HomeMalware & ThreatsAI Agents Employed in PaperCut Attacks Targeting 395 Organizations

AI Agents Employed in PaperCut Attacks Targeting 395 Organizations

Published on

spot_img

GreyNoise Discovers Large-Scale AI-Driven Attack Targeting PaperCut Systems

A recent investigation by the threat intelligence firm GreyNoise has unveiled a sophisticated and widespread cyber campaign that utilized artificial intelligence to exploit vulnerabilities within PaperCut systems. This campaign, attributed to a likely Russian-speaking threat actor, reportedly compromised a total of 395 organizations across 48 different countries.

The focus of this attack was on PaperCut NG and MF, self-hosted applications widely used for managing printing, copying, and scanning tasks. These applications are integral to many organizations’ operations, making them appealing targets for cybercriminals. GreyNoise’s analysis highlighted that the attacker leveraged two newly disclosed vulnerabilities within these applications. The first vulnerability allowed the intruder to bypass authentication processes, while the second flaw enabled remote code execution, both critical mechanisms that opened pathways for further exploitation. The urgency of these vulnerabilities prompted PaperCut to release emergency fixes at the end of August. A security bulletin issued by the company indicated that the updated versions containing these patches were rolled out on September 10, reinforcing the necessity of proactive measures in the rapidly evolving cyber landscape.

In their detailed report, GreyNoise shed light on the sequence of events that led to the widespread breaches. The attacker was observed creating and testing various exploits in a controlled environment equipped with vulnerable PaperCut software and an Active Directory server. Utilizing the Netlas search service, the attacker compiled a list of potential targets across the globe.

Equipped with hundreds of AI agents, the threat actor launched coordinated attacks on internet-facing PaperCut installations. The tools employed included OpenAI’s Codex, a DeepSeek model, and various publicly available offensive security tools. The sheer scale and speed at which the attacker was able to operate can largely be attributed to the capabilities of large language models, allowing for rapid deployment and execution of their malicious plans.

The results of the attack were alarming. GreyNoise confirmed that at least 440 PaperCut systems were compromised across the identified organizations. Notably, within the span of mere minutes, the attacker managed to breach the security of some entities. For instance, 11 organizations fell victim just 26 seconds after the initial campaign launch. Within four hours from starting with an empty workspace, the attacker succeeded in executing code remotely on their first victim’s system.

Once access to the PaperCut systems was established, the attacker sought to deepen their foothold within the affected networks by collecting privileged credentials and maneuvering deeper into the victim’s infrastructure. Various pathways allowed the attacker to achieve administrator-level access. This included the theft of privileged credentials, exploitation of outdated Windows vulnerabilities, and taking advantage of PaperCut servers that were already operating with elevated privileges.

GreyNoise’s findings revealed that the attacker successfully gained domain administrator access at 12 different organizations. In one notable instance, a U.S. high school experienced a breach where the attacker escalated privileges in just seven minutes after gaining initial access, further demonstrating the quick exploitative capabilities of this AI-assisted campaign.

Even amid these calculated attacks, measures were taken to avoid detection. The attacker ordered their AI agents to steer clear of targets located in 28 countries, including Russia, China, Iran, Belarus, and Ukraine. However, GreyNoise noted that attacks were still registered in some of these regions, suggesting that the actor might have underestimated their reach.

Of the affected organizations, a staggering 204 were within the education sector. GreyNoise posits that this figure likely correlates with PaperCut’s significant presence in educational institutions, rather than being an intentional focus on this sector alone. Additionally, during the investigation, the team observed that Cloudflare’s web application firewall successfully blocked an attack targeted at a PaperCut system that was presumed to be vulnerable.

This incident underscores the evolving threat landscape where the integration of artificial intelligence into cybercrime elevates the efficacy of attacks and poses significant risks to organizations worldwide. As cyber threats grow increasingly complex and sophisticated, the critical need for robust cybersecurity measures and timely updates cannot be overstated. Organizations using PaperCut systems and similar applications must remain vigilant and proactive in safeguarding their infrastructures against potential breaches.

Source link

Latest articles

VLC Media Player Vulnerabilities Enable Memory Corruption and Sensitive Data Leaks

Security Risks Discovered in VLC Media Player: Heap Memory Vulnerabilities Exposed Recent security assessments have...

ConnectWise Addresses Critical Authentication Failure in ScreenConnect After Five Days

ConnectWise Addresses Security Vulnerability in ScreenConnect In a decisive move to bolster cybersecurity, ConnectWise has...

Update Your Firewall Rules: Teams and Copilot Are Changing Addresses

Microsoft has outlined important updates for enterprises concerning the new Copilot address, specifically regarding...

Hackers Target US Eastern Business Hours in M365 Phishing Campaign

Phishing Campaign Exploiting Microsoft 365 Direct Send Feature Surfaces A recent investigation has unveiled a...

More like this

VLC Media Player Vulnerabilities Enable Memory Corruption and Sensitive Data Leaks

Security Risks Discovered in VLC Media Player: Heap Memory Vulnerabilities Exposed Recent security assessments have...

ConnectWise Addresses Critical Authentication Failure in ScreenConnect After Five Days

ConnectWise Addresses Security Vulnerability in ScreenConnect In a decisive move to bolster cybersecurity, ConnectWise has...

Update Your Firewall Rules: Teams and Copilot Are Changing Addresses

Microsoft has outlined important updates for enterprises concerning the new Copilot address, specifically regarding...