IN late August, GreyNoise reported that a likely Russian-speaking actor deployed hundreds of AI agents, trained in a lab, to locate Internet-connected Papercut print management servers, compromise the software and opportunistically move to Windows Active Directory environments. The campaign targeted Papercut NG and MF installations, affecting at least 440 instances across 395 organisations in 48 countries.
The analysis highlights the speed at which the AI swarm operated: from an initial foothold to remote code execution against a victim in just under four hours, reaching Active Directory domain admin within two more hours, and, once the campaign was underway, compromising multiple organisations in seconds.
Researchers emphasised that large language models are enabling attackers to scale and accelerate operations, while Google noted the growing availability of open-weight models is broadening access to agentic capabilities. The report also discusses the broader trend of AI-assisted attack lifecycles, including attempts to curb victimology in some cases and the risks of LLM hijacking and cloud-infrastructure abuse.
Defence rests on established security hygiene: multi-factor authentication, restrictive permissions and token lifetimes to hinder lateral movement, and monitoring for abnormal behaviour. Experts urge defenders to automate detection and response while retaining human oversight to maintain context and judgement.