AI-powered attack exploited PaperCut flaws to hack 395 organizations
AI-powered attack compromised 395 organizations using PaperCut vulnerabilities, targeting education sector and 48 countries.
Intelligence analysis by Qwen 2.5 (3B)

A sophisticated AI campaign exploited PaperCut software flaws to breach 395 organizations, highlighting the risks of unsecured software.
A bad guy used smart computers to find holes in a software program. They used these holes to get into 395 different schools and other places. The smart computers helped them find passwords and do bad things. The schools should fix the software to stop this from happening again.
Analysis
The Attack Timeline
The attack began on August 31, with the threat actor using AI to develop and refine exploits for two CVEs.
Exploits and Techniques
The attackers used a combination of OpenAI’s Codex and DeepSeek models, along with commodity tools, to launch the campaign.
Impact
The operation compromised at least 440 PaperCut instances, affecting 395 distinct organizations across 48 countries, with the education sector being the most targeted.
Defense Challenges
The attackers' rapid attack left defenders with very tight response margins, with the adversary achieving RCE in under four hours and full domain administrator access in seven minutes.
Attack Techniques
The attackers employed various techniques to gain access and maintain control, including:
- Dumping LSASS memory and registry secrets from domain-joined PaperCut servers.
- Using the “noPac” attack against vulnerable environments.
- Directly adding a newly created account to Domain Admins when PaperCut ran on a domain controller or under a domain administrator service account.
Toolset
The attacker's toolkit included Ligolo-ng, Mimikatz, Certipy, BloodHound, Rubeus, Impacket, NetExec, and custom Rust credential-collection utilities.
Recommendations
System administrators are advised to apply PaperCut's emergency security updates and follow the vendor's recommendations to mitigate the risk of such attacks.
Key points
- AI-powered attack compromised 395 organizations
- Targeted education sector and 48 countries
- Used PaperCut software flaws to gain access
- Rapid attack left defenders with tight response margins
- Recommendations include applying emergency security updates
With better security measures in place, the risk of such attacks can be significantly reduced.
If the bad guy finds a way to get around the new security measures, they might still be able to break in.



