Infrastructure & C2 Nodes
45.142.193.132(Orchestration & payload staging host)45.158.196.75(Secondary execution and scanning node)- Port
8000/TCP(Payload staging) / Port8089/TCP(Ligolo-ng C2 tunnel)
The PaperCut AI Campaign marks a watershed moment in threat intelligence: the transition from human-driven cyber operations assisted by script automation to fully autonomous, agent-orchestrated multi-stage intrusions.
Adversary Infrastructure (45.142.193.132) │ ├── AI Agent Swarm (OpenAI Codex Harness + DeepSeek Model) │ ├── Netlas.io Reconnaissance & Attack Target List │ ├── Virtual Lab Automated Exploit Testing (< 4 hours to RCE) │ └── Parallelized Autonomous Weaponization Engine │ ▼[Target Initial Access: 440 PaperCut Servers in 48 Countries] │ Chain: CVE-2026-81578 (Auth Bypass) + CVE-2026-82078 (Unsafe Reflection RCE) │ Execution Context: NT AUTHORITY\SYSTEM │ ├── Attack Path A: LSASS Memory Dumping + Pass-the-Hash ├── Attack Path B: Active Directory noPac Impersonation (CVE-2021-42278 / CVE-2021-42287) └── Attack Path C: Direct Domain Admin Addition + DCSync (NTDS.DIT Dump)The threat actor (operating from infrastructure 45.142.193.132 and 45.158.196.75) orchestrated a multi-tier attack chain:
PaperCut NG and MF are enterprise print management suites commonly installed on Windows servers with domain integration, running by default with NT AUTHORITY\SYSTEM privileges.
The AI agent swarm exploited a two-vulnerability chain:
DatabaseUtils. Once configurations are modified via the first flaw, the server instantiates an arbitrary Java database driver class, executing native commands under SYSTEM.Upon achieving initial access, the autonomous agents categorized target environments and executed one of three distinct domain escalation paths:
lsa_read.exe, lsa_collect_small.exe) and executed registry hive extractions (reg save HKLM\SYSTEM, reg save HKLM\SECURITY), base64-encoded them (certutil -encode), and passed harvested NTLM hashes to compromise the Domain Controller.sAMAccountName and requesting S4U2self Kerberos service tickets, the agent impersonated a Domain Controller and obtained instantaneous Domain Admin rights.net group "Domain Admins" Administrator17 /add /domain to establish immediate root-level domain access.NTDS.DIT and deployed Ligolo-ng reverse tunnels (legit-svc.exe) for persistent operator access.GreyNoise observed 440 compromised PaperCut instances across 395 unique organizations in 48 countries.
| Country | Compromised Instances | Credential Harvesting | OS/Domain Secrets Dumped | Domain Admin Achieved |
|---|---|---|---|---|
| United States | 98 | 59 | 31 | 1 |
| United Kingdom | 59 | 40 | 20 | 3 |
| France | 31 | 23 | 12 | 1 |
| Spain | 31 | 20 | 8 | 0 |
| Canada | 24 | 10 | 8 | 3 |
| Belgium | 16 | 13 | 8 | 1 |
| Portugal | 16 | 9 | 5 | 1 |
| Australia | 15 | 8 | 4 | 0 |
| Germany | 15 | 8 | 2 | 1 |
| Total Global | 440 | 280 | 147 | 12 |
The education sector suffered the brunt of the campaign (204 victims, 7 Domain Admins), driven by the prevalence of self-hosted PaperCut servers exposed directly to the public internet on campus networks.
Infrastructure & C2 Nodes
45.142.193.132 (Orchestration & payload staging host)45.158.196.75 (Secondary execution and scanning node)8000/TCP (Payload staging) / Port 8089/TCP (Ligolo-ng C2 tunnel)Dropped Binaries & Hashes
528cd4e69ecfa5191adbcf6ef28667bf (lsa_read.exe — Rust LSA dumper)ce870a91e8d27e8f663f0687abc60b04 (save_hives.exe — SAM/SYSTEM dumper)fc92dfafa7aa741c5f2b9cbcf75d1d19 (lsa_collect_small.exe — Bootkey extractor)974decb9ff4c8f9ccb0937c96d513347 (certipy.exe — ADCS abuse tool)C:\Windows\Temp\pc-sys.hiv, C:\Windows\Temp\pc-sec.hiv, C:\ProgramData\pc-sys-reg.hivC:\Windows\Temp\pc-*.b64...\PaperCut MF\server\custom\web\pcp_<10rand>.txtC:\ProgramData\LegitSvc\legit-svc.exe (Renamed Ligolo-ng agent)Administrator17title: PaperCut Server Spawning Suspicious Interactive Shell or Utilityid: papercut-ai-campaign-rcestatus: criticaldescription: Detects child processes spawned by PaperCut Application Server (pc-app.exe), indicative of CVE-2026-82078 exploitation.logsource: category: process_creation product: windowsdetection: selection: ParentImage|endswith: '\pc-app.exe' Image|endswith: - '\cmd.exe' - '\powershell.exe' - '\certutil.exe' - '\reg.exe' - '\net.exe' condition: selectionlevel: criticalalert http any any -> $HOME_NET any ( msg:"HERMES INTEL - PaperCut NG/MF Web Management Auth Bypass Attempt (CVE-2026-81578)"; flow:to_server,established; content:"/app"; http_uri; content:"service=direct/"; http_uri; pcre:"/service=direct\/(1|2)\/Home\//U"; classtype:web-application-attack; sid:202681578; rev:1;)The PaperCut campaign demonstrates that when adversaries employ autonomous agentic swarms, manual human response in a traditional SOC loop is hopelessly outmatched by 26-second multi-organization blitzes.
24.1.10, 25.0.13, or 26.0.5 immediately.ms-DS-MachineAccountQuota to 0.