PaperCut Attacker Uses Hundreds of AI Agents to Compromise 440+ Instances
A suspected Russian-speaking cyber actor has been attributed to the use of artificial intelligence (AI) to devise exploits targeting a recently disclosed pair of security flaws in PaperCut NG/MF and break into hundreds of instances. According to independent reports from Blackpoint Cyber and GreyNoise, the activity originates from "45.142.193[.]132," an IP address that has been linked to
- 1. A suspected Russian-speaking cyber actor has been attributed to the use of artificial intelligence (AI) to devise exploits targeting a recently disclosed pair of security flaws in PaperCut NG/MF and break into hundreds of instances.
- 2. Upon gaining remote code execution and credential harvesting within its self-hosted lab environment, the threat actor has been observed unleashing hundreds of AI Agents powered by OpenAI Codex, a DeepSeek model, and publicly available offensive security tools (e.g., Mimikatz, SharpHound, Certipy, Rubeus, and Impacket) to compromise no less than 440 instances of PaperCut MF/NG hosted by 395 identified victim organizations in 48 countries.
- 3. "The strongest AI impact in this campaign was not a novel exploit technique," Blackpoint said. "It was the reduction of human effort required to research, develop, debug, classify, track, retry, and continuously improve exploitation across hundreds of real systems."
Article analysis
Skim this article about "PaperCut Attacker Uses Hundreds of AI Agents to Compromise 440+ Instances": 3 key takeaways and more.
PaperCut Attacker Uses Hundreds of AI Agents to Compromise 440+ Instances
skim AI Analysis | The Hacker News
The Hacker News on PaperCut Attacker Uses Hundreds of AI Agents to Compromise 440+ Instances: skim's analysis surfaces 3 key takeaways. A Russian-speaking actor used AI to exploit PaperCut vulnerabilities, compromising over 440 instances. Read the takeaways in seconds, then decide whether the full article is worth your time.
Category: Tech. News article analyzed by skim.
Summary
A Russian-speaking actor used AI to exploit PaperCut vulnerabilities, compromising over 440 instances. Cybersecurity firms Blackpoint Cyber and GreyNoise reported the activity, originating from a specific IP address linked to previous attacks. The actor employed AI agents and various tools for exploit development, target selection, and post-exploitation activities.
Key Takeaways
- A suspected Russian-speaking cyber actor has been attributed to the use of artificial intelligence (AI) to devise exploits targeting a recently disclosed pair of security flaws in PaperCut NG/MF and break into hundreds of instances.
- Upon gaining remote code execution and credential harvesting within its self-hosted lab environment, the threat actor has been observed unleashing hundreds of AI Agents powered by OpenAI Codex, a DeepSeek model, and publicly available offensive security tools (e.g., Mimikatz, SharpHound, Certipy, Rubeus, and Impacket) to compromise no less than 440 instances of PaperCut MF/NG hosted by 395 identified victim organizations in 48 countries.
- "The strongest AI impact in this campaign was not a novel exploit technique," Blackpoint said. "It was the reduction of human effort required to research, develop, debug, classify, track, retry, and continuously improve exploitation across hundreds of real systems."
Statement Breakdown
- Claimed Facts: 70% of statements the article presents as facts
- Opinions: 20% of statements classified as editorial or subjective
- Claims: 10% of statements surfaced for additional reader evaluation
Credibility & Bias Reasoning
Credibility assessment: The article relies on reports from multiple cybersecurity firms, providing specific technical details and attributing activity to a particular IP address. While the claims are serious, the lack of direct confirmation from the targeted company or law enforcement slightly tempers the score.
Bias assessment: Technical Security Reporting. The article focuses on reporting technical details of a cyberattack, attributing actions to specific threat actors and citing cybersecurity firms. The language is objective and informative, aiming to convey factual information about a security incident.
Note: This article presents technical analysis from cybersecurity firms. Verify critical details with primary sources or further independent investigations.
Credibility flag: Technical Analysis
Claimed Facts (10)
- This is presented as a factual attribution of the cyber activity.
- This statement cites specific reports and an IP address as evidence of the activity's origin.
- This provides corroborating information from another security firm regarding the IP address.
- This details the specific vulnerabilities exploited and the primary target sectors and countries.
- This is a direct quote from Arctic Wolf detailing observed post-exploitation actions.
- This statement from GreyNoise provides a timeline and scope of the IP address's malicious activity.
- This statement from GreyNoise describes an attempted exclusion policy by the adversary and its partial failure.
- This provides specific timelines for the attack's progression, attributed to GreyNoise.
- This quantifies the extent of the adversary's access, presented as a reported fact.
- This statement from Blackpoint details the traced infrastructure and the AI-assisted workflow.
Opinions (4)
- This statement expresses a general concern about AI's role in cyberattacks, which is an interpretation of the findings.
- This is an interpretation of the impact of AI on cyberattack economics, attributed to a cybersecurity company.
- This describes the operator's process as an 'iterative development process,' which is an analytical interpretation.
- This statement analyzes how context was preserved, offering an interpretation of the operational flow.
Claims (5)
- While presented as a fact, the attribution to a 'suspected Russian-speaking cyber actor' is an inference based on analysis, not a definitive identification.
- This is a statement of uncertainty about the actor's ultimate goals, highlighting a lack of definitive information.
- This directly states that the attacker's objectives are unknown, indicating a lack of concrete evidence.
- This statement acknowledges the existence of victims that cannot be specifically identified, implying incomplete data.
- While based on observation, the claim of 'explicit attempt to avoid' and the subsequent failure is an interpretation of the adversary's intent and actions.
Key Sources
- Blackpoint Cyber — Cybersecurity Firm
- GreyNoise — Cybersecurity Firm
- Arctic Wolf — Cybersecurity Firm
- OpenAI Codex — AI Model
- DeepSeek — AI Model
- Sam Decker — Researcher
- Nevan Beal — Researcher
This analysis was generated by skim (skim.plus), an AI-powered content analysis platform by Credible AI. Scores and classifications represent the platform's AI-generated assessment and should be considered alongside other sources.
skim analyzes recent The Hacker News coverage for what holds up, what reads as opinion, and what may not be fully supported. Last updated 10th September 2026.