Get Your Free Report
Start for Free
SOCRadar® Cyber Intelligence Inc. | CyberXero: An AI-Augmented Initial Access Broker Targeting Ukrainian Critical Infrastructure
Oct 06, 2026
18 Mins Read
Moon
Summarize with:

CyberXero: An AI-Augmented Initial Access Broker Targeting Ukrainian Critical Infrastructure

SOCRadar’s Threat Research Unit (STRU) has documented CyberXero, a Russian-speaking, financially motivated Initial Access Broker that pairs commodity offensive tooling with an AI orchestration layer running on its own infrastructure. The operation runs two pipelines at once: a global, automated campaign against WordPress and e-commerce platforms, and a curated, manual campaign against Ukrainian energy and critical infrastructure. More than 628,000 Ukrainian individuals have confirmed data in the actor’s possession, including residents of Kharkiv, a city on an active war front.

The entire operation surfaced from a single configuration error: an exposed open directory that served the actor’s live working directory, including AI session logs, scripts with plaintext tokens, and exfiltrated victim data. CyberXero remained active throughout the investigation and was still active at the time of publication.

Threat actor card of CyberXero

Threat actor card of CyberXero

Download the full report (PDF) for the complete technical analysis, including the node-by-node infrastructure walkthrough, the Chinese-cluster Cobalt Strike operation, the PentAGI model configuration, and the full indicator set.

Key Takeaways

  • Two parallel pipelines: an opportunistic, global pipeline mass-exploiting WordPress and e-commerce for access and payment data, and a directed pipeline running deep reconnaissance and manual exploitation against Ukrainian energy and utilities
  • An AI orchestration layer: up to 51 specialized Claude Code agents on the primary workstation, plus a PentAGI deployment wired into a Cobalt Strike Team Server through an AI provider API, used for payload generation and pentest execution
  • Documented AI safety evasion: the actor’s own session logs record model refusals and the context-engineering and session-reset techniques used to work around them, recovered directly from the actor’s infrastructure
  • Industrial scale: a single automated execution scanned 4,708 targets, confirmed access to 429 WordPress administration panels, and deployed 32 shells in a 61-second window
  • Critical infrastructure focus: seven Ukrainian energy and utilities entities under curated reconnaissance, including the national transmission system operator and the country’s largest private energy holding
  • Attribution anchors: an exposed account file, forum self-incrimination, and a traceable paid subscription converge on the operator across five independent platforms

What Is CyberXero?

CyberXero is the underground-forum alias of a financially motivated Initial Access Broker (IAB), an attribution established during the analysis. An IAB compromises organizations and sells that access to other criminals rather than monetizing it directly. What sets CyberXero apart from a typical IAB is architectural: the actor wraps its toolset in an AI layer that lets a single operator run campaigns at a scale that would normally require a team.

Attribute Detail
Alias CyberXero (Dread, HackForums, Exploit.in)
Classification Initial Access Broker, financially motivated
Operational language Russian (primary); English for tooling and forums
Time zone Moscow (UTC+3), peak activity around 22:00 MSK
First infrastructure observed July 2026
Target countries Ukraine, Poland, China, Pakistan
Target sectors Energy and utilities, e-commerce, telecom, government
AI tooling Claude Code agent swarm; PentAGI wired to Cobalt Strike
Monetization Multi-currency cryptocurrency payment gateway
Status Active at the time of publication

How We Found It

The investigation began with an HTTP server at 46.21.250.135 (AS204601, Zomro NL) exposed as an open directory with no access control. It held the working directory of a Linux workstation, more than 90,000 files across 3,000 subdirectories: engagement folders named after target domains, exploitation toolkits, reconnaissance output, AI agent configurations, session logs, and victim database exports.

SOCRadar IoC enrichment for the seed node alongside the exposed open directory listing

SOCRadar IoC enrichment for the seed node alongside the exposed open directory listing

Exposing a live working directory with session logs, personal scripts, and victim data is an OPSEC failure operators rarely make. That single error let the investigation pivot across the rest of the infrastructure.

From the seed node, a provisioning token embedded in installation URLs acted as a fingerprint for deployments from the same infrastructure. An internal hostname in an SSH key, correlated command histories, and staging logs documenting direct communication between nodes tied the operation together. In total, eight distinct nodes were mapped with high confidence across three ASNs and two regions: workstations, a provisioning server, and monetization infrastructure in Europe, with the Cobalt Strike C2, staging, and Redis exploitation nodes on Tencent Cloud.

