| Attribute | Detail |
|---|---|
| Alias | CyberXero (Dread, HackForums, Exploit.in) |
| Classification | Initial Access Broker, financially motivated |
| Operational language | Russian (primary); English for tooling and forums |
| Time zone | Moscow (UTC+3), peak activity around 22:00 MSK |
| First infrastructure observed | July 2026 |
| Target countries | Ukraine, Poland, China, Pakistan |
| Target sectors | Energy and utilities, e-commerce, telecom, government |
| AI tooling | Claude Code agent swarm; PentAGI wired to Cobalt Strike |
| Monetization | Multi-currency cryptocurrency payment gateway |
| Status | Active at the time of publication |
CyberXero: An AI-Augmented Initial Access Broker Targeting Ukrainian Critical Infrastructure
SOCRadar’s Threat Research Unit (STRU) has documented CyberXero, a Russian-speaking, financially motivated Initial Access Broker that pairs commodity offensive tooling with an AI orchestration layer running on its own infrastructure. The operation runs two pipelines at once: a global, automated campaign against WordPress and e-commerce platforms, and a curated, manual campaign against Ukrainian energy and critical infrastructure. More than 628,000 Ukrainian individuals have confirmed data in the actor’s possession, including residents of Kharkiv, a city on an active war front.
The entire operation surfaced from a single configuration error: an exposed open directory that served the actor’s live working directory, including AI session logs, scripts with plaintext tokens, and exfiltrated victim data. CyberXero remained active throughout the investigation and was still active at the time of publication.

Threat actor card of CyberXero
Download the full report (PDF) for the complete technical analysis, including the node-by-node infrastructure walkthrough, the Chinese-cluster Cobalt Strike operation, the PentAGI model configuration, and the full indicator set.
Key Takeaways
- Two parallel pipelines: an opportunistic, global pipeline mass-exploiting WordPress and e-commerce for access and payment data, and a directed pipeline running deep reconnaissance and manual exploitation against Ukrainian energy and utilities
- An AI orchestration layer: up to 51 specialized Claude Code agents on the primary workstation, plus a PentAGI deployment wired into a Cobalt Strike Team Server through an AI provider API, used for payload generation and pentest execution
- Documented AI safety evasion: the actor’s own session logs record model refusals and the context-engineering and session-reset techniques used to work around them, recovered directly from the actor’s infrastructure
- Industrial scale: a single automated execution scanned 4,708 targets, confirmed access to 429 WordPress administration panels, and deployed 32 shells in a 61-second window
- Critical infrastructure focus: seven Ukrainian energy and utilities entities under curated reconnaissance, including the national transmission system operator and the country’s largest private energy holding
- Attribution anchors: an exposed account file, forum self-incrimination, and a traceable paid subscription converge on the operator across five independent platforms
What Is CyberXero?
CyberXero is the underground-forum alias of a financially motivated Initial Access Broker (IAB), an attribution established during the analysis. An IAB compromises organizations and sells that access to other criminals rather than monetizing it directly. What sets CyberXero apart from a typical IAB is architectural: the actor wraps its toolset in an AI layer that lets a single operator run campaigns at a scale that would normally require a team.
How We Found It
The investigation began with an HTTP server at 46.21.250.135 (AS204601, Zomro NL) exposed as an open directory with no access control. It held the working directory of a Linux workstation, more than 90,000 files across 3,000 subdirectories: engagement folders named after target domains, exploitation toolkits, reconnaissance output, AI agent configurations, session logs, and victim database exports.

SOCRadar IoC enrichment for the seed node alongside the exposed open directory listing
Exposing a live working directory with session logs, personal scripts, and victim data is an OPSEC failure operators rarely make. That single error let the investigation pivot across the rest of the infrastructure.
From the seed node, a provisioning token embedded in installation URLs acted as a fingerprint for deployments from the same infrastructure. An internal hostname in an SSH key, correlated command histories, and staging logs documenting direct communication between nodes tied the operation together. In total, eight distinct nodes were mapped with high confidence across three ASNs and two regions: workstations, a provisioning server, and monetization infrastructure in Europe, with the Cobalt Strike C2, staging, and Redis exploitation nodes on Tencent Cloud.

