1. Executive summary
A suspected Russian-speaking cyber actor has exploited a recently disclosed authentication-bypass-plus-RCE chain in PaperCut NG/MF (CVE-2026-81578 and CVE-2026-82078) to compromise at least 440 PaperCut instances across 395 identified victim organisations in 48 countries, using hundreds of AI agents (OpenAI Codex, a DeepSeek model) and public offensive tooling to accelerate exploit development and mass compromise. Post-exploitation activity observed by Arctic Wolf includes Windows registry hive collection, Metasploit/Meterpreter-related Java payloads, and host/user/process enumeration. No verified reference data resolved for this item, so no authoritative CVSS scores, severities, or CISA-KEV exploitation states are available — treat severity as unassessed pending vendor/CISA confirmation. The actor's end goal is unconfirmed; initial-access brokering, data theft, and ransomware deployment all remain possibilities per GreyNoise. EMEA financial services exposure is indirect but real: the campaign is opportunistic, targets internet-facing instances across sectors and geographies (including the UK, France, Spain, Germany, Belgium, Portugal, and Switzerland), and any PaperCut NG/MF deployment reachable from the internet should be treated as exposed.
2. Regulatory framing
| Article | Trigger (the fact in this item) | Practical impact |
|---|---|---|
| DORA Art. 18: classification of ICT-related incidents and cyber threats | The item is a confirmed, actively exploited threat campaign against a specific product (PaperCut NG/MF) with confirmed customer incidents and 440+ compromised instances — a cyber threat that financial entities must classify under their incident process, distinct from a routine vulnerability disclosure. | Clients running PaperCut NG/MF should classify this threat, assess whether their instances are internet-facing or compromised, and record the classification decision. |
| DORA Art. 28: ICT third-party risk — general principles | PaperCut NG/MF is third-party print-management software deployed on-premises and, in the observed campaign, exposed to the internet; the vendor has confirmed customer incidents tied to unspecified flaws in its product. | Clients should verify PaperCut deployments against third-party risk policy: exposure posture, vendor patch status, and contractually required security support. |
No specific NIS2 article is directly engaged by this item beyond generic incident-reporting applicability; clients under NIS2 Art. 23: incident reporting obligations should apply their own materiality thresholds to any confirmed compromise.
3. Technical analysis & attack chain
Attribution caveat: The "Russian-speaking" attribution is single-sourced to reporting on the campaign and no MITRE ATT&CK profile exists in the verified reference data (none resolved for this item). Treat the attribution as unconfirmed. The actor's end goal is also unconfirmed — GreyNoise states it is unclear whether the actor is developing access for handoff to affiliates or will directly pursue data theft or ransomware. Do not describe observed activity as "ransomware" — no ransomware deployment is confirmed in the source material.
Confirmed attack chain (as reported by GreyNoise, Blackpoint Cyber, and Arctic Wolf)
- Reconnaissance. The actor probed internet-facing systems from several vendors — Palo Alto, Ubiquiti, Citrix, SonicWall, and Proxmox VE — from IP
45.142.193[.]132, tracked by GreyNoise since early July 2026. The same IP was previously linked to unauthorized port scanning and brute-force attempts. - Target list building. The actor built target lists using the internet scanning service Netlas.io, using an identified API key.
- Exploit development in a lab. The actor built a self-hosted lab environment containing the vulnerable PaperCut software and an Active Directory server, and developed/tested exploits against it — achieving RCE and credential harvesting in the lab.
- AI-accelerated exploit development. The actor deployed hundreds of AI agents powered by OpenAI Codex and a DeepSeek model, alongside publicly available offensive security tools: Mimikatz, SharpHound, Certipy, Rubeus, and Impacket.
- Initial access. Exploitation of CVE-2026-81578 (authentication bypass) and CVE-2026-82078 (remote code execution) as a chain against internet-facing PaperCut NG/MF instances. The actor progressed from an empty workspace to first RCE against a real victim in just under four hours; once the campaign began in earnest, at least 11 organisations were compromised in 26 seconds.
- Post-exploitation. Per Arctic Wolf: delivery of Windows registry hive collection tools, Metasploit/Meterpreter-related Java payloads, and commands to identify hosts, users, processes, and sensitive configuration data.
- Privilege escalation / domain dominance. In one attack against a US high school, initial access to full domain administrator access took seven minutes. Domain administrator access was achieved against 12 of the 440+ compromised instances (395 identified victim organisations, 48 countries).
- Victim selection. Opportunistic, mainly targeting the education sector, with victims in the US, UK, France, Spain, Canada, Belgium, Portugal, Australia, Germany, and Switzerland. The actor attempted to avoid targeting entities in 28 listed countries (including Russia, China, Hong Kong, Thailand, Iran, Venezuela, Indonesia, Pakistan, and Bangladesh); the attempted restraint failed in some instances.
Technical specifics available in the source material
- Products: PaperCut NG and PaperCut MF (print management software; MF is the version integrating with multifunction copiers).
