AI agents PaperCut attacks have demonstrated how artificial intelligence can be used to automate large-scale cyberattacks against vulnerable systems.
The campaign highlights a growing shift in cyberattacks: artificial intelligence is no longer being used only to help write malicious code. In this operation, AI agents were reportedly involved in vulnerability research, exploit development, target selection, troubleshooting, and repeated attack attempts.
Security researchers from GreyNoise and Blackpoint Cyber independently analyzed the activity and found evidence of an automated attack infrastructure designed to continuously test, adapt, and expand the campaign.

PaperCut Vulnerabilities Exploited at Scale
The attackers targeted two recently disclosed PaperCut NG/MF vulnerabilities, CVE-2026-81578 and CVE-2026-82078.
Together, the flaws can be chained to bypass authentication and achieve remote code execution on vulnerable systems. PaperCut is widely used by organizations to manage printing environments, making exposed servers an attractive target for attackers looking for an initial foothold.
The campaign primarily affected organizations in the education sector. Victims were identified in countries including the United States, United Kingdom, France, Spain, Canada, Belgium, Portugal, Australia, Germany, and Switzerland.
GreyNoise identified at least 440 compromised PaperCut instances across 395 organizations. The researchers also found evidence that credentials were harvested from hundreds of victims and that attackers obtained operating system or domain-related secrets from numerous environments.
The activity was not limited to gaining access. In a smaller number of cases, the attackers were able to obtain domain administrator privileges.
AI Agents PaperCut Attack Used Hundreds of AI Agents
What makes this campaign particularly significant is the scale at which artificial intelligence was used.
According to the researchers, the threat actor deployed hundreds of AI agents powered by models including OpenAI Codex and DeepSeek, alongside established offensive security tools.
The agents were reportedly used across different stages of the operation. Instead of relying on a single automated script, the campaign used multiple workflows that could research vulnerabilities, generate and test code, analyze failures, update tools, classify targets, and retry unsuccessful operations.
This created a feedback loop in which the results of one stage could influence what happened next.
Blackpoint Cyber described the AI as the central component connecting vulnerability research, exploit development, testing, target selection, and execution.
The significance is less about AI discovering a completely new hacking technique and more about how it reduced the amount of manual work required to operate an attack campaign.
The AI agents PaperCut campaign is notable because the attackers used artificial intelligence across multiple stages of the operation.
Attackers Built Their Own Testing Environment
Before targeting victims at scale, the threat actor reportedly created a laboratory environment containing vulnerable PaperCut software and an Active Directory server.
This allowed the attackers to experiment with their techniques and refine their tools before expanding the operation.
Researchers found evidence that the actor compared patched and unpatched versions of PaperCut and developed tooling capable of validating whether an attack worked.
The attackers also used an internet-scanning service to identify potential PaperCut targets. Target information was then processed and organized according to factors such as geography, operating system, accessibility, and the stage reached during an attack.
This type of automation allowed the campaign to treat unsuccessful attacks as data rather than simply abandoning them.
The Speed of the Attacks Is Particularly Concerning
The campaign demonstrated how quickly AI-assisted automation can move from vulnerability research to real-world exploitation.
GreyNoise reported that the attacker went from an empty workspace to achieving remote code execution against a real victim in less than four hours.
Once the broader campaign began, researchers observed at least 11 organizations being compromised within 26 seconds.
In one particularly concerning incident involving a U.S. high school, the attackers reportedly progressed from initial access to full domain administrator privileges in approximately seven minutes.
That speed significantly reduces the amount of time defenders have to detect and contain an intrusion.
Traditional incident-response procedures often assume that attackers need time to manually investigate systems, move between machines, collect credentials, and determine their next steps. Highly automated AI-assisted operations can compress those stages dramatically.

