INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

AI-powered attack exploited PaperCut flaws to hack 395 organizations

| 2026-09-10 15:55 MEDIUM HIGH
Executive Summary AI-generated
The threat actor behind the global exploitation campaign targeting vulnerable PaperCut NG/MF servers has been identified as a Russian-speaking group using hundreds of AI agents to develop and launch their attack. The United States was the most targeted country, followed by several European nations including France, Spain, Canada, and others. GreyNoise researchers observed three attack paths exploiting the flaws in the software: dumping LSASS memory and registry secrets from domain-joined servers, passing recovered credential hashes to domain controllers using a "pass-the-hash" attack, and compromising at least 440 PaperCut instances linked to 395 distinct organizations across 48 countries within just under four hours.
Technical Mitigations AI-generated
* Apply immediate security updates to PaperCut NG/MF servers addressing CVE-2026-81578 and CVE-2026-82078, as recommended by the vendor. * Implement a patching strategy that includes: + Regularly updating operating systems and software to ensure all dependencies are patched. + Ensuring all applications and services on the network have up-to-date patches. + Conducting regular security audits and vulnerability assessments to identify potential weaknesses. * Use secure coding practices, such as: + Avoiding hardcoded credentials or sensitive information in code. + Using secure authentication mechanisms, like multi-factor authentication (MFA). + Implementing input validation and sanitization to prevent buffer overflows and other common vulnerabilities. * Monitor system logs and network traffic for suspicious activity, including: + Regularly reviewing system event logs for unusual login attempts or changes. + Monitoring network traffic for signs of data exfiltration or unauthorized access. + Using intrusion detection systems (IDS) and security information and event management (SIEM) tools to detect potential threats.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Raspberry RobinRaspberry Robin CVE-2026-81578CVE-2026-81578 CVE-2023-27351CVE-2023-27351 CVE-2026-82078CVE-2026-82078 CVE-2023-27350CVE-2023-27350 CVE-2021-42278CVE-2021-42278 CVE-2021-42287CVE-2021-42287
Target & Sectors
CIS CIS NORTH_AMERICA NORTH_AMERICA educationeducation
Incident Timeline
‎April 2023
Attackers exploited the PaperCut vulnerability CVE-2023-27350 in April 2023.
vulnerability CVE-2023-27350
general_metric 27350 -
vulnerability CVE-2023-27351
organisation Lace Tempest
‎April 13, 2023
PaperCut servers were compromised due to a recently discovered vulnerability in the latest patch.
‎May 2023
Threat actors used a known vulnerability in PaperCut MF/NG print management servers to target the education sector.
organisation Microsoft
source_region Iran, Islamic Republic of
organisation CVE-2023-27350
organisation APT
industry Education
tactic Ransomware
attribution FBI
‎August 27
PaperCut servers were compromised due to a recently discovered pre-authentication remote code execution flaw.
organisation PaperCut
tactic Remote Code Execution
‎2026/08/27
PaperCut NG/MF servers were targeted by hackers exploiting a zero-day vulnerability in the latest patch released on August 27, 2026.
organisation PaperCut NG/MF
organisation BleepingComputer
general_metric 25 versions
‎Aug 28, 2026
PaperCut servers were exploited by threat actors using a recently patched vulnerability in the latest version of their software.
‎August 31
GreyNoise and OpenAI's Codex were affected by a vulnerability in the latest PaperCut Server patch.
attribution GreyNoise
attribution OpenAI’s Codex
‎2026/09/10
Threat actors exploited a vulnerability in PaperCut NG and MF print management software, specifically CVE-2026-81578 and CVE-2026-82078, to target at least 440 servers linked to 395 organizations across 48 countries.
organisation PaperCut NG/MF
organisation LockBit
organisation CVE-2023-27350
organisation Lace Tempest
organisation NG
organisation CVSS
organisation Microsoft
organisation CVE-2026
infrastructure 8.8
organisation MF
organisation PaperCut NG
organisation PaperCut MF
organisation CVE-2021-42278
organisation BloodHound
organisation NetExec
organisation PaperCut
victims 395 organizations
organisation Vulnerability / Enterprise Security
organisation GreyNoise
organisation RCE
victims 11 organizations
infrastructure Windows
infrastructure Linux
infrastructure Macos
organisation Domain Admins
organisation NFL
organisation CHANEL
victims 280 victims
victims 12 organizations
organisation LinkedIn
organisation the PaperCut Application
organisation Hackers Are Probing PaperCut Servers
infrastructure 2,500 PaperCut installations
organisation Udydn.out
organisation PaperCut NG/MF Application
organisation IP
organisation Huntress
organisation Hutress
organisation Derby
organisation SecurityAffairs
organisation Patch Released
organisation Xerox
organisation PaperCut Application Servers
organisation BleepingComputer
organisation The Blue Report 2026
organisation PaperCut Zero-Day
organisation SetupCompleted
organisation University
organisation Application Servers
Tactical Metrics
Metrics
victims
395
Organizations
Metrics
victims
11
Organizations
Metrics
victims
280
Victims
Metrics
victims
12
Organizations
Metrics
infrastructure
‎Windows
Affected Product
Metrics
infrastructure
2,500
Papercut Installations
Metrics
infrastructure
‎8.8
Software Version
Metrics
infrastructure
‎Linux
Affected Product
Metrics
infrastructure
‎Macos
Affected Product