INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
AI-powered attack exploited PaperCut flaws to hack 395 organizations
| 2026-09-10 15:55 MEDIUM HIGHExecutive Summary AI-generated
The threat actor behind the global exploitation campaign targeting vulnerable PaperCut NG/MF servers has been identified as a Russian-speaking group using hundreds of AI agents to develop and launch their attack. The United States was the most targeted country, followed by several European nations including France, Spain, Canada, and others. GreyNoise researchers observed three attack paths exploiting the flaws in the software: dumping LSASS memory and registry secrets from domain-joined servers, passing recovered credential hashes to domain controllers using a "pass-the-hash" attack, and compromising at least 440 PaperCut instances linked to 395 distinct organizations across 48 countries within just under four hours.
Technical Mitigations AI-generated
* Apply immediate security updates to PaperCut NG/MF servers addressing CVE-2026-81578 and CVE-2026-82078, as recommended by the vendor.
* Implement a patching strategy that includes:
+ Regularly updating operating systems and software to ensure all dependencies are patched.
+ Ensuring all applications and services on the network have up-to-date patches.
+ Conducting regular security audits and vulnerability assessments to identify potential weaknesses.
* Use secure coding practices, such as:
+ Avoiding hardcoded credentials or sensitive information in code.
+ Using secure authentication mechanisms, like multi-factor authentication (MFA).
+ Implementing input validation and sanitization to prevent buffer overflows and other common vulnerabilities.
* Monitor system logs and network traffic for suspicious activity, including:
+ Regularly reviewing system event logs for unusual login attempts or changes.
+ Monitoring network traffic for signs of data exfiltration or unauthorized access.
+ Using intrusion detection systems (IDS) and security information and event management (SIEM) tools to detect potential threats.
Technical Observables
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Raspberry RobinRaspberry Robin
CVE-2026-81578CVE-2026-81578
CVE-2023-27351CVE-2023-27351
CVE-2026-82078CVE-2026-82078
CVE-2023-27350CVE-2023-27350
CVE-2021-42278CVE-2021-42278
CVE-2021-42287CVE-2021-42287
Target & Sectors
CIS
CIS
NORTH_AMERICA
NORTH_AMERICA
educationeducation
Incident Timeline
April 2023
Attackers exploited the PaperCut vulnerability CVE-2023-27350 in April 2023.
Click on any entity below to view its context and source!
vulnerability
CVE-2023-27350
In April 2023, Microsoft linked the
attacks
exploiting the CVE-2023-27350 and CVE-2023-27351 vulnerabilities in print management software PaperCut to a financially motivated threat actor tracked as Lace Tempest (formerly
DEV-0950
).
In April 2023, attackers began exploiting the critical CVE-2023-27350 PaperCut vulnerability, which allowed unauthenticated attackers to bypass authentication and remotely execute code on vulnerable servers.
general_metric
27350 -
In April 2023, Microsoft linked the
attacks
exploiting the CVE-2023-27350 and CVE-2023-27351 vulnerabilities in print management software PaperCut to a financially motivated threat actor tracked as Lace Tempest (formerly
DEV-0950
).
vulnerability
CVE-2023-27351
In April 2023, Microsoft linked the
attacks
exploiting the CVE-2023-27350 and CVE-2023-27351 vulnerabilities in print management software PaperCut to a financially motivated threat actor tracked as Lace Tempest (formerly
DEV-0950
).
organisation
Lace Tempest
In April 2023, Microsoft linked the
attacks
exploiting the CVE-2023-27350 and CVE-2023-27351 vulnerabilities in print management software PaperCut to a financially motivated threat actor tracked as Lace Tempest (formerly
DEV-0950
).
April 13, 2023
PaperCut servers were compromised due to a recently discovered vulnerability in the latest patch.
May 2023
Threat actors used a known vulnerability in PaperCut MF/NG print management servers to target the education sector.
