Executive Summary
A sophisticated campaign attributed to a suspected Russian-speaking threat actor has targeted over 395 organizations across 48 countries, primarily within the U.S. and European education sectors. The actor leverages a critical vulnerability chain in PaperCut NG/MF (CVE-2026-81578 and CVE-2026-82078) to bypass authentication and achieve remote code execution. The campaign is notable for its use of hundreds of AI agents powered by OpenAI Codex and DeepSeek models to automate vulnerability research, target identification, and exploit troubleshooting, significantly reducing the human effort required for large-scale compromise.
The attack chain involves initial reconnaissance via Netlas.io followed by the deployment of offensive tools like Metasploit, Mimikatz, and Rubeus. Once access is achieved, the actor focuses on credential harvesting and establishing persistence, often reaching domain administrator status within minutes of initial entry. While the final objectives remain unconfirmed, the methodology is highly consistent with initial access brokers seeking to hand off environments to ransomware affiliates like Lace Tempest (Cl0p/LockBit).
Immediate action is required for organizations running PaperCut NG/MF. PaperCut has released maintenance versions (26.0.5, 25.0.13, 24.1.10) that supersede previous emergency patches. CISA has added these vulnerabilities to its Known Exploited Vulnerabilities catalog, highlighting the urgency of remediation.
Key Details
Threat Name
CVE-2026-81578 and CVE-2026-82078
Affects
PaperCut NG, PaperCut MF, PaperCut servers
Adversary
suspected Russian-speaking threat actor Other Adversaries and Aliases: MCA; initial access brokers; Lace Tempest
MITRE Techniques
Malware/Tools
Metasploit, Mimikatz, SharpHound, Certipy, Rubeus, Impacket, SimpleHelp, Cl0p, LockBit, Meterpreter, lsa_collect.exe, save_hives.exe
