AI‑Driven Campaign Hijacks Hundreds of PaperCut Servers Across the Globe
A coordinated cyber operation attributed to a Russian‑speaking threat group has leveraged artificial‑intelligence tools to compromise at least 395 organizations worldwide by exploiting vulnerabilities in PaperCut NG and MF print‑management servers.
PaperCut software, widely adopted by enterprises, educational institutions, and government agencies to monitor and control printing activity, runs on on‑premises servers that often hold logs of user activity, authentication tokens, and document metadata. Because these servers sit at the intersection of network access and sensitive information, they present an attractive target for attackers seeking to harvest internal data or gain broader footholds.
According to the investigation, the attackers deployed hundreds of autonomous AI agents to automate the discovery of vulnerable PaperCut installations. The agents scanned public IP ranges, identified servers with outdated or misconfigured versions of the software, and generated exploit code without direct human intervention. This AI‑assisted methodology allowed the group to scale the campaign rapidly, moving from initial footholds to full compromise across a large number of targets.
While the full extent of the breach remains under analysis, the compromised servers could expose details such as printed document titles, user identifiers, and authentication credentials stored for single sign‑on integration. Security researchers warn that such information can be leveraged for credential‑stuffing attacks, espionage, or further lateral movement within victim networks.
PaperCut’s development team has responded by releasing security patches and advisory notices urging administrators to apply updates, enforce strong authentication, and segment print‑management services from critical network segments. Several cybersecurity firms have also issued guidance on detecting the AI‑generated exploitation patterns, recommending network monitoring for anomalous scanning activity and unexpected outbound connections from print servers.
The episode underscores a growing trend where adversaries employ generative AI to accelerate vulnerability research and exploit development. As AI tools become more accessible, defenders are faced with the challenge of anticipating automated attack vectors and reinforcing the security hygiene of legacy infrastructure that may not have been designed with AI‑driven threats in mind.
Comments (0)
Be the first to comment.
Join the discussion