Click on any entity below to view its context and source!
organisation
Microsoft
In May 2023, Microsoft
warned
that Iran-linked APT groups were exploiting another flaw, tracked as
CVE-2023-27350
, in attacks against PaperCut MF/NG print management servers.
source_region
Iran, Islamic Republic of
In May 2023, Microsoft
warned
that Iran-linked APT groups were exploiting another flaw, tracked as
CVE-2023-27350
, in attacks against PaperCut MF/NG print management servers.
organisation
CVE-2023-27350
In May 2023, Microsoft
warned
that Iran-linked APT groups were exploiting another flaw, tracked as
CVE-2023-27350
, in attacks against PaperCut MF/NG print management servers.
organisation
APT
In May 2023, Microsoft
warned
that Iran-linked APT groups were exploiting another flaw, tracked as
CVE-2023-27350
, in attacks against PaperCut MF/NG print management servers.
industry
Education
CISA and the FBI
issued a joint advisory
in May 2023 warning that the Bl00dy Ransomware Gang was also exploiting vulnerable PaperCut servers in attacks against the education sector.
tactic
Ransomware
CISA and the FBI
issued a joint advisory
in May 2023 warning that the Bl00dy Ransomware Gang was also exploiting vulnerable PaperCut servers in attacks against the education sector.
attribution
FBI
CISA and the FBI
issued a joint advisory
in May 2023 warning that the Bl00dy Ransomware Gang was also exploiting vulnerable PaperCut servers in attacks against the education sector.
August 27
PaperCut servers were compromised due to a recently discovered pre-authentication remote code execution flaw.
Click on any entity below to view its context and source!
organisation
PaperCut
PaperCut, the print management software running in schools, hospitals, and offices worldwide,
confirmed on August 27
that a pre-authentication remote code execution flaw is being actively exploited against real customers.
tactic
Remote Code Execution
PaperCut, the print management software running in schools, hospitals, and offices worldwide,
confirmed on August 27
that a pre-authentication remote code execution flaw is being actively exploited against real customers.
2026/08/27
PaperCut NG/MF servers were targeted by hackers exploiting a zero-day vulnerability in the latest patch released on August 27, 2026.
Click on any entity below to view its context and source!
organisation
PaperCut NG/MF
As
BleepingComputer reported yesterday
, PaperCut warned that hackers were exploiting a vulnerability in zero-day attacks against customer servers and released an initial emergency patch for PaperCut NG/MF versions 25 and 26.
organisation
BleepingComputer
As
BleepingComputer reported yesterday
, PaperCut warned that hackers were exploiting a vulnerability in zero-day attacks against customer servers and released an initial emergency patch for PaperCut NG/MF versions 25 and 26.
general_metric
25 versions
As
BleepingComputer reported yesterday
, PaperCut warned that hackers were exploiting a vulnerability in zero-day attacks against customer servers and released an initial emergency patch for PaperCut NG/MF versions 25 and 26.
Aug 28, 2026
PaperCut servers were exploited by threat actors using a recently patched vulnerability in the latest version of their software.
August 31
GreyNoise and OpenAI's Codex were affected by a vulnerability in the latest PaperCut Server patch.
Click on any entity below to view its context and source!
attribution
GreyNoise
Attack and threat intelligence company GreyNoise says the campaign began on August 31, combining OpenAI’s Codex and DeepSeek models with commodity offensive tools.
attribution
OpenAI’s Codex
Attack and threat intelligence company GreyNoise says the campaign began on August 31, combining OpenAI’s Codex and DeepSeek models with commodity offensive tools.
2026/09/10
Threat actors exploited a vulnerability in PaperCut NG and MF print management software, specifically CVE-2026-81578 and CVE-2026-82078, to target at least 440 servers linked to 395 organizations across 48 countries.
Click on any entity below to view its context and source!
organisation
PaperCut NG/MF
A threat actor, likely Russian-speaking, used hundreds of AI agents to develop and launch a global exploitation campaign targeting vulnerable PaperCut NG/MF servers.
PaperCut has now released emergency patches for customers with public-facing PaperCut NG/MF servers.
organisation
LockBit
Those attacks were ultimately linked to numerous threat actors, including the
Clop and LockBit ransomware operations
,
Iranian state-backed hacking groups
, and the
Bl00dy Ransomware Gang
.
"
In 2023, a
critical flaw
in PaperCut MF and NG (
CVE-2023-27350
, CVSS score: 9.8) was exploited by Russian threat actors as well as a financially motivated hacking group called Lace Tempest to deliver Cl0p and LockBit ransomware.
Microsoft also observed intrusions that led to LockBit ransomware attacks.
organisation
CVE-2023-27350
"
In 2023, a
critical flaw
in PaperCut MF and NG (
CVE-2023-27350
, CVSS score: 9.8) was exploited by Russian threat actors as well as a financially motivated hacking group called Lace Tempest to deliver Cl0p and LockBit ransomware.
