← Read the analysis
Incident timelineTLP:CLEAR
PaperCut mass exploitation by an AI agent
AI agents directed by a malicious cyber actor (MCA) used OpenAI's Codex with a DeepSeek model.
25 dated events on 4 daysUnauthorized access↑ ↓ to step through
Aug 272026
PaperCut publishes its security advisory
Aug 31
14:44:55 UTC
Workspace created and software downloaded
From its orchestration host, the MCA downloads the advisory and pre- and post-patch versions of the software, then searches the internet for public proofs of concept and exploits.
Open in the GreyNoise Visualizer ↗
Aug 31
15:18:26 UTC
First list of suspected vulnerable targets
Aug 31
15:54:53 UTC
Versions diffed and exploits developed
Installer components for the vulnerable and patched versions are extracted and diffed. The exploits are tested against patched and unpatched servers in Africa.
Aug 31
16:04:42 UTC
MCA is prompted for permission to continue
Aug 31
16:09:31 UTC
Multi-threaded tool built
Built to operationalize the previous findings in furtherance of the attack.
Aug 31
16:09:49 UTC
Tool identifies 462 potentially vulnerable targets
Aug 31
16:14:53 UTC
Multi-threaded tool refined
Aug 31
16:20:14 UTC
Multi-threaded tool refined again
Aug 31
16:23:19 UTC
Target list grows with the improved tool
Aug 31
16:26:00 UTC
1,005 potential target addresses resolved to countries
Using a downloaded IP2Location LITE DB1 country database.
Aug 31
16:35:10 UTC
Local lab built
An Active Directory server and a vulnerable PaperCut server.
Aug 31
16:46:47 UTC
Target list refined
Aug 31
16:58:46 UTC
Target list refined again
Aug 31
17:02:12 UTC
Lab gains 8 fake Active Directory users
Aug 31
Unauthorized access
18:39:39 UTC
First remote code execution on a real target
Remote code execution and a shell on a real target in Australia.
Aug 31
19:14:46 UTC
Target list excludes 28 countries
The MCA lists them in order, from Russia, China and Hong Kong to Namibia, Nigeria and Zimbabwe.
Aug 31
20:50:00 UTC
Per-target intrusion kits assembled
Compartmentalized "Kali-ready" kits with post-exploitation connectivity scripts. A kit can also create an account and password and add it to Domain Admin.
Aug 31
Unauthorized access
21:00:00 UTC
Domain Admin validated at the first real target
The initial Australian target.
Sep 1
07:00:00 UTC
Target list refined with Netlas.io results
Using a specific Application Programming Interface (API) key.
Sep 1
Unauthorized access
08:30:00 UTC
Agents launch the campaign via a second execution host
Hundreds of SSH sessions to that host. Unauthorized access to 11 organizations in 26 seconds, credential harvesting within a minute, 78 in the first hour, 8 with Domain Admin.
Sep 1
17:01:00 UTC
Cloudflare's Web Application Firewall defeats the MCA
Targeting a host behind Cloudflare fails. The MCA also notices performance issues and adjusts thread usage for targets in the United States.
Sep 1
17:15:00 UTC
Bug found and fixed automatically
The campaign continues harvesting credentials.
Sep 1
Unauthorized access
23:12:04 UTC
Last remote code execution of Sep 1
Unauthorized access to more than 223 PaperCut systems.
Sep 2
Unauthorized access
15:45:35 UTC
Last remote code execution of Sep 2
Unauthorized access to the remainder of the PaperCut systems.
Source: GreyNoise.
Times are UTC.
GreyNoise