A Russian-speaking operator tracked as CyberXero has blended commercial AI coding agents with established offensive tools to run both high-volume website attacks and targeted operations against Ukrainian energy organizations. Evidence recovered from an exposed working directory suggests the actor is functioning as an initial-access broker: compromising systems, collecting data and potentially preparing access that could be reused or sold.
Researchers at SOCRadar connected the campaign after discovering more than 90,000 exposed files, including scripts, AI session histories, configuration records and stolen information. The operation reportedly affected more than 40 organizations across several countries and remained active during the investigation.
Two layers of AI-assisted intrusion
CyberXero did not use AI only for advice or code snippets. On a primary workstation, the operator configured as many as 51 Claude Code agents with specialized roles covering web discovery, credential testing, exploitation and data collection. A separate environment linked the PentAGI AI penetration-testing framework to a Cobalt Strike team server through an AI provider API.
Recovered settings indicate that models and token budgets were assigned according to the difficulty of each task. Lower-cost roles handled routine searches and software installation, while more capable configurations were reserved for payload generation. This orchestration shows how an individual operator can distribute work across multiple agents and compress activities that once required more manual coordination.
In one automated run, the system scanned 4,708 targets, identified 429 accessible WordPress administration panels and reportedly planted 32 shells in 61 seconds. The figures illustrate the main defensive challenge posed by agentic tooling: it can move from discovery to exploitation across a large target set with very little delay.
Safeguards were tested and sometimes bypassed
Session records show the operator presenting malicious tasks as authorized security testing. When an agent refused, CyberXero sometimes opened a fresh session and reused the same prepared explanation. Other safeguards held, including refusals to install a backdoor, disable a firewall, move laterally and deploy a web shell.
This uneven result matters to both AI providers and enterprise users. A refusal inside one conversation is less valuable if a new session resets the relevant context. It also makes AI session records highly sensitive. Logs can reveal target information, credentials, attack logic and operational infrastructure, so organizations should encrypt them, tightly limit access and preserve reliable audit trails.
Mass compromise met targeted reconnaissance
The broad pipeline focused on WordPress and e-commerce sites. An internal package called wp2shell used a WordPress REST API batch route as part of a chain that injected SQL, created rogue administrator accounts and installed WSO-family web shells on vulnerable installations. The actor also targeted Magento and exploited a recently disclosed Support Board vulnerability within roughly a month of publication.
A more selective track mapped seven Ukrainian energy and utility entities. Across two organizations, the actor enumerated 95 subdomains and catalogued email, VPN and network-dispatch services. Researchers found file-confirmed theft at four Ukrainian organizations. Data associated with a Kharkiv district-heating provider included 564,073 subscriber records and 213,340 access-log entries, reportedly reached with a hardcoded credential found in the operator’s own tooling.
The investigation also linked eight infrastructure nodes across European hosting providers and Tencent Cloud. Shared artifacts connected mass scanning, staging, Cobalt Strike services and operator workstations. Although researchers did not prove that access had already been sold, the mix of opportunistic compromise and infrastructure-specific reconnaissance creates a credible follow-on risk.
Defensive priorities
- Patch WordPress core, plugins, e-commerce platforms and internet-facing support software promptly.
- Search for unfamiliar administrator accounts and plugin paths matching rogue wp2shell-style installations.
- Review web logs for rapid REST API batch activity, SQL injection attempts and unexpected shell uploads.
- Restrict internet exposure for Redis, rotate embedded credentials and audit authorized SSH keys.
- Treat AI-agent histories, configuration files and API tokens as sensitive security assets.
CyberXero’s importance lies less in any single tool than in the workflow connecting them. AI agents, exploitation frameworks and commodity post-compromise tooling can now form a repeatable pipeline. Defenders should expect shorter intervals between vulnerability discovery, scanning and compromise—and tune monitoring and patch operations accordingly.
Leave a Reply
You must be logged in to post a comment.