Incident
Published 2026-10-06
Verified 2026-10-08

SOCRadar: "CyberXero", a Russian-speaking access broker, ran up to 51 Claude Code agents and a PentAGI-to-Cobalt Strike setup against WordPress and shop sites worldwide and Ukrainian energy firms; an open directory exposed its live working files

SOCRadar's Threat Research Unit published research on 6 October 2026 into CyberXero, a Russian-speaking, financially motivated initial access broker that pairs common attack tools with an AI orchestration layer on its own servers. Everything surfaced through one mistake: an open directory served the actor's live working folder, more than 90,000 files including AI session logs, scripts with plaintext tokens and stolen data, and the actor stayed active while researchers watched. On one workstation it configured up to 51 Claude Code agents for discovery, password testing, exploitation and data theft; a second setup connected PentAGI, an open-source AI penetration-testing framework, to a Cobalt Strike team server through an AI provider's API, with model choice and token budgets set per task. Session logs show the operator telling the model the targets were its own systems under authorised testing and, when refused, opening a fresh session with the same cover story; some refusals held, including requests to install a backdoor, disable a firewall, move across a network and plant a webshell. The broad campaign used an internal wp2shell package that abuses the WordPress REST API batch endpoint to inject SQL, create a rogue administrator and drop a WSO-family webshell, and it also hit Magento and used Support Board CVE-2026-4815 within 30 days of disclosure; one automated run scanned 4,708 targets, found 429 reachable WordPress admin panels and placed 32 shells in 61 seconds. A separate hand-picked pipeline mapped seven Ukrainian energy and utility organisations, including the national transmission operator; four Ukrainian organisations had confirmed data theft, a Kharkiv district-heating provider lost 564,073 subscriber records, and data on more than 628,000 Ukrainians was found. More than 40 organisations were affected worldwide, with activity also seen in Poland, China and Pakistan; SOCRadar found no direct proof of an access sale. Infrastructure was first seen in July 2026 across eight nodes in European hosting and Tencent Cloud. Primary: SOCRadar; wire: Cyber Security News (7 Oct).

Product
WordPress (REST API batch endpoint abuse), Magento and Support Board (CVE-2026-4815) sites; Ukrainian energy and utility networks
Versions
n/a — intrusion campaign
Exploited in Australia?
unknown
Patch to
Keep WordPress core and plugins current, look for administrator accounts and plugins you did not add, and block or authenticate access to the REST API batch endpoint where you don't need it. Patch Support Board and Magento, keep Redis off the internet, and review authorized_keys on web servers. If you run AI coding agents, store their session logs like credentials: encrypted, access-limited and audited.

Primary: SOCRadar — CyberXero: an AI-augmented initial access broker targeting Ukrainian critical infrastructure (6 Oct 2026) · CVE: CVE-2026-4815 · Cyber Security News — CyberXero combines Claude Code, PentAGI and Cobalt Strike in AI-augmented cyberattacks (7 Oct 2026)

ai