CyberXero Actor Leverages AI Tools for Large-Scale Cyberattacks
A sophisticated initial access broker known as CyberXero is employing AI tools like Claude Code and PentAGI alongside Cobalt Strike to conduct extensive cyberattacks targeting WordPress, e-commerce sites, and Ukrainian energy infrastructure.

A new threat actor, identified as CyberXero, has emerged as a significant player in the cybercrime landscape, utilizing a potent combination of artificial intelligence tools and traditional hacking frameworks to execute large-scale intrusions. This Russian-speaking operator has been observed targeting WordPress and e-commerce platforms globally, while also conducting separate, more focused probes against Ukrainian energy and utility organizations. The scope of CyberXero's operations came into sharp focus after an inadvertently exposed directory revealed over 90,000 files, including sensitive AI session records, operational scripts, and exfiltrated data, indicating the campaign was active and ongoing during the investigation.
Analysts at SOCRadar, who identified and reported on the activity, described CyberXero as a financially motivated actor employing both automated and meticulously planned campaigns. The sheer scale of some automated operations is striking; one instance saw the actor scan 4,708 targets, identify 429 accessible WordPress administration panels, and successfully deploy 32 web shells in a mere 61 seconds. The impact on individuals is also considerable, with evidence suggesting the actor possessed confirmed data belonging to over 628,000 Ukrainian citizens, including residents of Kharkiv.
CyberXero's innovative approach lies in its sophisticated integration of AI, moving beyond simple assistance to treating AI as a core component of its attack infrastructure. On its primary workstation, the actor configured up to 51 Claude Code agents to perform various stages of the attack lifecycle, including web reconnaissance, password testing, exploitation, and data exfiltration. This mirrors patterns observed in other advanced attack campaigns that leverage commercial AI tools for automation. Further complicating the threat, a second setup integrated PentAGI, an AI-assisted penetration-testing framework, with a Cobalt Strike Team Server via an AI provider API. Recovered configurations suggest the actor intelligently assigned AI models and token budgets based on task complexity, dedicating more resources to critical payload generation while using less resource-intensive models for initial reconnaissance and deployment.
Evidence from recovered session logs highlights the actor's attempts to circumvent AI safety mechanisms. The operator was observed trying to overcome AI refusals by falsely claiming that targets were owned systems undergoing authorized testing. When an AI request was rejected, the actor would simply open a new session with the same preloaded context, demonstrating a method to weaken the effectiveness of single-session safeguards. Notably, some AI refusals persisted, including requests to install backdoors, disable firewalls, move laterally across networks, and deploy webshells. This underscores the critical importance of secure handling of AI agent logs, recommending encryption, access controls, and audit trails, treating them with the same security as credentials or cryptographic keys.
CyberXero's broad campaign primarily targeted WordPress and e-commerce sites. A proprietary package, dubbed 'wp2shell,' exploited the WordPress REST API's batch endpoint to inject SQL, create rogue administrator accounts, and deploy WSO-family webshells. This highlights the urgent need for prompt patching of vulnerabilities like the wp2shell remote execution chain on affected installations. The actor also demonstrated proficiency in targeting other platforms, including Magento, and exploited the Support Board CVE-2026-4815 vulnerability within 30 days of its disclosure. Administrators are advised to ensure WordPress installations are updated, scrutinize for unauthorized plugins and accounts, restrict internet-facing Redis instances, and review SSH keys for any suspicious additions.
The more targeted offensive against Ukrainian infrastructure identified seven energy and utility entities, including the national transmission system operator and the country's largest private energy holding. The AI agents enumerated 95 subdomains across two organizations, identifying a range of services from email and VPNs to network dispatch platforms. File-level evidence confirmed data theft from four Ukrainian organizations. A district heating provider in Kharkiv, for instance, suffered the loss of 564,073 subscriber records and 213,340 access log entries, exacerbated by the actor's use of hardcoded credentials within its own scripts. This incident serves as a stark reminder that the risks to Ukrainian infrastructure extend beyond mere service disruption to encompass significant data breaches.
Globally, the campaign impacted over 40 organizations, with activity also noted in Poland, China, and Pakistan. While direct proof of access sales was not found, the combination of broad data harvesting and detailed reconnaissance of critical infrastructure suggests a severe risk to any organization whose systems or data might be exposed. Researchers first observed the actor's infrastructure in July 2026, mapping eight interconnected nodes hosted across European providers and Tencent Cloud. The visibility into the exposed working directory, containing over 3,000 subdirectories, allowed investigators to correlate workstation activity, provisioning records, and attack staging through shared artifacts, distinguishing confirmed data theft from mere reconnaissance.
This evolving threat landscape, where AI significantly lowers the barrier to entry and amplifies the capabilities of threat actors like CyberXero, necessitates a proactive and adaptive security posture. The use of advanced AI tools for reconnaissance, exploitation, and data exfiltration, coupled with the targeting of critical infrastructure and widespread e-commerce platforms, signals a new era of cyber warfare. Organizations must prioritize vulnerability management, secure the handling of AI-generated data, and continuously monitor for sophisticated, AI-augmented attack vectors to defend against these increasingly potent threats.