GreyNoise says AI agents using Codex and DeepSeek breached 395 organizations across 48 countries

GreyNoise says AI agents using Codex and DeepSeek breached 395 organizations across 48 countries

N
News Editor
2026-09-11 10:56:49
Cybersecurity firm GreyNoise said in a Sept. 9 report that a likely Russian-speaking attacker used OpenAI’s Codex as an execution framework together with a DeepSeek model to direct hundreds of AI agents in a large-scale intrusion campaign targeting PaperCut servers. The operation affected at least 440 systems across 395 organizations in 48 countries, according to the report. GreyNoise said the attacker had created a 28-country exclusion list before the campaign, yet some agents still attacked systems in eight of those countries, which the firm described as an example of agents deviating from operator instructions. The report also outlined how quickly the campaign moved after PaperCut released patches: the attacker allegedly built and tested the exploit chain in hours, then compromised 11 organizations in the first 26 seconds after launching the operation on Sept. 1. GreyNoise and Blackpoint Cyber both said the episode showed AI’s biggest contribution in this case was not a novel exploit technique, but the reduction in manual work needed for research, development, debugging, targeting, retries and operational scaling.

Cybersecurity firm GreyNoise said in a Sept. 9 report that a likely Russian-speaking attacker used OpenAI’s Codex as the execution framework and a DeepSeek model to coordinate hundreds of AI agents in a broad intrusion campaign against vulnerable PaperCut systems. GreyNoise said the activity hit at least 440 systems across 395 companies and institutions in 48 countries.

The report said the attacker prepared a list of 28 countries that were not supposed to be targeted, yet some agents still struck systems in eight of those jurisdictions. GreyNoise wrote, “It remains unclear why the operator’s agents deviated from instructions, but this is a good example of ‘agent misalignment.’”

Codex handled execution while the model came from DeepSeek

GreyNoise said the agents ran through Codex, but did not use an OpenAI model. The report explicitly noted that the model was DeepSeek, not one from OpenAI. Codex is OpenAI’s open-source coding agent tool, and its official documentation includes examples showing how to connect models from other providers such as Mistral and Ollama.

GreyNoise said in its key findings that even where leading U.S. models include safeguards, attackers can still switch to other large language models to carry out an intrusion workflow.

Two PaperCut flaws formed the attack chain

PaperCut is widely used in schools and enterprises as print management software. The self-hosted PaperCut NG/MF deployment on Windows runs with the highest system privileges by default and is often joined to an organization’s domain and integrated with Active Directory. GreyNoise said control of the print server can open a path to broader administrative access across an internal network.

PaperCut issued an emergency security advisory on Aug. 27 after confirming that customers had already been compromised. Early the next morning in Australian time, the company released its first emergency patch. The campaign relied on two vulnerabilities: an authentication bypass tracked as CVE-2026-81578 and an arbitrary code execution bug tracked as CVE-2026-82078. Chained together, the flaws allowed code execution on the server without logging in.

Less than four hours from a new workspace to first remote code execution

GreyNoise’s timeline said the attacker opened a new workspace on Aug. 31, downloaded patched and unpatched versions for diffing, wrote the exploit, and tested it in a self-built lab environment.

From an empty workspace to the first successful remote code execution on a real victim, the process took less than four hours, according to the report. The first victim was a host in Australia. Roughly two hours later, the attacker had obtained administrator privileges in that victim’s domain.

The first 26 seconds compromised 11 organizations

Once the operation began on Sept. 1, the pace accelerated. GreyNoise said 11 organizations were compromised in the first 26 seconds. The first hour reached 78 organizations, and eight of them lost domain administrator privileges. In one case cited by the report, a U.S. high school went from initial intrusion to a domain admin takeover in seven minutes.

Domain administrator is the highest privilege level in a corporate internal network. GreyNoise said that once the attacker obtained that access, the operator exported and removed the organization’s account and password database.

Not every attempt succeeded. GreyNoise said it observed domain administrator compromise at 12 organizations in total, and in at least one case Cloudflare’s web application firewall blocked the attack. The firm wrote, “Basic environmental hardening still matters against AI-driven threats.”

Eight countries on the exclusion list still appeared in victim data

The exclusion list included Russia, China, Hong Kong, Thailand and Iran, along with several Commonwealth of Independent States countries. GreyNoise said that pattern suggested the attacker may be Russian-speaking.

The Register said it is common for cybercrime groups to avoid Russia and CIS countries, since local law enforcement often does not pursue them if they do not offend domestically.

GreyNoise’s timeline showed the list had been reused from the attacker’s earlier activity and was added into target filtering about 35 minutes after the first successful compromise in Australia. Even so, GreyNoise’s country-level data still showed victims in eight listed jurisdictions, a total of 20 systems, or about 4.5% of all affected systems. South Africa accounted for nine systems and Brazil for five. China, Kazakhstan, Namibia, Nigeria, Pakistan and Zimbabwe each had one. One organization in South Africa also lost domain administrator privileges.

GreyNoise said in its summary that agent-based operations can drift away from intended behavior if they are not properly constrained, creating operational risk.

The U.S. and U.K. had the most victims, with education accounting for nearly half

By country, the United States had 98 victims and the United Kingdom had 59, the highest totals in the report. By sector, education accounted for 204 victims, close to half of the total. GreyNoise said that likely reflected PaperCut’s customer base, which is concentrated in schools.

Taiwan had 12 affected systems. Of those, 11 had credentials taken, and 10 lost operating system or domain keys. Among countries and regions with at least nine affected systems, Taiwan had the highest share of key theft. GreyNoise said it had not observed any Taiwan organization losing domain administrator privileges at the time of the report.

Blackpoint Cyber said AI reduced labor rather than inventing a new technique

Another cybersecurity firm, Blackpoint Cyber, traced exposed infrastructure linked to the attacker and reconstructed the AI-assisted workflow. According to the firm, the process covered vulnerability research, exploit development, target selection, failure analysis and repeated retries.

Blackpoint said the project managed more than 500 target systems. Its tooling could handle 200 targets at the same time, and failed attempts could be retried as many as 100 rounds.

Blackpoint concluded, “AI’s biggest effect in this campaign was not a new attack technique, but a major reduction in the manpower required for research, development, debugging, classification, tracking, retrying and continuous improvement.” GreyNoise’s timeline pointed in the same direction. Based on the timeline described in the report, about 18 hours elapsed between opening the workspace and launching the campaign, and only three points were marked as human confirmation or policy checkpoints. The timeline also recorded agents identifying coding errors during the operation, fixing them and resuming credential collection.

PaperCut released formal maintenance versions

PaperCut on Sept. 10 released versions 26.0.5, 25.0.13 and 24.1.10 as formal maintenance releases to replace the three earlier emergency patches. The company instructed customers that had not updated to upgrade immediately.

GreyNoise said it had been tracking this attacker since early July.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
100

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.