CyberXero infrastructure map showing the eight correlated nodes and the artifacts linking them

CyberXero infrastructure map showing the eight correlated nodes and the artifacts linking them

The timeline splits into two phases. Before late July, the actor ran the reconnaissance and exploitation activity documented in the workstation bash histories. The second phase begins with the creation of the AI account and introduces the AI augmentation layer over the existing operation, with a measurable increase in the scale of the WordPress campaigns and SQL injection chains.

CyberXero infrastructure timeline across the two operational phases

CyberXero infrastructure timeline across the two operational phases

Two Pipelines, One Operator

CyberXero’s operations split into two pipelines with different targeting logic, tooling, and purpose. The opportunistic pipeline is global and automated, chasing access volume across e-commerce and WordPress with direct monetization through access sales or payment-data theft. The directed pipeline is selective and geographically concentrated, aiming deep reconnaissance and manual exploitation at Ukrainian critical infrastructure, with no obvious direct-monetization explanation. Both run on the same workstation and share part of the same arsenal.

CyberXero's opportunistic and directed pipelines, orchestrated through the AI layer

CyberXero’s opportunistic and directed pipelines, orchestrated through the AI layer

The Opportunistic Pipeline: Mass WordPress and E-Commerce

The centerpiece of the global pipeline is wp2shell, an internally developed Python package that abuses a desynchronization in the WordPress REST API batch endpoint to inject SQL, write a rogue administrator, and deploy a WSO-family webshell registered as an active plugin. The rogue account follows a fixed naming pattern, the username wp2_ followed by eight hexadecimal characters, which is the single most actionable indicator from this campaign. For the full mechanics of the underlying flaw, see our analysis of how the wp2shell WordPress vulnerability works.

Each successful compromise fires a real-time notification to a Telegram bot, which let the operator monitor compromises without an active terminal. The scale is the story here: the target set exceeds 56,000 identified URLs, and a single automated execution scanned 4,708 targets, confirmed 429 accessible administration panels, and deployed 32 shells, all inside a 61-second window. Exploitation of Magento and other e-commerce platforms ran in parallel, including a time-based SQL injection against Support Board (CVE-2026-4815) weaponized within 30 days of disclosure.

Telegram bot notifications confirming 429 accessible panels out of 4,708 scanned targets

Telegram bot notifications confirming 429 accessible panels out of 4,708 scanned targets

The Directed Pipeline: Ukrainian Critical Infrastructure

The second pipeline is where CyberXero stops looking like a commodity IAB. The infrastructure documents curated reconnaissance against seven Ukrainian energy and utilities entities, including the national transmission system operator and the country’s largest private energy holding. One target list enumerates 95 subdomains of those two organizations alone, covering email infrastructure, VPN, network dispatch systems, and data platforms, a depth of reconnaissance that does not appear anywhere in the e-commerce operations.

Four Ukrainian organizations had file-confirmed exfiltration. The most severe was a district heating provider in Kharkiv: a hardcoded credential in the actor’s own script gave direct access, and a multithreaded extractor pulled 564,073 subscriber records with personal data, home addresses, and account numbers, plus 213,340 access-log entries with timestamps and IP addresses. Because Kharkiv sits on an active conflict front, this dataset poses a potential physical risk to identifiable civilians that goes well beyond a conventional data breach. The most elaborate chain, against an e-commerce portal, combined blind SQL injection, a time-constrained password-reset token extraction, and PHP deserialization to reach remote code execution and full database access.

The most plausible explanation for the directed pipeline is access brokering to a buyer with a specific interest in Ukrainian critical infrastructure. CyberXero operates on Dread, where access sales are documented practice, and access to electricity or gas operators carries a market value far above a WordPress panel. No direct evidence of a sale was recovered during the analysis.

The AI Augmentation Layer

The actor deployed AI in two independent layers. The first runs on the primary workstation and uses Claude Code with a swarm of 51 specialized agents defined in a dedicated directory, grouped into functional roles: offensive agents such as c2-operator, exploit-chainer, scada-attacker, and lateral-movement; reconnaissance agents for web hunting, subdomain mapping, and credential testing; and post-exploitation agents for data exfiltration. The second layer runs on the Team Server and integrates PentAGI, an open-source AI-augmented pentesting framework, with Cobalt Strike through an AI provider API.

Specialized Claude Code agent definitions in the agent directory on the primary workstation

Specialized Claude Code agent definitions in the agent directory on the primary workstation

A recovered provider configuration file assigns models to roles by reasoning complexity, with explicit cost-benefit logic: the payload-generation role receives the highest token budget and reasoning effort, while cheaper roles handle search and installation tasks. The deliberate sizing shows an operator treating AI spend as a real operational investment, likely offset by the sale of exfiltrated data.

