Trusted Design

Agents Gone Wild: An AI-Orchestrated Global Campaign Against PaperCut NG/MF

概要

A likely Russian-speaking malicious cyber actor leveraged artificial intelligence to orchestrate a global campaign exploiting PaperCut NG/MF print management software via CVE-2026-81578 and CVE-2026-82078. Using AI agents powered by DeepSeek models and OpenAI's Codex, the adversary moved from empty workspace to first remote code execution in under four hours, compromising at least 440 PaperCut instances across 395 organizations in 48 countries. The campaign originated from IP 45.142.193.132, which had been tracked since July 2026 for attacks against various technologies. The adversary developed and tested exploits in a self-hosted lab environment before launching coordinated attacks using AI agents to achieve rapid compromise, with the fastest domain admin access achieved in just five minutes. Domain administrator access was confirmed in 12 organizations, primarily affecting educational institutions in the United States.

Created: 2026-09-10

Indicators

Indicatorsは見つかっていない。

類似Pulses

類似するPulseは見つかりませんでした。

このPulseに関連する脅威アクター (事実ベース)

事実ベースの脅威アクターは見つかりませんでした。

このPulseに関連する脅威アクター (推論ベース)

推論ベースの脅威アクターは見つかりませんでした。

Related CVEs

このPulseに見つかったCVEはありません。

Pulse – 脅威アクター グラフ


← Pulse一覧に戻る