Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Attackers Hijack .gh, .sl, .as Domain Registries for Rogue HTTPS Certificates
October 7, 2026
CyberXero Blends AI Tools Claude Code, PentAGI with Cobalt Strike for Attacks
October 7, 2026
CrowdStrike, AWS, NVIDIA Expand Cybersecurity Startup Accelerator
October 7, 2026
Home/CyberSecurity News/CyberXero Blends AI Tools Claude Code, PentAGI with Cobalt Strike for Attacks
CyberSecurity News

CyberXero Blends AI Tools Claude Code, PentAGI with Cobalt Strike for Attacks

Key Takeaways The Russian-speaking threat actor CyberXero is leveraging a combination of commercial AI tools like Claude Code and PentAGI with Cobalt Strike to conduct large-scale cyberattacks....

Sarah simpson
Sarah simpson
October 7, 2026 6 Min Read
2 0

Key Takeaways

  • The Russian-speaking threat actor CyberXero is leveraging a combination of commercial AI tools like Claude Code and PentAGI with Cobalt Strike to conduct large-scale cyberattacks.
  • Targets include WordPress and e-commerce websites globally, as well as critical infrastructure, specifically energy and utility organizations in Ukraine.
  • An exposed directory revealed over 90,000 files, including scripts, AI session logs, and stolen data, indicating ongoing operations and potential sale of compromised access.
  • The campaign has resulted in significant data theft, with over 628,000 Ukrainian residents’ data confirmed to be in the actor’s possession, including those from Kharkiv.
  • AI tools are being used for various stages of the attack chain, from web discovery and exploitation to data exfiltration and payload generation, demonstrating sophisticated AI-augmented attack capabilities.

A new initial access broker (IAB) known as CyberXero has emerged, utilizing a sophisticated blend of established hacking tools and advanced artificial intelligence to orchestrate extensive intrusion campaigns. The Russian-speaking operator has been observed targeting WordPress and e-commerce platforms worldwide, while simultaneously conducting reconnaissance and probing against Ukrainian energy and utility sector entities.

Table Of Content

  • Key Takeaways
  • CyberXero Combines Claude Code, PentAGI, and Cobalt Strike
  • Websites and Ukrainian Infrastructure
  • What You Should Do

The scope of this operation came to light following the discovery of an open directory containing more than 90,000 files. These files included various scripts, detailed AI session records, and exfiltrated data, providing a rare glimpse into the attacker’s methodologies. This exposed evidence indicated that the CyberXero campaign was still active during the investigation, raising serious concerns that the compromised access could be subsequently sold to other threat actors or reused for further malicious activities. Security researchers at SOCRadar said in a report that they identified this activity and attributed it to a financially motivated actor operating under the CyberXero alias.

The scale and efficiency of CyberXero’s operations are particularly alarming. In one automated instance, the actor scanned 4,708 targets, successfully identified 429 accessible WordPress administration panels, and deployed 32 webshells within a mere 61 seconds. Furthermore, the actor has confirmed possession of data belonging to over 628,000 Ukrainian citizens, including residents of Kharkiv.

CyberXero Combines Claude Code, PentAGI, and Cobalt Strike

CyberXero’s approach to integrating AI goes beyond simple assistance, incorporating two distinct AI layers within its attack infrastructure. On a primary workstation, the actor configured up to 51 Claude Code agents. These agents were deployed for various tasks, including web discovery, password brute-forcing, vulnerability exploitation, and data exfiltration. This multi-agent setup mirrors other documented cases where commercial AI tools like Claude have been leveraged for automated attack operations.

A second, more advanced configuration involved connecting PentAGI, an AI-assisted penetration-testing framework, to a Cobalt Strike Team Server via an AI provider API. Recovered settings from this setup reportedly showed that models and token budgets were strategically assigned based on the complexity of the task. More resource-intensive operations, such as payload generation, were allocated greater computational effort, while less demanding tasks like reconnaissance searches and initial installations were handled by more cost-effective roles.

Analysis of session logs revealed how the operator attempted to circumvent AI model refusals by presenting a fabricated narrative. When a request was denied, the actor would initiate a new session with the same preloaded story, demonstrating how single-session security measures can be undermined by session resets. However, the logs also documented instances where AI models successfully resisted requests, specifically denying attempts to install backdoors, disable firewalls, perform network lateral movement, and deploy webshells. This highlights the critical importance of securely managing AI agent logs: organizations must encrypt them, restrict access, maintain comprehensive audit trails, and treat them with the same level of security as credentials or cryptographic keys.

Websites and Ukrainian Infrastructure

CyberXero’s broad-ranging campaign specifically targeted WordPress and e-commerce platforms. The actor utilized an internal tool, dubbed “wp2shell,” which exploited the WordPress REST API batch endpoint. This allowed for SQL injection, the creation of unauthorized administrator accounts, and the installation of a WSO-family webshell. This attack chain underscores the critical need for prompt patching of WordPress installations vulnerable to the wp2shell remote execution vulnerability. The actor also targeted Magento platforms and was observed exploiting Support Board CVE-2026-4815 within 30 days of its public disclosure.

Beyond the opportunistic attacks on websites, CyberXero also conducted a highly targeted reconnaissance effort against Ukrainian critical infrastructure. This specialized pipeline focused on seven distinct energy and utility entities in Ukraine, including the national transmission system operator and the country’s largest private energy holding company. The actor successfully enumerated 95 subdomains across two of these organizations, identifying various critical services such as email systems, VPN infrastructure, and network dispatch platforms. Confirmed data theft occurred at four Ukrainian organizations.

