A Russian-speaking threat actor deployed hundreds of AI agents to exploit critical vulnerabilities in PaperCut NG and PaperCut MF, successfully compromising over 440 instances worldwide within weeks of public disclosure.

Blackpoint Cyber and GreyNoise attributed the campaign to an attacker operating from IP address 45.142.193.132. The actor leveraged artificial intelligence to automate exploit development and delivery at scale, representing a significant shift in attack methodology. Rather than manual exploitation, the threat actor generated multiple AI-driven attack variants to bypass defenses and establish initial access across vulnerable installations.

PaperCut NG and PaperCut MF are print management solutions deployed in enterprises, government agencies, and educational institutions globally. Both products manage document workflows, user authentication, and print job accounting. The flaws targeted in this campaign allow unauthenticated remote code execution, granting attackers direct system access without credentials.

The vulnerability exploitation pattern reveals industrial-scale compromise operations. The attacker scanned the internet for exposed PaperCut instances, identified vulnerable versions, and deployed AI-generated exploit payloads. Each attack variant differed slightly, complicating signature-based detection. Organizations running unpatched or recently updated instances fell victim within the compromise window.

Blackpoint Cyber and GreyNoise detected this activity through network telemetry and threat intelligence feeds. The campaign demonstrates how adversaries now weaponize AI to accelerate exploitation cycles. Traditional response timelines assume attackers work sequentially. This actor compressed that window by parallelizing attacks across hundreds of targets simultaneously using automated AI agents.

Organizations running PaperCut NG or PaperCut MF should assume immediate risk. The 440-plus compromised instances represent organizations that either delayed patching or ran internet-exposed systems. Attackers gained footholds enabling lateral movement, data exfiltration, print system manipulation, and persistence mechanisms. Secondary intrusions from other threat actors become likely once access is sold or shared.

Response actions include applying patches immediately to all PaperCut deployments, conducting forensic analysis on potentially compromised systems, and reviewing authentication logs for unauthorized access. Network segmentation should isolate print management systems from critical infrastructure. Organizations should assume attackers obtained user credentials, system configurations, and potentially document metadata from compromised instances.

This campaign reflects broader trends in cybercriminal tactics. Russian-speaking groups increasingly adopt AI automation to scale operations beyond traditional manual exploitation limits. Vulnerability disclosure timelines compressed. Patch windows narrowed. Defenders now face attacks spanning hundreds of targets within days rather than weeks.

PaperCut released patches addressing the flaws. However, patch adoption lagged significantly in the initial weeks following disclosure. Organizations prioritizing cost reduction over security often deprioritize print management updates, treating these systems as non-critical infrastructure. This assumption proved costly.

The use of hundreds of AI agents represents an operational escalation. Previous campaigns against PaperCut and similar systems relied on smaller, manually-coordinated attack teams. This actor deployed automation that reduces human effort while maintaining attack effectiveness. The model scales economically for threat actors willing to absorb failed exploitation attempts.

Defenders should treat PaperCut instances as high-value targets requiring immediate patching and network isolation. Print systems frequently occupy network blind spots, receiving less scrutiny than primary business applications. This invisibility makes them attractive attack vectors for establishing persistence and pivoting to sensitive systems.