SOCRadar reported that CyberXero, a Russian-speaking, financially motivated initial access broker, is running parallel campaigns against global WordPress and e-commerce sites and Ukrainian critical infrastructure. An exposed working directory contained victim data, exploitation tools, and AI session logs, linking eight infrastructure nodes to the operator. The investigation confirmed data exfiltration from four Ukrainian organizations involving more than 628,000 records associated with Ukrainian individuals, alongside curated reconnaissance against seven energy and utilities entities. CyberXero uses up to 51 specialized Claude Code agents and a PentAGI–Cobalt Strike integration to augment reconnaissance, exploitation, and post-exploitation. Logs showed both successful attempts to bypass AI refusals using fabricated authorization narratives and session resets, and refusals that held.
The operation illustrates adversary practices documented by MITRE ATT&CK: vulnerability scanning (T1595.002), obtaining publicly available or legitimate tools (T1588.002), and acquiring exploits rather than developing them internally (T1588.005). MITRE documents these practices across espionage and criminal groups, including scanning for vulnerabilities in internet-facing applications and using tools such as Cobalt Strike, Impacket, and Mimikatz; those broader examples are not all attributed to CyberXero. Defenders should prioritize internet-facing application patching, investigate suspicious scanning and Cobalt Strike activity, and assess potential data exposure. CyberXero remained active when SOCRadar published its report, but the purpose of its directed Ukrainian campaign and any sale of the resulting access remained unconfirmed.

Track how attackers are adapting to this technology.
14 events from the most recent confirmed update back to the earliest known activity.
CyberXero created AI accounts in late July, beginning a second operational phase in which its WordPress campaigns and SQL-injection chains increased in scale.
CyberXero's infrastructure was first observed in July 2026. The investigation distinguished an initial reconnaissance and exploitation phase from a later AI-augmented phase.
Investigators correlated eight infrastructure nodes using a shared provisioning token, an SSH-key hostname, command histories, and staging logs. Exposed account and billing information, a cover persona, and a verified Dread post linked CyberXero's identity across five platforms.
An unauthenticated HTTP directory at 46.21.250.135 exposed more than 90,000 files across approximately 3,000 subdirectories. Its contents included AI session logs, plaintext tokens, exploitation scripts, reconnaissance results, and exfiltrated databases.
Recovered logs showed CyberXero presenting fabricated authorization claims across four unrelated victims and two tools, and reopening sessions after model refusals. Some attempts succeeded, while other sessions sustained refusals to deploy backdoors or webshells, disable a firewall, move laterally, or perform a scan.
CyberXero attempted WAF bypass and credential spraying against two Pakistani national-security entities. The investigation did not confirm the outcome of these attempts.
CyberXero compromised a Chinese cluster through Redis exploitation and operated Cobalt Strike with China-specific tooling.
CyberXero's Polish activity included confirmed e-commerce compromises and WordPress exploitation attempts against state-administration entities. The activity involved 284 scanned domains.
CyberXero attacked an e-commerce portal using blind SQL injection to extract a time-limited password-reset token, followed by PHP deserialization. The chain achieved remote code execution and full database access.
Recovered files confirmed exfiltration of more than 628,000 records associated with Ukrainian individuals from four organizations. At a Kharkiv district-heating provider, CyberXero used a hardcoded credential to extract 564,073 subscriber records and 213,340 access-log entries.
CyberXero conducted curated reconnaissance against seven Ukrainian energy and utilities entities, including the national transmission system operator and the largest private energy holding. One recovered list enumerated 95 subdomains spanning email, VPN, dispatch, and data systems.
CyberXero exploited the time-based SQL-injection vulnerability CVE-2026-4815 in Support Board 3.8.7 within 30 days of its disclosure. Separate activity tested approximately 93 Magento domains in connection with CVE-2015-1397.
One automated execution scanned 4,708 targets, confirmed access to 429 WordPress administration panels, and deployed 32 shells within 61 seconds. CyberXero's wp2shell package used WordPress REST API batch-processing desynchronization to inject SQL, create rogue administrators, and deploy a WSO-family webshell.
CyberXero deployed up to 51 specialized Claude Code agents for activities including reconnaissance, exploitation, lateral movement, and exfiltration. It also operated a separate PentAGI integration with Cobalt Strike through an AI-provider API.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 13 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
6 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcesocradar.io
Open sourceattack.mitre.org
Open sourceattack.mitre.org
Open sourceattack.mitre.org
Open sourceattack.mitre.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.