How the Actor Worked Around Model Refusals

The most significant finding for defenders is what the session logs reveal about AI safety evasion. A cross-functional agent built a complete fictional authorization protocol, an “authorized pentest on my own infrastructure” narrative, designed to reduce the chance the model refuses. The same ownership claim appears verbatim across four unrelated victims and two different tools, which marks it as a rehearsed script rather than a genuine engagement. This is context engineering; it does not technically bypass the model, it reframes the request.

Russian-language prompts from the session logs repeating the "my own site" ownership claim

Russian-language prompts from the session logs repeating the “my own site” ownership claim

The second technique is architectural. Model safety controls act on the context of a session, not on the model weights, so a refusal in one session does not carry into the next. When an agent refused a task, the actor reopened a fresh session with the authorization framing preloaded and tried again. The logs also record genuine refusals that held: across four iterations the model declined to install a backdoor, disable a firewall, move laterally, and deploy a webshell, and in a separate episode it refused a scan four consecutive times and correctly rejected a forged ownership token.

Session log showing a refused vulnerability scan and the actor's switch to Russian

Session log showing a refused vulnerability scan and the actor’s switch to Russian

The practical implication is that these session logs are the functional equivalent of a keylogger for offensive activity. They recorded every task the actor planned, every target evaluated, every refusal received, and every evasion attempted. Organizations deploying AI agents with access to terminals, networks, or sensitive data should treat agent session logs with the same retention, encryption, and access controls as credential logs or cryptographic keystores.

Attribution and Operator Profile

Attribution rests on three converging lines of evidence. The open directory contained an account file recording the operator’s AI account data; the session logs captured the actor trying to validate ownership of a Dread forum by pointing the model at a post written under the CyberXero alias; and external verification confirmed that post was published by CyberXero and describes, in the first person, the same progression of techniques seen across the infrastructure, from database dumping to an attempted move into digital card skimming.

A chain of OPSEC failures made the operator traceable. The exposed directory was the root failure. On top of it, the paid AI subscription tied to a personal email and billing provider created multiple independent paths to the operator’s identity, a cover persona used for competitor-suppression abuse reports was linked to a real email in the same source file, and the Dread verification episode confirmed the forum alias. Identity resolution drew on five independent platforms, and activity timing and language analysis place the operator in the Moscow time zone, working primarily in Russian. To reduce harm, the specific personal identifiers are kept in the full report rather than reproduced here.

Victimology

The victim set cannot be explained by a single threat model. The opportunistic pipeline produces a broad, pattern-less spread across e-commerce, ISPs, CRM, and content platforms, consistent with an IAB selling access independent of sector. The directed pipeline concentrates on energy and utilities in one country at war. Confirmed exfiltration covers four Ukrainian organizations, totaling more than 628,000 records tied to Ukrainian individuals, while seven more energy-sector entities were under curated reconnaissance without confirmed compromise.

Geographic distribution of confirmed CyberXero victims

Geographic distribution of confirmed CyberXero victims

Beyond Ukraine, Poland recorded the second-highest activity, with confirmed e-commerce compromises and WordPress exploitation attempts against state administration entities among 284 scanned domains. A separate Chinese cluster was compromised through Redis exploitation and worked over Cobalt Strike with China-specific tooling, and two Pakistani national-security entities were targeted with WAF bypass and credential spraying without a confirmed result. The result is more than 40 affected organizations worldwide.

Sector distribution of confirmed CyberXero victims

Sector distribution of confirmed CyberXero victims

Detection and Hunting Guidance

Organizations running WordPress, Magento, or PrestaShop, exposing Redis to the internet, or with outbound traffic to the Team Server on the C2 ports have concrete reasons to run the checks below.

  • Rogue WordPress administrators: accounts whose username matches wp2_ followed by eight hexadecimal characters were created by wp2shell, not by a legitimate user
  • wp2shell plugin path: the plugin directory pattern /wp-content/plugins/wp2shell_[0-9a-f]{8}/ indicates a deployed webshell
  • WSO webshell variant: the deployed shell is a WSO-family variant obfuscated with the R00t-Shell.com 2.0.15 obfuscator and was undetected on VirusTotal at analysis time; its header carries a characteristic obfuscator string suitable for a YARA signature
  • Redis authorized-keys injection: unexpected entries in ~/.ssh/authorized_keys on internet-exposed Redis hosts, consistent with the rogue-replication (SLAVEOF) technique
  • AI agent session logs: treat agent session logs as sensitive material; an exposed log is an operational intelligence breach, and the session-reset evasion is best managed through logging and auditing at the infrastructure layer rather than at the model
SOCRadar detection rules: SOCRadar publishes YARA rules for the wp2shell artifacts and the obfuscated WSO variant. The full rule set, hashes, and additional indicators are in the report appendix and on the SOCRadar platform.

