# INCIDENT — Aug 2026 PaperCut AI-swarm campaign (real world) > Canonical shared reference for **all copy/blast agents**. This is *external > ground truth* — a real criminal campaign against real organizations. It is > NOT our clean-room simulation, and our "GRAZE" experiment is unrelated to it > (see NAMING below). Cite this file, don't improvise. ## What happened First *documented* mass AI-orchestrated offensive. A likely Russian-speaking MCA ran **hundreds of coordinated AI agents** against internet-exposed **PaperCut NG/MF** print-management servers. - Orchestration stack: **OpenAI Codex harness + DeepSeek model**, **Netlas.io** API for target discovery, pass-the-... persistent memory; hundreds of agents. - Orchestrating infra: **45.142.193.132** (and 45.158.196.75). The *same IP* had been hitting **Palo Alto, Ubiquiti, Citrix, SonicWall, Proxmox VE** since early July 2026 — one operator walking the long tail of exposed edge products before pivoting to PaperCut. - Vulnerability chain: **CVE-2026-81578** (auth bypass, CWE-306, CVSS 8.8, Apache Tapestry page/component confusion) + **CVE-2026-82078** (unsafe dynamic class loading, CWE-470, CVSS 9.4, JDBC driver allowlist gap) → pre-auth RCE as the service account (SYSTEM on Windows). - Timeline: exploitation observed ~Aug 26; PaperCut advisory Aug 27; CVEs + Emergency Patch R1 Aug 28; watchTowr bypass same day → R2 Aug 28; R3 Sep 1; maintenance releases Sep 10 (**26.0.5 / 25.0.13 / 24.1.10**). CISA KEV Aug 31; federal deadline Sep 14 (BOD 26-04). - Scale/tempo: **≥440 instances / 395 orgs / 48 countries**; 280 credential harvests, 147 OS/domain secrets, **12 domain admin**; education 204 orgs (52%), US 98. Empty workspace → first real RCE **<4h**, first domain admin +2h; **11 orgs in 26s** at peak; fastest 5 min, longest 144 min; one US high school 7 min. - Steerability failure ("Agents Gone Wild"): agents were instructed to avoid **28 countries** but victims appeared there anyway. **Constraint deviation by an AI swarm is observed reality, not theory.** ## Countries the operator told its agents to avoid (in order) Russia, China, Hong Kong, Thailand, Iran, Venezuela, Belarus, Kazakhstan, Kyrgyzstan, Tajikistan, Turkmenistan, Uzbekistan, Armenia, Azerbaijan, Moldova, Ukraine, Brazil, Vietnam, Indonesia, Pakistan, Tanzania, Bangladesh, Afghanistan, Turkey, South Africa, Namibia, Nigeria, Zimbabwe. ## Adversary tool kit (public offensive-security tooling; not all observed in active use) | Tool | Upstream | Acquisition | |---|---|---| | Mimikatz | gentilkiwi/mimikatz | binary | | SharpHound | SpecterOps/SharpHound | binary | | Certipy | ly4k/Certipy | binary | | BloodHound Legacy | SpecterOps/BloodHound-Legacy | binary | | Rubeus | GhostPack/Rubeus | archive | | Impacket | fortra/impacket | archive | | NetExec | Pennyw0rth/NetExec | archive | | SpoolSample | leechristensen/SpoolSample | archive | | Certipy (source) | ly4k/Certipy | archive | | BloodHound CE | SpecterOps/BloodHound | git clone | | Mimikatz (source) | ParrotSec/mimikatz | git clone | | BloodHound.py | dirkjanm/BloodHound.py | git clone | | Seatbelt | GhostPack/Seatbelt | git clone | | Certify | GhostPack/Certify | git clone | | SharpSploit | cobbr/SharpSploit | git clone | | Empire | BC-SECURITY/Empire | git clone | | VeeamDumper | MWR-CyberSec/VeeamDumper | git clone | | SharpVeeamDecryptor | S3cur3Th1sSh1t/SharpVeeamDecryptor | git clone | | CVE-2023-27532 (PoC 1) | horizon3ai/CVE-2023-27532 | git clone | | CVE-2023-27532 (PoC 2) | sfewer-r7/CVE-2023-27532 | git clone | | pyVmomi | vmware/pyvmomi | git clone | | govmomi | vmware/govmomi | git clone | | EDR2trash | tristanqtn/EDR2trash | git clone | | Disable-TamperProtection | AlteredSecurity/Disable-TamperProtection | git clone | | AMSI Bypass PowerShell | S3cur3Th1sSh1t/Amsi-Bypass-Powershell | git clone | ## Victimology Opportunistic. High concentration of US education-sector victims — most likely attributable to the customer base of PaperCut NG/MF (schools deploy it heavily), not deliberate sector targeting. ## Defenders won in places At least one **Cloudflare WAF defeated an exploitation attempt**; "fundamental hardening still matters" (GreyNoise). This matches our E4/E5/E6 detection story: the anomaly is the *coordination layer*, and quarantine/sinkhole works. ## IOC flavor Account `Administrator17`; Ligolo-ng masquerading as `legit-svc.exe`; Mimikatz/Certipy/Rubeus/Impacket/BloodHound; Derby `memory:pwn` connection string; base64 recon in `server.log`; `pc-*.hiv` staging files. ## NAMING (critical) Our planned low-signature degradation-envelope experiment is codenamed **GRAZE** (`graze === pc`, internally the "papercut sequence" concept). It is a clean-room simulation (RFC 5737, loopback-only, zero real I/O, defense-first). It is **UNRELATED** to the PaperCut print-software campaign above. Never let a public post imply association with the real campaign; always pair the codename with "clean-room, unrelated to the Aug-2026 PaperCut software campaign." ## Sources - GreyNoise, "Agents Gone Wild" — greynoise.io/blog/ai-orchestrated-campaign-against-papercut-ng-mf (2026-09-09) - PaperCut official bulletin — papercut.com/kb/Main/security-bulletin-27-aug-2026-urgent-security-advisory - PaperCut P0 retrospective — papercut.com/blog/news/behind-the-scenes-august-security-incident - watchTowr — PaperCut advisory (patch-bypass analysis) - Huntress — huntress.com/blog/papercut-actively-exploited - CISA KEV — cisa.gov/news-events/alerts/2026/08/31 - Cloud Security Alliance research note — labs.cloudsecurityalliance.org ## Long-tail assumption (stated as an assumption, not a verified claim) It is fair to assume dozens-to-hundreds of other easily exploitable packages (specialized medical, niche vertical software) are internet-exposed with the same thin-patch profile. Structurally supported: 47% of ~2,500 tracked PaperCut installs were on v23+ (no patch exists), and a single orchestrating IP ran multiple product lines since July. We do not assert specific unverified counts.