"What we can say: the bulletin advises customers to watch for intrusion-detection, endpoint, or network-monitoring alerts tied to the PaperCut Application Server, and we'll publish indicators of compromise as they're verified."
PaperCut servers were previously targeted in 2023 after attackers began exploiting CVE-2023-27350, an authentication bypass and remote code execution vulnerability.
organisation
Lace Tempest
"
In 2023, a
critical flaw
in PaperCut MF and NG (
CVE-2023-27350
, CVSS score: 9.8) was exploited by Russian threat actors as well as a financially motivated hacking group called Lace Tempest to deliver Cl0p and LockBit ransomware.
organisation
NG
"
In 2023, a
critical flaw
in PaperCut MF and NG (
CVE-2023-27350
, CVSS score: 9.8) was exploited by Russian threat actors as well as a financially motivated hacking group called Lace Tempest to deliver Cl0p and LockBit ransomware.
PaperCut Software warns that attackers are actively exploiting a zero-day in its NG and MF print management products.
PaperCut warns of NG, MF flaw exploited in zero-day attacks.
organisation
CVSS
"
In 2023, a
critical flaw
in PaperCut MF and NG (
CVE-2023-27350
, CVSS score: 9.8) was exploited by Russian threat actors as well as a financially motivated hacking group called Lace Tempest to deliver Cl0p and LockBit ransomware.
organisation
Microsoft
Microsoft later
linked some of those attacks
to the Clop ransomware operation, which exploited vulnerable PaperCut servers for initial access to company networks.
Microsoft said an Iranian state-backed group known for attacking critical infrastructure
exploited
the same bug that year in multiple attacks.
organisation
CVE-2026
System administrators are advised to apply PaperCut’s emergency security updates addressing CVE-2026-81578 and CVE-2026-82078 immediately, and follow the
vendor’s recommendations in this bulletin
.
PaperCut has now shared technical details and CVE identifiers for the two vulnerabilities, tracked as CVE-2026-82078 and CVE-2026-81578.
infrastructure
8.8
The company released patches for the bugs, tracked as CVE-2026-82078 and CVE-2026-81578, which both carry severity scores over 8.8 out of 10.
organisation
MF
PaperCut Software warns that attackers are actively exploiting a zero-day in its NG and MF print management products.
PaperCut warns of NG, MF flaw exploited in zero-day attacks.
PaperCut has released a second emergency security update for two actively exploited vulnerabilities in its PaperCut NG and MF print management software after researchers discovered multiple ways to bypass the initial fixes.
organisation
PaperCut NG
“PaperCut Software security response team is investigating active exploitation of a vulnerability affecting PaperCut NG and PaperCut MF.”
reads the advisory
.
Ravie Lakshmanan
Aug 28, 2026
Vulnerability / Enterprise Security
PaperCut has
alerted
customers that bad actors are actively exploiting a vulnerability impacting all versions of its PaperCut NG and PaperCut MF print management software in zero-day attacks.
“Huntress reproduced a full pre-authentication RCE chain against a vanilla PaperCut NG
25.0.11.75758
server.
PaperCut
released
an emergency advisory on Thursday evening saying vulnerabilities in their print management software, PaperCut NG and MF, are under active exploitation.
PaperCut has released a second emergency security update for two actively exploited vulnerabilities in its PaperCut NG and MF print management software after researchers discovered multiple ways to bypass the initial fixes.
PaperCut is warning that hackers are actively exploiting a vulnerability in all versions of its PaperCut NG and PaperCut MF print management software in zero-day attacks.
organisation
PaperCut MF
“PaperCut Software security response team is investigating active exploitation of a vulnerability affecting PaperCut NG and PaperCut MF.”
reads the advisory
.
Ravie Lakshmanan
Aug 28, 2026
Vulnerability / Enterprise Security
PaperCut has
alerted
customers that bad actors are actively exploiting a vulnerability impacting all versions of its PaperCut NG and PaperCut MF print management software in zero-day attacks.
PaperCut is warning that hackers are actively exploiting a vulnerability in all versions of its PaperCut NG and PaperCut MF print management software in zero-day attacks.
organisation
CVE-2021-42278
Using the
“noPac” attack
against environments still vulnerable to CVE-2021-42278 and CVE-2021-42287.
organisation
BloodHound
The attacker’s toolkit includes Ligolo-ng, Mimikatz, Certipy, BloodHound, Rubeus, Impacket, NetExec, and custom Rust credential-collection utilities.
organisation
NetExec
The attacker’s toolkit includes Ligolo-ng, Mimikatz, Certipy, BloodHound, Rubeus, Impacket, NetExec, and custom Rust credential-collection utilities.
organisation
PaperCut
AI-powered attack exploited PaperCut flaws to hack 395 organizations.
