| AI Security / Autonomous Attack | A Hacker's AI Agents Breached 395 Organizations in 48 Countries. It Took Them Six Hours to Go From Nothing to Full Domain Control. | Key Points | | — | GreyNoise reported Sept. 9 that a likely Russian-speaking actor used hundreds of AI agents, built on OpenAI's Codex harness and a DeepSeek model, to breach 440 PaperCut instances at 395 organizations in 48 countries. | | — | The agents went from an empty workspace to remote code execution in under four hours, reached domain-admin two hours after that, and compromised 11 organizations in a single 26-second window at peak. | | — | The agents built their own target lists via the Netlas.io scanning service and ran known offensive tools — Mimikatz, SharpHound, Certipy — largely without step-by-step human direction. | | — | Despite the breadth, full domain-admin access landed at only 12 organizations — breadth scaled far faster than depth. | | | | An ordinary office print server was the entry point for a breach spanning 48 countries. | GreyNoise reported on September 9 that a likely Russian-speaking threat actor used hundreds of AI agents — built on OpenAI's Codex harness and a DeepSeek model — to develop and deploy exploits against two vulnerabilities in PaperCut NG/MF print-management software, compromising at least 440 instances across 395 identified organizations in 48 countries since the campaign began August 31. The speed is the actual story. GreyNoise found the attacker went from an empty workspace to remote code execution against a real victim in under four hours, reached first domain-admin access two hours after that, and once the full campaign launched, compromised 11 organizations in a single 26-second window. The agents built their own target lists using the Netlas.io internet-scanning service, then ran known offensive-security tools — Mimikatz, SharpHound, Certipy, Rubeus, Impacket — largely without step-by-step human direction. | By The Numbers | | 4 hrs empty workspace to first RCE | | | 26 sec to compromise 11 organizations at peak | | | 12 orgs where domain-admin was actually reached | | | Education institutions accounted for roughly half of all breaches, the most-hit sector; the United States was the most-targeted country, followed by the UK, France, Spain, and Canada. GreyNoise found the attacker had explicitly instructed the agents to avoid eight countries, including Russia, China, and Iran — a targeting pattern consistent with state-nexus tradecraft, though the campaign hit victims in some excluded countries anyway. Despite the breadth, most of the damage stayed contained: credentials were harvested from 280 organizations and OS or domain secrets from 147, but full domain-admin privileges were reached at only 12. | Large language models are enabling adversaries to move at greater speed and scale. — GreyNoise, incident analysis | | 🧠 Quick Quiz | | How many organizations did the attacker compromise in a single 26-second window at peak campaign speed? | | ✓ Answer: B. 11 organizations in 26 seconds — a rate of compromise no human-run operation could realistically sustain across 395 total victims. | The gap between initial access — 440 instances, near-instant — and full domain control at just 12 organizations is itself informative. It suggests AI-accelerated attacks are currently better at breadth than depth: automating the easy, repeatable steps at a scale no human team could match, while harder, environment-specific escalation still bottlenecks on local configuration quirks the agents couldn't universally exploit. That gap is the current state of the art, not a permanent ceiling — and it's shrinking with every version of the underlying models this newsletter has covered chaining zero-days and escaping their own sandboxes elsewhere this month. |