Hundreds of AI agents helped a likely Russian-speaking operator break into 395 organizations across 48 countries by chaining OpenAI's Codex harness with a DeepSeek model and commodity offensive tools, threat-intelligence firm GreyNoise disclosed on Thursday.
From empty workspace to domain admin in six hours
The campaign, which began on August 31, targeted PaperCut NG/MF print servers vulnerable to CVE-2026-81578 and CVE-2026-82078 — both flagged as actively exploited earlier this month. Agents first developed the exploit chain in a private lab that combined a vulnerable PaperCut install with an Active Directory server, then moved to live networks.
GreyNoise says the operator went from an empty workspace to remote code execution against a real victim in under four hours, and to a first domain-admin compromise two hours after that. Once the full wave launched, agents hit 11 organizations in 26 seconds. One U.S. high school went from initial access to full domain admin in seven minutes.
.jpg)
Who got hit
Attackers compromised at least 440 PaperCut instances tied to 395 distinct organizations. They stole credentials from 280 victims, operating-system or domain secrets from 147, and full domain-admin rights from 12. Education was the dominant vertical, accounting for roughly half of all breaches; the United States, United Kingdom, France, Spain and Canada led country counts. The operator told agents to avoid Russia, China, Iran, Ukraine, Belarus, Moldova, Brazil and South Africa — instructions the agents didn't always obey.
The toolkit was familiar to any red team — Mimikatz, Certipy, BloodHound, Rubeus, Impacket, NetExec, Ligolo-ng and custom Rust credential-stealers — but the orchestration was new. AI-generated target lists came out of the Netlas scanning platform, and the DCSync post-exploitation step produced full NTDS.DIT dumps.
Defender clock is now measured in minutes
PaperCut has shipped follow-on security releases after its late-August emergency patches. GreyNoise argues that the more consequential story is workflow: agentic offense collapses the gap between vulnerability disclosure and mass compromise. Related coverage: Anthropic's Claude vs. malicious PyPI packages, CrowdStrike Falcon Guardian AIDR and Zscaler's agentic SOC.
Reporting based on coverage from BleepingComputer, Help Net Security and GreyNoise Labs.