Indicators of Compromise

Infrastructure

Indicator Role
46.21.250.135 Primary workstation, open directory seed node (AS204601, Zomro NL)
45.88.106.2 Provisioning server, port 1500 (AS204601, Zomro NL)
212.193.31.189 Multi-chain CryptoPay gateway (AS202799)
42.193.227.214 Cobalt Strike Team Server and PentAGI, port 9995 (AS45090, Tencent Cloud)
91.208.184.148 Secondary workstation (AS200019)
45.88.106.78 Mass scanning server (AS204601, Zomro NL)
49.234.12.182 Staging and payload delivery, Chinese cluster (AS45090, Tencent Cloud)
42.193.100.94 Redis exploitation node and PentAGI agents (AS45090, Tencent Cloud)
42.193.227.214:1002 Cobalt Strike beacon, HTTPS
42.193.227.214:8044 Cobalt Strike HTTP staging
42.193.227.214:8033 Cobalt Strike PowerShell IEX stager delivery

Malware and Hacktool Hashes (SHA-256)

Hash File Description
92a789444708fa1cb4cc5a89e0aa6cc7a279b62a7b8a4d2857255a18197d0090 stager32.bin CS x86 stager, Pwn3rs Team build 4.9.1
a5ae0aab352871bc0b038b3aa43b03eb223425628c884af7b9fc592cd34eb86c WSO-Shell.php WSO obfuscated with R00t-Shell.com 2.0.15, undetected at analysis time
71e21094c1ac1cf0275c91ed377965e248bca1c12711f6dd20e2682681fc1192 1.bin Chinese-cluster staging payload (N007)
59c535f47ab4d35f6d9fc8b8aec4a72438ea0b89e5a4dcea74b05d2d32cfa483 config.bin Chinese-cluster staging payload (N007)

Behavioral Indicators

Value Description
wp2_[0-9a-f]{8} Rogue WordPress administrator username pattern created by wp2shell
/wp-content/plugins/wp2shell_[0-9a-f]{8}/ wp2shell webshell plugin path pattern
UpdSvc Persistence service created via svc.cna, binPath pointing to a C2 IEX download
http://42.193.227.214:8033/[a-z0-9]{13} PowerShell stager download URL pattern

Weaponized CVEs

CVE Product CVSS Use
CVE-2026-63030 WordPress REST API batch endpoint N/A wp2shell primary exploitation chain
CVE-2026-60137 WordPress batch handler N/A wp2shell secondary chain
CVE-2026-4815 Support Board 3.8.7 8.8 Time-based SQLi with anti-detection technique
CVE-2015-1397 Magento CE N/A Magento cluster, approx. 93 domains tested
MS17-010 (EternalBlue) Windows SMB 9.8 Patch verification on Chinese network; exploitation not confirmed

