Skip to content
Tech News
← Back to articles

Papercut AI Swarm Attack Heralds Changes for Cyber Kill Chain

read original get Ubiquiti UniFi Cloud Gateway Ultra → more articles
Why This Matters

An AI-agent 'swarm' compromised hundreds of PaperCut servers and pivoted into Active Directory at machine speed — 11 organizations breached in 26 seconds, per GreyNoise. It's a concrete sign that attackers are automating the full kill chain with LLMs, collapsing the window defenders have to patch or respond.

Key Takeaways
Worth a Look

Ubiquiti UniFi Cloud Gateway Ultra — When automated AI-driven scanners can find and exploit an exposed server in seconds, keeping management software like PaperCut off the open Internet matters. The UniFi Cloud Gateway Ultra gives small teams real firewall and VPN control plus visibility into what's talking to the outside world, so internal services stay internal.

See Ubiquiti UniFi Cloud Gateway Ultra on Amazon → Affiliate link — we may earn a commission on purchases, at no extra cost to you. Product picked by AI based on this article; it is not a tested recommendation.

In the waning hours of August, a likely Russian-speaking actor used hundreds of AI agents trained in a lab environment to seek out Internet-connected instances of the print management software Papercut, compromise the software, and opportunistically attempt to compromise Windows Active Directory (AD) environments, according to an analysis published on Sept. 9 by threat intelligence firm GreyNoise. The attack targeted two vulnerabilities in at least 440 instances of PaperCut NG and MF hosted by 395 organizations in 48 countries, the company said.

The incident is notable for the sheer speed with which the AI swarm was able to accomplish its goal.

"It's clear that large language models (LLM) are enabling adversaries to move at greater speed and scale," GreyNoise researchers said in their analysis. "The adversary went from an empty workspace to first achieving RCE [remote code execution] against a real victim in just under four hours, first [Active Directory] domain admin in an additional two hours, and once the full campaign launched, compromised at least 11 organizations in 26 seconds."

Related:Attackers Use Multi-Hop Google Redirects for Phishing Campaign

The attack is the latest to showcase the progress that cyberattackers are making in incorporating AI agents into every stage of the cyber kill chain, which is the model of the steps attackers take to go from reconnaissance to compromise to delivering a payload. And the Papercut incident is not a one-off: in another incident reported last week, an attacker methodically breached a network, harvested credentials, gained root access, and dropped their payload — all with the assistance of frontier LLMs working as a team.

And indeed, on Sept. 8, Google warned that the most forward-looking adversaries are adding agentic capabilities through the attack life cycle and using them to achieve greater efficiency and reliability in their attacks. While nation-state actors are often the most sophisticated and likely to incorporate AI into the attack life cycle, the ready accessibility of open-weight models means that using these capabilities is becoming democratized, says Kelli Vanderlee, senior manager with the Google Threat Intelligence Group (GTIG).

AI agents are entering every stage of the attack cycle now. Source: Google

"Well-resourced state-sponsored actors likely have a head start over financially motivated actors in terms of access to commercially available AI tooling and training," she says. "However, another significant differentiator is the willingness to experiment with the capabilities of the technology — many threat actors are using chatbots to ask basic questions or troubleshoot, [while] some are building more complex, multistep workflows."

Related:OpenAI Agents Took Over Wiki Site Before Hugging Face Attack

Nefarious AI in Supply Chains & Stealing Frontier Models

... continue reading