a lab containing vulnerable PaperCut software and Active Directory before attacking real systems.
Work inside the test environment allowed the actor to develop the exploitation process and verify that it worked. Potential victims were later assembled using the Netlas internet-scanning service.
After testing, the operator ran the workflow through OpenAI’s Codex harness paired with a DeepSeek model. Established offensive security tools were also available to the agents, although researchers cautioned that not every tool in the actor’s collection was seen in use.
Researchers watched the operation move from an empty workspace to remote code execution against a real system in under four hours. Once the campaign was running at scale, 11 organizations were compromised within 26 seconds. Automation allowed the attacker to repeat a prepared intrusion across multiple environments with very little time between compromises.
Compromised PaperCut servers exposed credentials and domain secrets
Post-compromise activity varied sharply across victims. Some intrusions stopped after access to the PaperCut server, while others reached credentials and higher-value parts of the Windows environment.
- 280 compromised instances had credential harvesting observed.
- 147 instances had operating-system or domain secrets accessed.
- 12 environments reached confirmed domain administrator access.
One US high school went from initial access to domain administrator in seven minutes. PaperCut servers can run with powerful Windows privileges and connect to Active Directory, creating opportunities for privilege escalation after a successful breach.
Attackers recovered Windows credentials in some environments and exploited weak or overly privileged configurations in others. Successful escalation could expose credentials with control over much larger parts of a network.
Existing defenses interrupted at least some activity. GreyNoise saw a Cloudflare web application firewall block one exploitation attempt. Researchers could not determine how the actor ultimately planned to use the compromised environments, leaving possible follow-on activity unresolved.
Education IT teams should investigate beyond the PaperCut server
If you manage PaperCut for a school or university, installing the fixed release should not be the final step if the server was exposed during the attack period. A patched system may still need investigation for earlier access, particularly when the server could reach Windows credentials or Active Directory.
PaperCut lists maintenance releases 26.0.5, 25.0.13, and 24.1.10 as containing the fixes that replaced its earlier emergency patches. The company also advises organizations whose Application Server has been compromised to rebuild it from a clean backup and follow their normal security response procedures.
Education IT teams responsible for exposed systems should check for evidence that activity moved past the application.
- Review PaperCut logs and endpoint telemetry from the period when the server was exposed. Missing or unexpectedly altered logs also warrant scrutiny.
- Look for unexpected accounts, changes in group membership, or other signs of Active Directory compromise.
- Identify privileged credentials used by or accessible from the PaperCut server and rotate them when exposure cannot be ruled out.
- Expand the incident response process if investigators find credential access or privilege escalation.
Patching closes the known flaws. It does not, however, determine whether earlier access reached credentials or other systems, so affected education IT teams should establish the extent of any compromise before closing the incident.
More cybersecurity news: NSA, FBI, and CISA say billions of tokens were extracted from Claude, GPT, Gemini, and Grok through coordinated distillation campaigns.