- Vulnerabilities: CVE-2026-81578 (authentication bypass) and CVE-2026-82078 (RCE), exploited as a chain. The vendor confirmed customer incidents in late August 2026 and stated it was treating the matter with highest priority; at that time the flaw(s) were described as unspecified. No CVSS scores, severity ratings, or CISA-KEV states are available in the verified reference data for these CVEs — do not treat severity as assessed.
- Tooling: Mimikatz, SharpHound, Certipy, Rubeus, Impacket (credential access, AD reconnaissance, certificate abuse, Kerberos manipulation, lateral movement); Metasploit/Meterpreter Java payloads; Windows registry hive collection tools; Netlas.io (internet scanning, with an identified API key).
- Infrastructure: Single source IP
45.142.193[.]132for scanning, brute-force, and exploitation activity. - Speed metrics: <4 hours from empty workspace to first real-victim RCE; 11 organisations compromised in 26 seconds; 7 minutes from initial access to domain admin in one case.
Single-sourced and unconfirmed elements: The AI-agent scale ("hundreds of agents"), the lab-environment reconstruction, the Netlas.io API key detail, and the victim counts (440 instances / 395 organisations / 48 countries) all rest on GreyNoise's reporting; Blackpoint and Arctic Wolf corroborate the exploitation activity and post-exploitation tradecraft but not necessarily every count. The exclusion-list detail is GreyNoise's. Verify before enforcement.
4. Mitigation & containment
P1 — within 24 hours
- Inventory PaperCut deployments. Identify all PaperCut NG/MF instances (default ports and install paths per vendor documentation; check for
pcng-appserver/ PaperCut services). Determine which are internet-facing. Any internet-facing instance should be treated as presumptively exposed to CVE-2026-81578/CVE-2026-82078. - Block the known actor infrastructure. Deny all inbound and outbound traffic to/from
45.142.193[.]132at perimeter firewalls and EDR network containment. Note this is a single reported IP; absence of traffic to it is not evidence of non-compromise. - Isolate internet-facing PaperCut hosts. Remove PaperCut admin/application interfaces from the internet immediately (VPN or reverse-proxy behind authentication, or restrict to management VLAN). The source gives no vendor fix version — check PaperCut's official advisories for the current patched release and apply it as soon as it is available; if no patch is yet available for your version, isolate the service.
- Hunt for the described post-exploitation tradecraft on PaperCut hosts and their AD environments: registry hive collection (e.g.,
reg save, hive dump tooling), Meterpreter-related Java payloads, and Mimikatz/SharpHound/Certipy/Rubeus/Impacket execution (see §6).
P2 — within 72 hours
- Review authentication and audit logs on PaperCut servers for the reporting window (GreyNoise tracking of the IP begins early July 2026; vendor confirmation of exploitation late August 2026): anomalous admin logins, authentication bypass patterns, unexpected RCE-originated processes, and new service/scheduled-task creation.
- Check AD for compromise indicators consistent with the reported 7-minute initial-access-to-domain-admin timeline: unexpected DCSync attempts, Kerberos ticket anomalies (Rubeus), certificate template modifications (Certipy), and SharpHound-style LDAP enumeration bursts.
- Rotate credentials for all accounts with privileges on PaperCut hosts if compromise is suspected or cannot be ruled out; the actor performed credential harvesting in its lab and post-exploitation credential tooling is reported.
P3 — within 7 days
- Patch management: Track PaperCut's advisory for the official fix for CVE-2026-81578/CVE-2026-82078 and apply per vendor guidance. The source material does not name a fixed version — do not assume any version is safe without vendor confirmation.
- Third-party risk review: Confirm PaperCut NG/MF is captured in ICT third-party risk registers and that vendor security advisories are monitored (see DORA Art. 28 row in §2).
- Assume follow-on risk. Given the unconfirmed end goal (access brokering, data theft, or ransomware), any confirmed compromise should trigger full incident response rather than remediation-only, including retrospective review for secondary access.
5. Indicators of compromise
| Type | Value | Confidence | Source |
|---|---|---|---|
| ipv4 | 45.142.193[.]132 | Medium — corroborated by Blackpoint, GreyNoise, and Arctic Wolf for scanning/exploitation activity | The Hacker News (citing Blackpoint Cyber, GreyNoise, Arctic Wolf) |
ipv4 45.142.193[.]132
Behavioural indicators (no further atomic IOCs — hashes, file names, domains — are present in the source material):
| Behaviour | Where to observe | Confidence |
|---|---|---|
| Port scanning / brute-force attempts against internet-facing services (Palo Alto, Ubiquiti, Citrix, SonicWall, Proxmox VE, PaperCut) | Perimeter firewall / IDS logs, GreyNoise-style internet noise monitoring | High — multi-source |
| Authentication bypass followed by RCE on PaperCut NG/MF application servers | PaperCut application logs, host process creation logs | High — vendor-confirmed exploitation |
| Windows registry hive collection (hive dump tooling) | EDR, process command lines, file writes of .hive/hive files |
Medium — Arctic Wolf reporting |
| Metasploit/Meterpreter-related Java payloads delivered post-exploitation | EDR, Java process anomalies on PaperCut hosts | Medium — Arctic Wolf reporting |
| Host/user/process/sensitive-configuration enumeration commands | EDR command-line telemetry | Medium — Arctic Wolf reporting |
| Mimikatz, SharpHound, Certipy, Rubeus, Impacket execution in AD environment | EDR, Windows event logs (4624/4662/4769 patterns), LDAP query volume | Medium — GreyNoise reporting |
| Extremely rapid compromise cadence (11 organisations in 26 seconds; 7 minutes to domain admin) | SIEM correlation of initial access to privilege events | Medium — GreyNoise reporting |
6. Detection
The sources name offensive tools and post-exploitation behaviours but provide no file hashes, exact command lines, or payload strings. The tool names below are generic public tooling, not campaign-specific artefacts; the Sigma rule targets the reported post-exploitation behaviour pattern on PaperCut hosts. No YARA rule is emitted — no distinctive strings, mutexes, file paths, or hard-coded values from the threat's own artefacts appear in the source material.