PaperCut warns of hackers using printer management software flaw in attacks.
PaperCut releases second emergency patch for exploited flaws.
PaperCut issued emergency patches on Friday and urged customers to install them immediately.
Ravie Lakshmanan
Aug 28, 2026
Vulnerability / Enterprise Security
PaperCut has
alerted
customers that bad actors are actively exploiting a vulnerability impacting all versions of its PaperCut NG and PaperCut MF print management software in zero-day attacks.
PaperCut warns of NG, MF flaw exploited in zero-day attacks.
victims
395 organizations
AI-powered attack exploited PaperCut flaws to hack 395 organizations.
GreyNoise data indicates that the operation compromised at least 440 PaperCut instances linked to 395 distinct organizations across 48 countries.
organisation
Vulnerability / Enterprise Security
Ravie Lakshmanan
Aug 28, 2026
Vulnerability / Enterprise Security
PaperCut has
alerted
customers that bad actors are actively exploiting a vulnerability impacting all versions of its PaperCut NG and PaperCut MF print management software in zero-day attacks.
organisation
GreyNoise
GreyNoise data indicates that the operation compromised at least 440 PaperCut instances linked to 395 distinct organizations across 48 countries.
organisation
RCE
“The adversary went from an empty workspace to first achieving RCE against a real victim in just under four hours, first domain admin in an additional two hours, and once the full campaign launched, compromised at least 11 organizations in 26 seconds,”
GreyNoise notes.
“Huntress reproduced a full pre-authentication RCE chain against a vanilla PaperCut NG
25.0.11.75758
server.
Huntress, which has been working with PaperCut during the incident, says it
observed exploitation
in two customer environments and reproduced the full pre-authentication RCE chain.
victims
11 organizations
“The adversary went from an empty workspace to first achieving RCE against a real victim in just under four hours, first domain admin in an additional two hours, and once the full campaign launched, compromised at least 11 organizations in 26 seconds,”
GreyNoise notes.
infrastructure
Windows
Emergency Patch Release 2 is available for PaperCut NG and MF versions 24, 25, and 26 on Windows, Linux, and macOS.
One incident lasted under two minutes total, with the attacker running nothing more aggressive than
whoami
and
ver
, basic commands to identify the compromised account and Windows version.
The attack caused PaperCut’s
pc-app.exe
Application Server to launch
charmap.exe
with SYSTEM privileges, confirming that the vulnerability can lead to code execution at the highest Windows privilege level.
infrastructure
Linux
Emergency Patch Release 2 is available for PaperCut NG and MF versions 24, 25, and 26 on Windows, Linux, and macOS.
infrastructure
Macos
Emergency Patch Release 2 is available for PaperCut NG and MF versions 24, 25, and 26 on Windows, Linux, and macOS.
organisation
Domain Admins
Directly adding a newly created account to Domain Admins when PaperCut ran on a domain controller or under a domain administrator service account.
organisation
NFL
Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.
organisation
CHANEL
Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.
victims
280 victims
The attacker harvested credentials from 280 victims, obtained operating system or domain secrets from 147, and obtained administrator privileges at 12 organizations.
victims
12 organizations
The attacker harvested credentials from 280 victims, obtained operating system or domain secrets from 147, and obtained administrator privileges at 12 organizations.
organisation
LinkedIn
Cybersecurity firm watchTowr, which has been working with PaperCut during the incident,
said on LinkedIn
that the vulnerabilities allow unauthenticated attackers to bypass authentication and gain remote code execution on affected PaperCut NG/MF instances.
organisation
the PaperCut Application
"What we can say: the bulletin advises customers to watch for intrusion-detection, endpoint, or network-monitoring alerts tied to the PaperCut Application Server, and we'll publish indicators of compromise as they're verified."
PaperCut servers were previously targeted in 2023 after attackers began exploiting CVE-2023-27350, an authentication bypass and remote code execution vulnerability.
The following indicators of compromise have been shared so far -
Alerts from intrusion-detection, endpoint-security, or network-monitoring tools involving the PaperCut Application Server, particularly suspicious post-exploitation activity from "pc-app.exe"
Missing, unexpectedly truncated, or deleted PaperCut server.log files
The presence of the below entries in "server.log" -
ERROR
So far, the company has identified several indicators of compromise:
Intrusion-detection, endpoint-security, or network-monitoring tools may flag suspicious activity involving the PaperCut Application Server, especially activity linked to
pc-app.exe
.
