Agents Gone Wild: An AI-Orchestrated Global Campaign Against PaperCut NG/MF · GreyNoise, threat-intelligence firm · Published September 9, 2026
A single attacker used hundreds of AI agents to compromise 440 PaperCut instances
GreyNoise watches attacker traffic through its own sensor network. It reports that a likely Russian-speaking actor began building and testing exploits for two PaperCut vulnerabilities in a private lab on August 31, then deployed hundreds of AI agents against real PaperCut NG and MF servers.
The agents used OpenAI's Codex as their harness and paired it with a DeepSeek model. They also worked with public offensive tools such as Mimikatz and Certipy. PaperCut NG and MF are self-hosted Windows print-management applications that run with SYSTEM-level privileges by default and are usually joined to Active Directory. A compromise can therefore extend beyond the print system.
GreyNoise says the agents moved from an empty workspace to remote code execution against a real victim in under four hours, then reached their first domain admin two hours later. At one point, they compromised 11 organizations in 26 seconds.
The campaign reached at least 440 instances at 395 organizations in 48 countries. Domain admin access occurred at 12 of those organizations. The fastest escalation took five minutes, one United States high school took seven minutes, and the slowest took 144 minutes. The attacker had instructed the agents to avoid 28 countries, including Russia and China, but GreyNoise found victims in several of them. The firm wrote that "it is a good example of Agents Gone Wild."
Why it matters: Defenders of self-hosted services now face automation that can move from exploit development to remote code execution in under four hours and compromise 11 organizations in 26 seconds. GreyNoise reports that Cloudflare's firewall stopped one attack outright. Exposed PaperCut deployments need prompt patching and a firewall.