title: PaperCut NG/MF Exploitation - Registry Hive Collection via reg.exe
id: 7c2f1a44-3b8e-4d69-9f10-2a5e6b7c8d91
status: experimental
description: >
Detects Windows registry hive collection activity consistent with post-exploitation
behaviour reported by Arctic Wolf following PaperCut NG/MF exploitation
(CVE-2026-81578 / CVE-2026-82078). Registry hive dumping via reg.exe save is a
common credential-access precursor.
references:
- https://thehackernews.com/2026/09/papercut-attacker-uses-hundreds-of-ai.html
author: Adverse Trace
date: 2026-09-10
logsource:
category: process_creation
product: windows
detection:
selection_img:
- Image|endswith: '\reg.exe'
- OriginalFileName: 'reg.exe'
selection_cmd:
CommandLine|contains|all:
- 'save'
- 'hklm'
selection_hive:
CommandLine|contains:
- 'SAM'
- 'SYSTEM'
- 'SECURITY'
condition: all of selection_*
falsepositives:
- Legitimate backup or forensic collection activity
level: high
title: Suspicious AD Reconnaissance Tool Execution on PaperCut-Associated Hosts
id: 9a3d5e21-7c4b-4e8f-a1d2-6b9c0e3f4a5b
status: experimental
description: >
Detects execution of tools reported in the PaperCut campaign post-exploitation
phase (SharpHound, Certipy, Rubeus, Mimikatz, Impacket) per GreyNoise reporting.
Tool names are generic public tooling; tune for your environment.
references:
- https://thehackernews.com/2026/09/papercut-attacker-uses-hundreds-of-ai.html
author: Adverse Trace
date: 2026-09-10
logsource:
category: process_creation
product: windows
detection:
selection_sharphound:
CommandLine|contains:
- 'SharpHound'
- 'sharphound'
selection_certipy:
CommandLine|contains:
- 'certipy'
selection_rubeus:
CommandLine|contains:
- 'Rubeus'
- 'rubeus'
selection_mimikatz:
CommandLine|contains:
- 'mimikatz'
- 'Mimikatz'
selection_impacket:
CommandLine|contains:
- 'secretsdump'
- 'wmiexec'
- 'psexec.py'
- 'atexec'
condition: 1 of selection_*
falsepositives:
- Authorised penetration testing and red team activity
- Legitimate administrative use of Impacket tooling
level: high
7. Sources
- The Hacker News — "PaperCut Attacker Uses Hundreds of AI Agents to Compromise 440+ Instances" — https://thehackernews.com/2026/09/papercut-attacker-uses-hundreds-of-ai.html — 2026-09-10
- Help Net Security — "Unknown PaperCut NG/MF vulnerability is under active attack" — https://www.helpnetsecurity.com/2026/08/27/papercut-ng-mf-vulnerability-attack/ — 2026-08-27
- Reporting cited within the primary item: Blackpoint Cyber, GreyNoise, and Arctic Wolf (original reports not directly supplied; details as relayed by The Hacker News).
8. Adverse Trace position
Severity cannot be authoritatively scored — no verified reference data resolved for this item, so no CVSS scores, severity ratings, or CISA-KEV states exist for CVE-2026-81578/CVE-2026-82078 in our reference set, and we will not re-assess from press reporting. Operationally, however, this is an actively exploited, vendor-confirmed campaign with demonstrated mass compromise (440+ instances, 395 organisations, 48 countries) and rapid domain-admin escalation, and it should be treated as high-priority by any client with PaperCut NG/MF exposed to the internet, regardless of sector — the victimology is opportunistic and includes multiple EMEA countries. Attribution to a Russian-speaking actor is unconfirmed (no MITRE profile in verified data) and the end goal — access brokering versus direct data theft or ransomware — is unknown; the AI-agent scale and victim counts are largely single-sourced to GreyNoise and should be verified before enforcement action. For EMEA financial services, the immediate exposure is any internet-facing PaperCut deployment; the secondary risk is follow-on access by affiliates if the actor is brokering access. We will monitor for the vendor's official advisory and fixed versions, CISA-KEV listing, additional corroborating IOCs beyond the single reported IP, and any evidence of follow-on objectives, and will reissue this advisory with updated severity and exploitation state once verified data resolves.
Published via PulseTrace — Adverse Trace threat intelligence.