If your organization runs one of these older versions, the safest option for now is to remove the PaperCut Application Server from the public internet.
organisation
Hackers Are Probing PaperCut Servers
Hackers Are Probing PaperCut Servers, and 47% Still Have No Patch.
infrastructure
2,500 PaperCut installations
Huntress found that about 47% of the roughly 2,500 PaperCut installations it tracks still run version 23 or earlier, and there is currently no patch for those versions.
organisation
Udydn.out
“After exploitation, the .class file deletes its own
Udydn.out
file, as well as the server’s
server.log
file.
organisation
PaperCut NG/MF Application
“If your PaperCut NG/MF Application Server is accessible from the public internet,
immediately
restrict web access to trusted IP addresses only (e.g. internal IP addresses).”
states the advisory
.
Users who have PaperCut NG/MF Application Server exposed to the internet are advised to immediately restrict access to trusted IP addresses.
organisation
IP
Users who have PaperCut NG/MF Application Server exposed to the internet are advised to immediately restrict access to trusted IP addresses.
The company urged customers to remove their servers from the public internet and restrict web access to only trusted IP addresses.
Even though patches are available, PaperCut to urge customers to restrict access to the web interfaces to trusted IP addresses using firewall rules, network access controls, or equivalent measures.
It also recommends disconnecting application servers from the internet and limiting access to trusted IP addresses.
The company says it is aware of confirmed attacks on customers and is urging organizations with Internet-exposed PaperCut Application Servers to immediately restrict access to the web interfaces to trusted IP addresses.
organisation
Huntress
Researchers at Huntress found evidence of exploitation in two customer environments, and the security firm went further, reproducing the entire attack chain from scratch against a clean, unpatched install.
Multiple cybersecurity companies
confirmed
evidence of exploitation including Huntress, which
said
it has at least two customers impacted by the campaign targeting the bugs.
Second emergency patch released
On Friday, PaperCut released Emergency Patch Release 2, an updated security fix that includes additional hardening developed after further analysis with its internal security team and researchers at Huntress and watchTowr.
organisation
Hutress
reads the
report
published by Hutress.
organisation
Derby
One artifact survived that cleanup regardless: a Derby database log entry reading
memory:...\pwn
, an oddly named database directory that PaperCut’s own investigation guidance now flags as a high-confidence indicator of compromise.
organisation
SecurityAffairs
Follow me on Twitter:
@securityaffairs
and
Facebook
and
Mastodon
Pierluigi Paganini
(
SecurityAffairs
– hacking, Philippine nuclear and naval targets)
Follow me on Twitter:
@securityaffairs
and
Facebook
and
Mastodon
Pierluigi Paganini
(
SecurityAffairs
– hacking, Zero-Day)
organisation
Patch Released
PaperCut Zero-Day Under Active Attack: Emergency Patch Released
PaperCut warns that a zero-day in NG and MF is being exploited.
organisation
Xerox
Organizations use PaperCut software to manage a variety of printer brands including Canon, Epson, Xerox, Brother and more.
organisation
PaperCut Application Servers
The company says it is aware of confirmed attacks on customers and is urging organizations with Internet-exposed PaperCut Application Servers to immediately restrict access to the web interfaces to trusted IP addresses.
organisation
BleepingComputer
BleepingComputer contacted PaperCut with questions about this exploitation and will update the story when we receive a response.
organisation
The Blue Report 2026
The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.
organisation
PaperCut Zero-Day
PaperCut Zero-Day Under Active Attack: Emergency Patch Released.
PaperCut Zero-Day Exploited in Attacks, Affecting All NG and MF Versions.
organisation
SetupCompleted
PaperCut MF/NG contains an improper access control vulnerability within the SetupCompleted class that allows authentication bypass and code execution in the context of SYSTEM.
organisation
University
The company says its security team reproduced the vulnerability using information provided by a University customer.
organisation
Application Servers
The company continues to warn customers whose Application Servers are exposed to the Internet to use firewall rules or network access controls to restrict their web interfaces to trusted IP addresses.
Tactical Metrics
Metrics
victims
395
Organizations
Click for context!
AI-powered attack exploited PaperCut flaws to hack 395 organizations.
