A financially motivated operator reportedly used open-source autonomous AI tools—Strix for vulnerability discovery, Cairn for exploitation, and Hermes for orchestration—to compromise online retailers and deploy payment-card skimmers. Gambit Security said the campaign compromised at least 27 companies during a September attack period, stole more than 600,000 payment-card records from two victims, and deployed skimmers at 19 identified victims plus more than 100 additional infected sites.
The reported intrusion chains included SQL injection, MFA bypass using exposed one-time passwords, web-shell deployment, sudo privilege escalation, NFS pivoting, AWS Secrets Manager access, and Magento database theft. The operator's records reportedly showed an average cost of $25.46 for each of 101 completed scans, despite spending an estimated $12,000–$18,000 on AI-model access; in two cases, it deleted payment-card data and database tables after exfiltration. Gambit Security notified affected organizations and worked with Shadowserver Foundation and Cloudflare to disrupt the infrastructure, but said the operator continued rebuilding it.

Track how attackers are adapting to this technology.
9 events from the most recent confirmed update back to the earliest known activity.
Cairn reportedly launched 105 attack projects and compromised at least 27 companies to varying degrees.
Strix conducted 146 deep-mode scans against 138 hosts, consuming 633 scanner-hours in 195 hours of elapsed time.
The operator reportedly spent between $12,000 and $18,000 on AI-model access through OpenRouter during the campaign period.
A financially motivated operator began an automated campaign against online retailers using the open-source AI tools Strix, Cairn, and Hermes.
Gambit Security notified affected organizations and worked with the Shadowserver Foundation and Cloudflare to dismantle attacker infrastructure. The operator reportedly rebuilt disrupted infrastructure repeatedly and continued the campaign.
A Hermes skill instructed the agent to erase payment-card fields from Magento databases after exfiltration. At a bicycle-retailer victim, the agent created staging tables and dropped 180 matching tables, including administrator-created backups.
Payment-card skimmers were confirmed at 19 named victims, with more than 100 additional infected sites identified with assistance from researcher Varys. Injection methods included altered jQuery files, poisoned S3/CDN content, Kubernetes initContainers, and recurring JBoss-directory cron jobs.
The operator reportedly exfiltrated more than 600,000 payment-card records from two victims. Overwatch Data validated the records and found that about 488,000, or 79%, belonged to U.S. cardholders.
One documented intrusion used unauthenticated SQL injection and an exposed plaintext one-time password to bypass MFA, then deployed a web shell, escalated through misconfigured sudo, and pivoted via NFS. The intrusion obtained 46 AWS Secrets Manager secrets, accessed a Magento database, and acquired a key used to decrypt stored card numbers.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.