A suspected Russian linked cyber actor has been attributed to the use of artificial intelligence (AI) to devise exploits targeting a recently disclosed pair of security flaws in PaperCut NG/MF and break into hundreds of instances has been observed scanning New Zealand and Australian IP addresses as part of its campaign.
According to independent reports from Blackpoint Cyber and GreyNoise, the activity is linked to “45.142.193[.]132” and “45.142.193[.]196” IP addresses that has been linked to unauthorized port scanning and brute-force attack attempts in recent weeks.
For New Zealand activity the IP addresses were observed scanning IP Sec, iDRAC, ldap/ldaps services as well as attempting Global Protect VPN logins.
It’s worth noting that some of the same IP addresses were also flagged by Arctic Wolf in connection with the exploitation activity last week.
It is not known if the aim of the campaign is by an initial access broker or a ransomware operator/affiliate. Nor do we know the name of the Australian business where Domain Admin access was gained on the morning of the 1st of September.
The campaign attempts to exploit CVE-2026-81578 and CVE-2026-82078, a combination of an authentication bypass and remote code execution chain.
GreyNoise said it has been tracking the malicious use of the IP addresses since early July 2026 for probing internet-facing systems from several vendors, including Palo Alto GlobalProtect, Ubiquiti, Citrix, SonicWall, and Proxmox VE and other reports online for FortiWeb scanning from the IP address as well.
In 1 day and 8 hours the actor completed exploit development and testing, they built and attacked a lab environment that included the vulnerable PaperCut software and an Active Directory server as well as repeatedly refined a target list of victims. Pre AI this would have taken weeks.
Fortunately for us but unfortunately for the attacker they left an open HTTP directory on the host they were using which shed light on exactly how they were executing their campaign.


They were observed using netlas.io, an online scanner to help build their target list. Netlas.io do not list which IP addresses they use to do their scanning so organisations cannot identify if they have been scanned nor block future scans. You could register for a free account and check what information is held by netlas.io against your IP addresses though it is less featured than shodan.io.
Upon gaining remote code execution and credential harvesting within its self-hosted lab environment, the threat actor has been seen unleashing hundreds of AI Agents powered by AionUI, a free open-source desktop app that brings multiple command-line AI agents and models together, as well as publicly available offensive security tools (e.g., Mimikatz, SharpHound and Impacket).
In the end they compromised more than 440 instances of PaperCut hosted by 395 identified victim organizations in 48 countries, while avoiding victims in 28 listed countries including Russia and China.

Timeline
| Date & Time | Activity |
| 27/08/2026 | PaperCut security advisory published |
| 1/09/2026 2:44 | Workspace created; PaperCut advisory downloaded. Pre- and post-patch versions downloaded and internet searches conducted for PoC code. |
| 1/09/2026 3:28 | Initial list of targets created |
| 1/09/2026 3:54 | Diffed vulnerable and patched versions, created exploits and ran tests against patched and unpatched targets in Africa |
| 1/09/2026 4:09 | Built multithreaded tool which runs and identifies 462 targets |
| 1/09/2026 4:23 | Added targets to target list following code improvements |
| 1/09/2026 4:26 | Downloaded IP2Location country database and checked the countries associated with 1,501 potential target IP addresses |
| 1/09/2026 4:35 | Created local lab containing an Active Directory server and vulnerable PaperCut server |
| 1/09/2026 5:02 | Added eight additional fake users to AD and refined target list |
| 1/09/2026 6:39 | Achieved first RCE and shell on an Australia-based victim |
| 1/09/2026 7:14 | Added logic to exclude targets from 28 specific countries |
| 1/09/2026 8:50 | Created compartmentalised kits per target, including combinations of scripts to enable post-exploitation network connectivity and create accounts for addition to victims’ Domain Admin groups |
| 1/09/2026 9:00 | Validated Domain Admin access on the Australian victim |
| 1/09/2026 19:00 | Refined target list using Netlas.io, a web-based internet scanner |
| 1/09/2026 20:30 | Launched exploitation campaign against refined target list. 11 organisations exploited in the first 26 seconds. Credential harvesting began within one minute. In the first hour, 78 organisations were exploited, with 8 achieving Domain Admin access |
| 1/09/2026 20:38 | First attempts from 45.142.193[.]196 against New Zealand IP Addresses |
| 2/09/2026 5:01 | Due to security controls encountered, scanner automatically adjusted thread usage to reduce performance impacts |
| 2/09/2026 5:15 | Scanner recognised a bug, automatically fixed it and continued |
| 2/09/2026 8:20 | Last attempts from 45.142.193[.]196 against New Zealand IP Addresses observed |
| 2/09/2026 11:12 | Last RCE achieved. 223 organisations compromised |
IOCs
IP Addresses – Unsurprisingly none of these with in the Malware Free network feeds
Search between 15th July 2026 and 8th September 2026.
45.142.193[.]132
45.142.193[.]196
194.180.48[.]134
Ports scanned
tcp: 389, 636, 4300, 4301, 4117, 4118, 9191, 9292, 9195
udp: 500, 4500, 623