A cyber attack leveraging artificial intelligence has been attributed to a Russian-speaking threat actor targeting vulnerabilities in PaperCut NG/MF software. Recent findings by Blackpoint Cyber and GreyNoise highlight the use of AI to exploit security flaws, impacting over 440 instances globally. The activity traces back to IP address ‘45.142.193[.]132’, known for unauthorized scanning and brute-force attempts.
Vulnerability Exploitation Details
The attack exploits CVE-2026-81578 and CVE-2026-82078, involving authentication bypass and remote code execution, particularly affecting educational institutions across the U.S., U.K., and several other countries. Arctic Wolf reports post-exploitation activities, including Windows registry collection and Metasploit deployments, aiming to gather sensitive configuration data.
GreyNoise has tracked the IP address since July 2026, noting its use in probing systems from various vendors like Palo Alto and Citrix. The attackers constructed a lab with vulnerable PaperCut software to develop and test their exploits, using services like Netlas.io for target list generation.
AI-Driven Attack Strategy
The attackers utilized OpenAI Codex and other AI resources to deploy hundreds of AI agents, aiming to compromise PaperCut instances in 48 countries. Despite attempts to avoid certain regions, some countries were inadvertently targeted. The campaign rapidly achieved code execution and credential harvesting, highlighting AI’s role in accelerating cyber attacks.
In under four hours, the attackers moved from an empty workspace to compromising real targets, with some organizations breached in mere seconds. The attacker’s ultimate goals remain uncertain, but potential motives include selling access or executing ransomware attacks.
Advanced Techniques and Implications
Blackpoint’s investigation reveals the attacker’s use of AI in vulnerability research and exploit development. The campaign involved iterative testing and adaptation, minimizing human effort through AI-driven automation. Python scripts facilitated task management, while open-source tools like Hindsight and AionUi supported AI operations.
This campaign underscores the growing role of AI in cybercrime, reducing manual labor and enhancing attack efficiency. The use of AI in such efforts poses significant challenges for cybersecurity defenses, necessitating advanced strategies to mitigate these evolving threats.
The integration of AI into attack workflows not only aids in malware development but also in managing operational complexities. As cyber threats evolve, understanding and countering AI-assisted attacks becomes crucial for safeguarding digital infrastructures.
