CyberXero Combines Claude Code, PentAGI and Cobalt Strike in AI-Augmented Cyberattacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com


CyberXero has emerged as an initial access broker that combines familiar hacking tools with artificial intelligence to run large-scale intrusions.

The Russian-speaking operator targeted WordPress and e-commerce sites worldwide while separately probing Ukrainian energy and utility organizations.

The campaign came to light after an open directory exposed more than 90,000 files, including scripts, AI session records and stolen data.

The evidence indicates that the operation remained active during the investigation, raising concern that compromised access could be sold or reused. Analysts at SOCRadar identified the activity and linked it to a financially motivated actor using the CyberXero alias.

SOCRadar said in a report shared with Cyber Security News (CSN) that the actor ran both automated and carefully chosen campaigns.

The scale is striking. One automated run scanned 4,708 targets, found 429 accessible WordPress administration panels and placed 32 shells in 61 seconds. More than 628,000 Ukrainian people had confirmed data in the actor’s possession, including residents of Kharkiv.

CyberXero Combines Claude Code, PentAGI and Cobalt Strike

CyberXero used two AI layers rather than treating AI as a simple writing assistant. On a primary workstation, the actor configured up to 51 Claude Code agents for web discovery, password testing, exploitation and data theft, a pattern that mirrors other Claude AI attack automation cases involving commercial AI tools.

A second setup connected PentAGI, an AI-assisted penetration-testing framework, to a Cobalt Strike Team Server through an AI provider API.

Recovered settings reportedly assigned models and token budgets according to task complexity, reserving greater effort for payload generation while cheaper roles handled searches and installations.

CyberXero’s opportunistic and directed pipelines (Source - SOCRadar)
CyberXero’s opportunistic and directed pipelines (Source – SOCRadar)

Separate Claude Code ransomware intrusions have likewise shown AI handling multiple attack stages. Session logs showed the operator trying to overcome refusals by claiming that targets were owned systems undergoing authorized testing.

When a request was rejected, the actor opened a fresh session with the same preloaded story, showing how session resets can weaken the practical value of single-session safeguards.

The logs also recorded refusals that held, including requests to install a backdoor, disable a firewall, move across a network and deploy a webshell.

This makes secure handling of agent logs essential: organizations should encrypt them, limit access, retain audit trails and treat them like credentials or cryptographic keys.

Websites and Ukrainian Infrastructure

CyberXero’s broad campaign focused on WordPress and e-commerce targets. Its internal wp2shell package abused the WordPress REST API batch endpoint to inject SQL, create a rogue administrator and install a WSO-family webshell, making prompt patching critical for sites affected by the wp2shell remote execution vulnerability chain on vulnerable installations.

The actor also targeted Magento and used Support Board CVE-2026-4815 within 30 days of disclosure. Administrators should verify WordPress updates, inspect for unfamiliar plugins and unexpected administrator accounts, restrict internet-facing Redis, and review authorized SSH keys for unauthorized changes.

The more selective pipeline mapped seven Ukrainian energy and utility entities, including the national transmission system operator and the country’s largest private energy holding.

Specialized Claude Code agent definitions in the agent directory on the primary workstation (Source - SOCRadar)
Specialized Claude Code agent definitions in the agent directory on the primary workstation (Source – SOCRadar)

It enumerated 95 subdomains across two organizations and identified services ranging from email and VPN systems to network dispatch platforms. Four Ukrainian organizations had file-confirmed data theft.

A Kharkiv district heating provider lost 564,073 subscriber records and 213,340 access-log entries after the actor used a hardcoded credential in its own script, a reminder that Ukrainian infrastructure attack risks can extend beyond service disruption.

The campaign affected more than 40 organizations globally, with activity also observed in Poland, China and Pakistan. While the researchers found no direct proof of an access sale, the mix of broad harvesting and detailed energy-sector reconnaissance suggests a serious risk to organizations whose systems or data are exposed.

Investigators first observed the infrastructure in July 2026 and mapped eight connected nodes across European hosting and Tencent Cloud.

The exposed working directory contained more than 3,000 subdirectories, allowing researchers to connect workstation activity, provisioning records and attack staging through shared artifacts.

This visibility helped distinguish confirmed data theft from reconnaissance that had not produced a verified compromise at the time of the investigation.

Indicators of compromise (IoCs):-

Type Indicator Description
IP address 46.21.250.135 Primary workstation and open-directory seed node
IP address 45.88.106.2 Provisioning server, port 1500
IP address 212.193.31.189 Multi-chain CryptoPay gateway
IP address 42.193.227.214 Cobalt Strike Team Server and PentAGI, port 9995
IP address 91.208.184.148 Secondary workstation
IP address 45.88.106.78 Mass-scanning server
IP address 49.234.12.182 Staging and payload delivery node in the Chinese cluster
IP address 42.193.100.94 Redis exploitation node and PentAGI agents
Network endpoint 42.193.227.214:1002 Cobalt Strike beacon over HTTPS
Network endpoint 42.193.227.214:8044 Cobalt Strike HTTP staging
Network endpoint 42.193.227.214:8033 Cobalt Strike PowerShell IEX stager delivery
SHA-256 92a789444708fa1cb4cc5a89e0aa6cc7a279b62a7b8a4d2857255a18197d0090 stager3
SHA-256 a5ae0aab352871bc0b038b3aa43b03eb223425628c884af7b9fc592cd34eb86c WSO-S
SHA-256 71e21094c1ac1cf0275c91ed377965e248bca1c12711f6dd20e2682681fc1192 1.bin
SHA-256 59c535f47ab4d35f6d9fc8b8aec4a72438ea0b89e5a4dcea74b05d2d32cfa483 config.b
Username pattern wp2_[0-9a-f]{8} Rogue WordPress administrator account pattern
File path pattern /wp-content/plugins/wp2shell_[0-9a-f]{8}/ wp2shell webshell plugin path
Service name UpdSvc Persistence service created through svc.cna
URL pattern http://42.193.227.214:8033/[a-z0-9]{13} PowerShell stager download URL pattern

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Stops threats before impact with 21 min faster MTTR. Integrate ANYRUN’s Sandbox in your SOC

The post CyberXero Combines Claude Code, PentAGI and Cobalt Strike in AI-Augmented Cyberattacks appeared first on Cyber Security News.