CyberXero is a Russian-speaking, financially motivated initial access broker active on underground forums including Dread, HackForums, and Exploit.in. Its operations combine automated, opportunistic attacks against WordPress and e-commerce platforms worldwide with selective reconnaissance and exploitation of Ukrainian critical infrastructure. Its infrastructure was first observed in July 2026. Russian-language activity and Moscow-time-zone operating patterns do not establish a confirmed country of origin, and no state sponsorship has been established. CyberXero uses up to 51 specialized Claude Code agents and integrates the AI-assisted penetration-testing framework PentAGI with Cobalt Strike to support reconnaissance, exploitation, command-and-control operations, and data theft. Its techniques include SQL injection, rogue administrator creation, WSO-family webshell deployment, password spraying, Redis exploitation with unauthorized SSH-key insertion, PHP deserialization, session-token theft, database dumping, WMI execution, and pass-the-hash. Persistence includes webshells and an unauthorized service, while proxying and web application firewall bypass support evasion. The operator has repeatedly used fabricated authorization claims and fresh AI sessions to circumvent refusals, although some safeguards continued to block requests. The campaign affected more than 40 organizations worldwide, with activity in Ukraine, Poland, China, and Pakistan. Ukrainian targeting included seven energy and utility entities, and confirmed data theft affected four Ukrainian organizations, exposing information concerning more than 628,000 individuals. A Kharkiv district-heating provider accounted for 564,073 stolen subscriber records and 213,340 access-log entries. Polish activity included e-commerce compromises and exploitation attempts against government entities; activity in China included Redis compromise, while attempts against Pakistani national-security entities had no confirmed outcome. CyberXero is characterized as an access broker, but sales of compromised access have not been confirmed, and the ultimate objective of its directed Ukrainian campaign remains unresolved.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
21 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
5 malware families attributed to this actor across reporting.
4 CVEs this actor has used in observed campaigns. 4 of them exploited in the wild.
The actor also targeted Magento and used Support Board CVE-2026-4815 within 30 days of disclosure.
CVE-2015-1397 | Magento CE | N/A | Magento cluster, approx. 93 domains tested
CVE-2026-60137 | WordPress batch handler | N/A | wp2shell secondary chain
The weaponized-vulnerability table identifies CVE-2026-63030 in the WordPress REST API batch endpoint as the primary wp2shell exploitation chain.
13 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A financially motivated, Russian-speaking operator conducting automated intrusions against WordPress and e-commerce sites worldwide alongside targeted reconnaissance of Ukrainian energy and utility organizations. The campaign affected more than 40 organizations globally, with file-confirmed data theft at four Ukrainian organizations. Researchers characterize the actor as an initial access broker, but found no direct proof that compromised access was sold. Exposed operational files showed extensive AI-assisted attack automation and continued activity during the investigation.
An active, Russian-speaking initial access broker operating two parallel campaigns: automated global compromises of WordPress and e-commerce platforms, and selective reconnaissance and exploitation of Ukrainian critical infrastructure. The actor uses up to 51 specialized AI agents and a separate PentAGI–Cobalt Strike integration to support reconnaissance, exploitation, payload generation, and post-exploitation. Reported activity affected more than 40 organizations worldwide, with confirmed exfiltration from four Ukrainian organizations involving more than 628,000 individuals. Access sales and payment-data theft are monetization objectives, but the purpose of the directed Ukrainian campaign remains unresolved; brokering access to a specifically interested buyer is a hypothesis, not a confirmed transaction. The report attributes the activity to a single operator rather than a demonstrated multi-member organization.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.