GreyNoise data indicates that the operation compromised at least 440 PaperCut instances linked to 395 distinct organizations across 48 countries.
Metrics
victims
11
Organizations
“The adversary went from an empty workspace to first achieving RCE against a real victim in just under four hours, first domain admin in an additional two hours, and once the full campaign launched, compromised at least 11 organizations in 26 seconds,”
GreyNoise notes.
Metrics
victims
280
Victims
The attacker harvested credentials from 280 victims, obtained operating system or domain secrets from 147, and obtained administrator privileges at 12 organizations.
Metrics
victims
12
Organizations
The attacker harvested credentials from 280 victims, obtained operating system or domain secrets from 147, and obtained administrator privileges at 12 organizations.
Metrics
infrastructure
Windows
Affected Product
One incident lasted under two minutes total, with the attacker running nothing more aggressive than
whoami
and
ver
, basic commands to identify the compromised account and Windows version.
The attack caused PaperCut’s
pc-app.exe
Application Server to launch
charmap.exe
with SYSTEM privileges, confirming that the vulnerability can lead to code execution at the highest Windows privilege level.
Emergency Patch Release 2 is available for PaperCut NG and MF versions 24, 25, and 26 on Windows, Linux, and macOS.
Metrics
infrastructure
2,500
Papercut Installations
Huntress found that about 47% of the roughly 2,500 PaperCut installations it tracks still run version 23 or earlier, and there is currently no patch for those versions.
Metrics
infrastructure
8.8
Software Version
The company released patches for the bugs, tracked as CVE-2026-82078 and CVE-2026-81578, which both carry severity scores over 8.8 out of 10.
Metrics
infrastructure
Linux
Affected Product
Emergency Patch Release 2 is available for PaperCut NG and MF versions 24, 25, and 26 on Windows, Linux, and macOS.
Metrics
infrastructure
Macos
Affected Product
Emergency Patch Release 2 is available for PaperCut NG and MF versions 24, 25, and 26 on Windows, Linux, and macOS.
Intelligence Sources
The Hacker News
2026-08-28
BleepingComputer
2026-08-27
PaperCut warns of NG, MF flaw exploited in zero-day attacks
BleepingComputer
Security Affairs
2026-08-28
PaperCut Zero-Day Under Active Attack: Emergency Patch Released
Security Affairs
BleepingComputer
2026-08-28
PaperCut releases second emergency patch for exploited flaws
BleepingComputer
TheRecord
2026-08-28
Security Affairs
2026-08-30
Hackers Are Probing PaperCut Servers, and 47% Still Have No Patch
Security Affairs
BleepingComputer
2026-09-10
AI-powered attack exploited PaperCut flaws to hack 395 organizations
BleepingComputer
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-09-11T06:03
Comprehensive Tactical Telemetry
Highly Correlated Entities
41x
organisation
Identified Entity
PaperCut NG/MF
entity
16x
target region
Target Country
Russian Federation
country
10x
timeline
Temporal Reference
August 31
date
6x
vulnerability
Exploited CVE
CVE-2026-81578
cve
4x
attribution
Attributing Entity
GreyNoise
authority
3x
tactic
Cyber Operation Type
Ransomware
tactic
3x
tactic
MITRE ATT&CK Technique
T1592.002 - Software
technique
3x
victims
Organizations
395
organizations
3x
infrastructure
Affected Product
Windows
software
2x
malware
Offensive Tool
Mimikatz
tool
2x
source region
Origin Country
Iran, Islamic Republic of
country
Contextual Telemetry
Context Block
21 METRICS
industry
Targeted Sector
Education
sector
general metric
Papercut Instances
440
papercut instances
general metric
Countries
48
countries
general metric
Seconds
26
seconds
victims
Victims
280
victims
general metric
%
47
%
infrastructure
Papercut Installations
2,500
papercut installations
general metric
Hours
24
hours
infrastructure
Software Version
8.8
version
general metric
Cve-2026
81,578
cve-2026
general metric
Versions
25
versions
general metric
Vulnerability
9
vulnerability
general metric
Flaw
9
flaw
general metric
Emergency Patch Release
2
emergency patch release
general metric
-
27,350
-
general metric
Blue Report
2,026
blue report
general metric
Simulations
338,000,000
simulations
general metric
Version
23
version
malware
Malware Payload
Raspberry Robin
tool
general metric
Critical Flaw
10
critical flaw
general metric
Aug
28
aug
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.