AI-powered attack exploited PaperCut flaws to hack 395 organizations
Attackers used AI tools to find and exploit flaws in PaperCut NG/MF software, breaking into 395 organizations worldwide. The attackers then stole data and installed malware on the compromised systems.
- Report priority
- Medium
How it works
- The attackers sent specially crafted requests to PaperCut NG/MF servers that had not been updated.
- These requests tricked the software into running code that let the attackers take control of the system.
- The attackers then used that access to steal data and install malware.
What to do
If you use PaperCut NG/MF software, check your installed version by opening the software and looking for the version number in the About or version screen. If your version is before 20.0.8000, you are affected and should update immediately.
Update to PaperCut NG/MF version 20.0.8000 or later. You can download the latest version from the official PaperCut website. After updating, verify the new version number to confirm the fix is applied.
Technical details
The attackers used AI tools to automate scanning for vulnerable PaperCut servers and crafting the malicious requests. Once a server was compromised, the attackers moved laterally within the network to steal sensitive data and deploy ransomware.
A threat actor, likely Russian-speaking, used hundreds of AI agents to develop and launch a global exploitation campaign targeting vulnerable PaperCut NG/MF servers.