What Happened After Initial Access?
Researchers observed several forms of post-exploitation activity after vulnerable PaperCut systems were compromised.
The attackers attempted to collect credentials and sensitive information from Windows environments and conducted reconnaissance to identify users, processes, hosts, and network configurations.
Tools associated with the campaign included widely known penetration-testing and security tools such as Mimikatz, BloodHound, Certipy, Rubeus, Impacket, NetExec, and Ligolo-ng, as well as custom utilities.
The researchers also observed attempts to obtain domain credentials and expand access within compromised Windows environments.
However, the ultimate objective of the campaign remains unclear.
There is currently insufficient evidence to determine whether the attackers were primarily collecting access to sell to other criminal groups or intended to use the compromised environments themselves for activities such as data theft or ransomware deployment.
AI Was Also Used to Manage Targets
Another notable aspect of the campaign was the use of AI-assisted automation beyond exploitation itself.
Recovered code and infrastructure showed a system for organizing potential targets, filtering them geographically, checking whether systems were reachable, tracking successful and unsuccessful attack stages, and deciding which targets should be retried.
The attackers even attempted to exclude organizations in a number of countries from their targeting lists.
Researchers noted, however, that the exclusion rules were not always followed successfully, resulting in some organizations being targeted despite those restrictions.
This illustrates an important characteristic of AI-driven cyber operations: automation does not necessarily mean perfect execution. AI agents can make mistakes, misinterpret instructions, or produce unexpected results. What makes the activity dangerous is the ability to repeat those processes at very high speed.
A New Challenge for Cybersecurity Defenders
The PaperCut campaign provides an important example of how artificial intelligence could change the economics of cybercrime.
Attackers traditionally need skilled operators to investigate vulnerabilities, write or modify tools, analyze failed attempts, identify promising targets, and coordinate different stages of an operation.
AI agents can increasingly assist with many of those tasks simultaneously.
The result is not necessarily a more sophisticated attack at every individual step. Instead, it can be a much faster and more persistent attack process.
That distinction matters for defenders. An attack that once required hours of manual work may now be able to perform many iterations automatically, giving organizations considerably less time to respond.
The campaign also demonstrates why securing internet-facing applications remains critical. A vulnerable application can become the starting point for a much broader compromise if attackers are able to obtain credentials or reach an organization’s internal network.

What Organizations Can Do
Organizations running PaperCut NG/MF should make sure their deployments are fully updated and that the affected vulnerabilities have been addressed.
Security teams should also review internet-facing PaperCut systems for signs of unauthorized access and investigate unusual authentication, administrative, or network activity.
Beyond PaperCut specifically, the campaign reinforces several broader security practices:
- Keep internet-facing applications and servers patched.
- Minimize direct exposure of administrative interfaces to the public internet.
- Use strong authentication and limit privileged accounts.
- Monitor unusual activity on servers running business-critical applications.
- Segment critical systems and Active Directory environments where possible.
- Maintain centralized logging so suspicious activity can be investigated quickly.
- Review privileged-account activity for unexpected changes.
- Prepare incident-response procedures that account for rapidly automated attacks.
Organizations should also recognize that AI-assisted attacks can move extremely quickly. Detection and automated response therefore become increasingly important parts of modern cybersecurity.
The Bigger Picture
The PaperCut campaign is an important warning about where cyberattacks may be heading.
The most significant development is not that criminals have discovered a new way to exploit software. It is that AI agents can help connect many previously manual activities into a single, continuously operating workflow.
Vulnerability research, testing, target discovery, troubleshooting, exploitation, and post-exploitation can increasingly become parts of the same automated process.
For defenders, this creates an uncomfortable imbalance: attackers can potentially scale their operations with relatively little additional human effort, while organizations still need to identify and respond to each individual intrusion.
As AI capabilities continue to improve, cybersecurity teams will need to adapt accordingly. Protecting systems will increasingly depend not only on preventing vulnerabilities but also on detecting abnormal behavior quickly enough to stop automated attacks before they can spread.
The PaperCut campaign shows just how narrow that window can become.
GreyNoise’s analysis of the campaign provides additional technical details about the AI-assisted exploitation activity and affected organizations.
Stay Ahead With Future Tech Hub
Technology moves fast. We keep you ahead with the latest AI, technology, cybersecurity, software, and gadget news.