MITRE ATT&CK TTPs

Tactic Technique Procedure
TA0043 Reconnaissance T1595.002 Active Scanning: Vulnerability Scanning masscan, nuclei, and wpscan against global IP ranges and curated Ukrainian and Polish domain lists
TA0043 Reconnaissance T1590.002 Gather Victim Network Information: DNS Enumeration of 95 subdomains of Ukrainian energy targets
TA0042 Resource Development T1588.002 Obtain Capabilities: Tool Cobalt Strike 4.9.1 from an unauthorized Pwn3rs Team build
TA0042 Resource Development T1588.005 Obtain Capabilities: Exploits Weaponization of CVE-2026-63030, CVE-2026-4815, CVE-2015-1397 within 30 days of disclosure
TA0001 Initial Access T1190 Exploit Public-Facing Application wp2shell against WordPress REST API; blind SQLi, CVE-2026-4815, and WAF bypass against further targets
TA0001 Initial Access T1078.003 Valid Accounts: Local Accounts Direct authentication to a district heating service using a hardcoded administrator credential
TA0001 Initial Access T1110.003 Brute Force: Password Spraying Password spraying against named employee accounts; default-credential attempts against a ZTE router
TA0002 Execution T1059.001 Command and Scripting Interpreter: PowerShell IEX stager delivery from C2:8033; UpdSvc persistence
TA0002 Execution T1047 Windows Management Instrumentation WMI remote execution against Chinese-cluster hosts using a blank-password account
TA0002 Execution T1072 Software Deployment Tools PentAGI orchestrating Cobalt Strike operations on the Team Server via API
TA0003 Persistence T1505.003 Server Software Component: Web Shell WSO and wp2shell webshells; wp2shell registered as an active WordPress plugin
TA0003 Persistence T1098.004 Account Manipulation: SSH Authorized Keys SSH public key injected via rogue Redis replication server
TA0003 Persistence T1136.001 Create Account: Local Account Rogue administrators following the wp2_ pattern on compromised WordPress installs
TA0005 Defense Evasion T1027 Obfuscate or Encode Files or Information WSO obfuscated with R00t-Shell.com 2.0.15; XOR cipher on staging payloads
TA0006 Credential Access T1056.003 Input Capture: Web Portal Capture Card skimmer endpoint built and tested against a production payment flow
TA0006 Credential Access T1539 Steal Web Session Cookie Active session tokens extracted from a gas provider user table
TA0008 Lateral Movement T1550.002 Use Alternate Authentication Material: Pass the Hash PTH across multiple internal segments via scan_pth.cna
TA0009 Collection T1213 Data from Information Repositories Full dump of MySQL, MongoDB, and Redis at an e-commerce target
TA0011 Command and Control T1102.002 Web Service: Bidirectional Communication Telegram bot used as a real-time operational notification channel
TA0011 Command and Control T1090.003 Proxy: Multi-Hop Proxy VLESS/Xray node layer anonymizing attack traffic across campaigns
TA0040 Impact T1565.001 Data Manipulation: Stored Data Manipulation Administrator and superadministrator passwords overwritten at e-commerce targets

Conclusion

CyberXero shows what a single financially motivated operator can now assemble: commodity tooling, internally developed exploitation frameworks, conventional C2, and an AI layer that compresses the work of a team into one workstation. The industrial scale is real, 429 panels compromised in a single day while the operation stayed active, and the numbers were still growing at the close of the analysis.

The part that does not fit a conventional IAB is the curated focus on Ukrainian energy and critical infrastructure, with civilian data from a city on an active front sitting in the actor’s possession. Whether that activity is access brokering to a specific buyer or something else, its objective remains unresolved. For defenders, the clearest takeaway beyond the indicators is that AI agent session logs are sensitive material, and the evasion patterns seen here are managed at the infrastructure layer, not the model.

Download the full CyberXero report (PDF) for the complete infrastructure analysis, the Chinese-cluster Cobalt Strike operation, the PentAGI model configuration, the profiling section, and the full indicator set.

Frequently Asked Questions

What is CyberXero?

CyberXero is the alias of a Russian-speaking, financially motivated Initial Access Broker that compromises organizations and sells access. It stands out for wrapping its toolset in an AI orchestration layer and for running a curated campaign against Ukrainian critical infrastructure alongside its opportunistic global operation.

How was CyberXero discovered?

Through an exposed open directory that served the actor’s live working directory, including more than 90,000 files: AI session logs, scripts with plaintext tokens, provisioning configurations, and exfiltrated victim data. That single OPSEC failure enabled the pivot across eight infrastructure nodes.

How does CyberXero use AI?

In two layers. A swarm of 51 specialized Claude Code agents runs on the primary workstation for reconnaissance, exploitation, and post-exploitation tasks, and a PentAGI framework is wired into a Cobalt Strike Team Server through an AI provider API for payload generation and pentest execution.

Did the AI models refuse the actor’s requests?

Yes. The session logs record multiple genuine refusals that held, including declining to install a backdoor, disable a firewall, move laterally, and deploy a webshell, and a repeated refusal to scan a forum along with rejection of a forged ownership token. The actor used context engineering and session resets to work around other requests, which reframe the prompt rather than bypassing the model.

What is the most actionable indicator of a wp2shell compromise?

A WordPress administrator account whose username matches wp2_ followed by eight hexadecimal characters. That pattern is created by the wp2shell tool, not by legitimate users, and signals that the host may have been compromised.

Who did CyberXero target?

A global opportunistic campaign hit WordPress and e-commerce platforms across many countries, while a directed campaign focused on Ukrainian energy and utilities. More than 628,000 Ukrainian individuals have confirmed data in the actor’s possession, with further confirmed or attempted activity in Poland, China, and Pakistan.

Why do AI agent session logs matter for defenders?

They function as a keylogger for offensive activity, recording every task, target, refusal, and evasion attempt. Organizations running AI agents with access to terminals, networks, or sensitive data should give agent session logs the same retention, encryption, and access controls as credential logs or cryptographic keystores.