One notable incident involved a Kharkiv district heating provider, which suffered the loss of 564,073 subscriber records and 213,340 access-log entries. This breach was facilitated by the actor’s use of a hardcoded credential embedded within their own script. This incident serves as a stark reminder that cyber risks to Ukrainian infrastructure extend beyond operational disruption to include significant data exfiltration.

The campaign’s global reach extended to over 40 organizations, with observed activity in countries including Poland, China, and Pakistan. Although investigators found no direct evidence of compromised access being sold, the combination of widespread data harvesting and precise reconnaissance of critical energy infrastructure suggests a substantial threat to any organization with exposed systems or data.

Investigators first identified CyberXero’s infrastructure in July 2026, mapping eight interconnected nodes hosted across European providers and Tencent Cloud. The exposed working directory, containing over 3,000 subdirectories, provided crucial insights, enabling researchers to link workstation activity, provisioning records, and attack staging through shared artifacts. This detailed visibility was instrumental in differentiating confirmed data theft incidents from reconnaissance activities that had not yet resulted in verified compromises at the time of the investigation.

Indicators of Compromise (IoCs):-

Type Indicator Description
IP address 46.21.250.135 Primary workstation and open-directory seed node
IP address 45.88.106.2 Provisioning server, port 1500
IP address 212.193.31.189 Multi-chain CryptoPay gateway
IP address 42.193.227.214 Cobalt Strike Team Server and PentAGI, port 9995
IP address 91.208.184.148 Secondary workstation
IP address 45.88.106.78 Mass-scanning server
IP address 49.234.12.182 Staging and payload delivery node in the Chinese cluster
IP address 42.193.100.94 Redis exploitation node and PentAGI agents
Network endpoint 42.193.227.214:1002 Cobalt Strike beacon over HTTPS
Network endpoint 42.193.227.214:8044 Cobalt Strike HTTP staging
Network endpoint 42.193.227.214:8033 Cobalt Strike PowerShell IEX stager delivery
SHA-256 92a789444708fa1cb4cc5a89e0aa6cc7a279b62a7b8a4d2857255a18197d0090 stager3
SHA-256 a5ae0aab352871bc0b038b3aa43b03eb223425628c884af7b9fc592cd34eb86c WSO-S
SHA-256 71e21094c1ac1cf0275c91ed377965e248bca1c12711f6dd20e2682681fc1192 1.bin
SHA-256 59c535f47ab4d35f6d9fc8b8aec4a72438ea0b89e5a4dcea74b05d2d32cfa483 config.b
Username pattern wp2_[0-9a-f]{8} Rogue WordPress administrator account pattern
File path pattern /wp-content/plugins/wp2shell_[0-9a-f]{8}/ wp2shell webshell plugin path
Service name UpdSvc Persistence service created through svc.cna
URL pattern http://42.193.227.214:8033/[a-z0-9]{13} PowerShell stager download URL pattern

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

What You Should Do

  • Patch and Update Regularly: Ensure all web applications, especially WordPress and e-commerce platforms like Magento, are immediately updated to the latest versions. Pay particular attention to patches addressing remote code execution vulnerabilities like those exploited by CyberXero’s wp2shell.
  • Monitor for Rogue Accounts and Plugins: Regularly inspect WordPress installations for any unfamiliar or unauthorized administrator accounts and unexpected plugins. Implement strong access controls and multi-factor authentication for all administrative interfaces.
  • Restrict Internet-Facing Services: Limit direct internet exposure for services like Redis. Implement robust firewall rules and network segmentation to minimize attack surfaces.
  • Review SSH Keys and Credentials: Conduct periodic audits of authorized SSH keys and other critical credentials for any unauthorized changes or suspicious activity. Rotate credentials frequently.
  • Secure AI Agent Logs: If using AI tools in your operations, treat their session logs with the highest level of security. Encrypt these logs, restrict access to authorized personnel, and maintain comprehensive audit trails. Consider them as sensitive as cryptographic keys or privileged credentials.
  • Implement Advanced Threat Detection: Deploy endpoint detection and response (EDR) and network detection and response (NDR) solutions capable of identifying indicators of compromise (IoCs) and anomalous behavior, especially those related to Cobalt Strike beacons and webshell deployments.
  • Enhance Critical Infrastructure Security: Organizations in critical sectors, particularly energy and utilities, should conduct thorough vulnerability assessments and penetration tests. Focus on exposed services, implement strict access policies, and enhance monitoring for reconnaissance activities targeting their infrastructure.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackCVEExploitPatchransomwareSecurityThreatVulnerability

Share Article

Sarah simpson

Sarah simpson

Sarah is a cybersecurity journalist specializing in threat intelligence and malware analysis. With over 8 years of experience covering APT groups, zero-day exploits, and advanced persistent threats, Sarah brings deep technical expertise to breaking cybersecurity news. Previously, she worked as a security researcher at leading threat intelligence firms, where she analyzed malware samples and tracked cybercriminal operations. Sarah holds a Master's degree in Computer Science with a focus on cybersecurity and is a regular contributor to major security conferences.

Previous Post

CrowdStrike, AWS, NVIDIA Expand Cybersecurity Startup Accelerator

Next Post

Attackers Hijack .gh, .sl, .as Domain Registries for Rogue HTTPS Certificates

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
FBI Warns of Critical FortiBleed Attacks Exploiting Fortinet Firewalls and VPNs
October 7, 2026
Fake Cloudflare CAPTCHAs Spread LUNEXSTEALER to 100+ Websites
October 7, 2026
Critical Atlassian Jira RCE Exploit Released for CVE-2023-22524
October 7, 2026
Top Authors
David kimber
David kimber
Marcus Rodriguez
Marcus Rodriguez
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us