AI-Driven Campaign Targets Hundreds of PaperCut Servers in Global Attack
Threat intelligence firm GreyNoise has uncovered a coordinated intrusion effort that has compromised at least 440 PaperCut NG/MF servers across 395 organizations in 48 countries. The campaign, which began on August 31, 2026, relies on hundreds of artificial‑intelligence‑powered agents to infiltrate and maintain access to the targeted systems.
According to GreyNoise, the malicious actors deployed automated AI agents that scan for vulnerable PaperCut installations, exploit weak credentials, and establish persistent footholds. The breadth of the operation—affecting nearly half a thousand servers in dozens of nations—suggests a level of automation and scale uncommon in traditional ransomware or espionage attacks.
PaperCut NG/MF is a widely used print‑management solution that enables organizations to control, monitor, and bill for printing services. Its central role in handling sensitive document workflows makes it an attractive target for adversaries seeking to harvest data, disrupt operations, or leverage compromised machines for further malicious activity.
While definitive attribution remains pending, GreyNoise notes linguistic and operational clues that point to a Russian‑speaking threat actor. The use of AI agents aligns with a growing trend among sophisticated groups that integrate machine‑learning tools to automate reconnaissance, credential stuffing, and lateral movement, thereby reducing the need for manual intervention.
In response to the findings, GreyNoise has alerted affected entities and recommended immediate steps, including patching to the latest PaperCut releases, enforcing strong authentication, and reviewing network traffic for anomalous AI‑generated patterns. PaperCut Software Ltd. has acknowledged the report and is working with security partners to issue mitigations and guidance.
The incident underscores a broader shift in cyber‑threat landscapes, where artificial intelligence is becoming a force multiplier for attackers. Security professionals warn that as AI tools become more accessible, similar large‑scale campaigns could target other enterprise software, prompting a reassessment of defensive strategies that must now account for automated, adaptive threats.
Comments (0)
Be the first to comment.
Join the discussion