09-09-2026
Agents Gone Wild: An AI-Orchestrated Global Campaign Against PaperCut NG/MF
https://www.greynoise.io/blog/ai-orchestrated-campaign-against-papercut-ng-mf
Report completeness: High
Threats:
Credential_harvesting_technique
Passthehash_technique
Nopac_tool
Dcsync_technique
Ligolo_tool
Ligolo-ng_tool
Mimikatz_tool
Bloodhound_tool
Certipy_tool
Rubeus_tool
Impacket_tool
Netexec_tool
Seatbelt_tool
Sharpsploit
Empire_loader
Amsi_bypass_technique
Victims:
Education sector, Papercut ng/mf organizations
Industry:
Energy, Education, Retail, Healthcare, Entertainment, Government
Geo:
Argentina, Puerto rico, Singapore, Ireland, Cambodia, Hong kong, Mexico, China, Taiwan, France, Russia, Thailand, Armenia, Australia, Finland, Belgium, India, Turkmenistan, Azerbaijan, Canada, Denmark, Tanzania, United states, Tajikistan, United kingdom, Iran, South africa, Vietnam, Portugal, Indonesia, Netherlands, Sweden, Turkey, Kazakhstan, Namibia, Moldova, Ukraine, Poland, Nigeria, Chile, Venezuela, Italy, Bangladesh, Afghanistan, Lithuania, Zimbabwe, Austria, Saudi arabia, Sri lanka, Spain, Switzerland, Philippines, Japan, Romania, New zealand, Brazil, Germany, Greece, Belarus, Kyrgyzstan, Malaysia, Botswana, Bulgaria, Colombia, Ecuador, Uzbekistan, Estonia, Pakistan
CVEs:
CVE-2021-42278 [Vulners]
CVSS V3.1: 7.5,
Vulners: Exploitation: True
Soft:
- microsoft windows_server_2004 (<10.0.19041.1348)
- microsoft windows_server_2008 (-, r2)
- microsoft windows_server_2012 (-, r2)
- microsoft windows_server_2016 (<10.0.14393.4770)
- microsoft windows_server_2019 (<10.0.17763.2300)
have more...
CVE-2026-82078 [Vulners]
CVSS V3.1: 9.1,
Vulners: Exploitation: True
Soft:
- papercut papercut_mf (<24.1.9, <25.0.12, <26.0.4)
- papercut papercut_ng (<24.1.9, <25.0.12, <26.0.4)
CVE-2021-42287 [Vulners]
CVSS V3.1: 8.8,
Vulners: Exploitation: True
Soft:
- microsoft windows_server_2004 (<10.0.19041.1348)
- microsoft windows_server_2008 (-, r2)
- microsoft windows_server_2012 (-, r2)
- microsoft windows_server_2016 (<10.0.14393.4770)
- microsoft windows_server_2019 (<10.0.17763.2300)
have more...
CVE-2026-0400 [Vulners]
CVSS V3.1: 4.9,
Vulners: Exploitation: Unknown
Soft:
- sonicwall sonicos (<7.3.2-7010)
CVE-2026-81578 [Vulners]
CVSS V3.1: 9.8,
Vulners: Exploitation: True
Soft:
- papercut papercut_mf (<24.1.9, <25.0.12, <26.0.4)
- papercut papercut_ng (<24.1.9, <25.0.12, <26.0.4)
CVE-2023-27532 [Vulners]
CVSS V3.1: 7.5,
Vulners: Exploitation: True
Soft:
- veeam veeam_backup_\&_replication (<11.0.1.1261, 12.0.0.1420)
TTPs:
Tactics: 1
Technics: 0
ChatGPT TTPs:
do not use without manual checkT1003.001, T1003.006, T1068, T1098, T1136, T1190, T1550.002, T1587.004, T1593
IOCs:
IP: 2
Path: 10
Registry: 2
Url: 1
Hash: 5
Soft:
PaperCut, SonicWall, Active Directory, OpenAI, Codex, DeepSeek, Anthropic
Algorithms:
base64
Win API:
DIT
Languages:
powershell, java, rust
Links:
https://github.com/gentilkiwi/mimikatzhttps://github.com/GreyNoise-Intelligence/gn-research-supplemental-datahttps://github.com/SpecterOps/SharpHoundhave more...