Skip to content
Auto-CTI
Back to today
NEW Russian-speaking APT (suspected state-sponsored) CRITICAL C3

PaperCut Attacker Uses Hundreds of AI Agents to Compromise 440+ Instances

C The Hacker News ·

Admiralty grading (A–F · 1–6)

Source reliability

  • A Completely reliable
  • B Usually reliable
  • C Fairly reliable
  • D Not usually reliable
  • E Unreliable
  • F Cannot be judged

Information credibility

  • 1 Confirmed
  • 2 Probably true
  • 3 Possibly true
  • 4 Doubtful
  • 5 Improbable
  • 6 Cannot be judged

NATO Admiralty (AJP-2.1) grades confidence, independent of the risk score. Cross-source corroboration isn't tracked for non-CVE news, so single-source items are capped at a lower credibility number; a low number does not imply low quality.

Key insight

A suspected Russian-speaking state actor is leveraging hundreds of AI agents to systematically exploit PaperCut instances and gain enterprise access,exemplifying state-sponsored cyber operations using advanced automated techniques.

Description

A suspected Russian-speaking cyber actor has leveraged AI-assisted exploit development against two recently disclosed security flaws in PaperCut NG/MF to compromise over 440 instances. The activity originates from an IP address linked to Russian operations (45.142.193.132) and is documented by independent researchers at Blackpoint Cyber and GreyNoise. This exemplifies escalating APT tactics: attackers are automating exploitation and reconnaissance using AI to rapidly and at scale infiltrate targets. PaperCut is deployed as a central print and document management solution in manufacturing environments, data centers, and enterprise networks.

Risk score

80
strategic relevance
0.80

Path: strategic

ESC