CyberXero infrastructure map showing the eight correlated nodes and the artifacts linking them
The timeline splits into two phases. Before late July, the actor ran the reconnaissance and exploitation activity documented in the workstation bash histories. The second phase begins with the creation of the AI account and introduces the AI augmentation layer over the existing operation, with a measurable increase in the scale of the WordPress campaigns and SQL injection chains.

CyberXero infrastructure timeline across the two operational phases
Two Pipelines, One Operator
CyberXero’s operations split into two pipelines with different targeting logic, tooling, and purpose. The opportunistic pipeline is global and automated, chasing access volume across e-commerce and WordPress with direct monetization through access sales or payment-data theft. The directed pipeline is selective and geographically concentrated, aiming deep reconnaissance and manual exploitation at Ukrainian critical infrastructure, with no obvious direct-monetization explanation. Both run on the same workstation and share part of the same arsenal.

CyberXero’s opportunistic and directed pipelines, orchestrated through the AI layer
The Opportunistic Pipeline: Mass WordPress and E-Commerce
The centerpiece of the global pipeline is wp2shell, an internally developed Python package that abuses a desynchronization in the WordPress REST API batch endpoint to inject SQL, write a rogue administrator, and deploy a WSO-family webshell registered as an active plugin. The rogue account follows a fixed naming pattern, the username wp2_ followed by eight hexadecimal characters, which is the single most actionable indicator from this campaign. For the full mechanics of the underlying flaw, see our analysis of how the wp2shell WordPress vulnerability works.
Each successful compromise fires a real-time notification to a Telegram bot, which let the operator monitor compromises without an active terminal. The scale is the story here: the target set exceeds 56,000 identified URLs, and a single automated execution scanned 4,708 targets, confirmed 429 accessible administration panels, and deployed 32 shells, all inside a 61-second window. Exploitation of Magento and other e-commerce platforms ran in parallel, including a time-based SQL injection against Support Board (CVE-2026-4815) weaponized within 30 days of disclosure.

Telegram bot notifications confirming 429 accessible panels out of 4,708 scanned targets
The Directed Pipeline: Ukrainian Critical Infrastructure
The second pipeline is where CyberXero stops looking like a commodity IAB. The infrastructure documents curated reconnaissance against seven Ukrainian energy and utilities entities, including the national transmission system operator and the country’s largest private energy holding. One target list enumerates 95 subdomains of those two organizations alone, covering email infrastructure, VPN, network dispatch systems, and data platforms, a depth of reconnaissance that does not appear anywhere in the e-commerce operations.
Four Ukrainian organizations had file-confirmed exfiltration. The most severe was a district heating provider in Kharkiv: a hardcoded credential in the actor’s own script gave direct access, and a multithreaded extractor pulled 564,073 subscriber records with personal data, home addresses, and account numbers, plus 213,340 access-log entries with timestamps and IP addresses. Because Kharkiv sits on an active conflict front, this dataset poses a potential physical risk to identifiable civilians that goes well beyond a conventional data breach. The most elaborate chain, against an e-commerce portal, combined blind SQL injection, a time-constrained password-reset token extraction, and PHP deserialization to reach remote code execution and full database access.
The most plausible explanation for the directed pipeline is access brokering to a buyer with a specific interest in Ukrainian critical infrastructure. CyberXero operates on Dread, where access sales are documented practice, and access to electricity or gas operators carries a market value far above a WordPress panel. No direct evidence of a sale was recovered during the analysis.
The AI Augmentation Layer
The actor deployed AI in two independent layers. The first runs on the primary workstation and uses Claude Code with a swarm of 51 specialized agents defined in a dedicated directory, grouped into functional roles: offensive agents such as c2-operator, exploit-chainer, scada-attacker, and lateral-movement; reconnaissance agents for web hunting, subdomain mapping, and credential testing; and post-exploitation agents for data exfiltration. The second layer runs on the Team Server and integrates PentAGI, an open-source AI-augmented pentesting framework, with Cobalt Strike through an AI provider API.

Specialized Claude Code agent definitions in the agent directory on the primary workstation
A recovered provider configuration file assigns models to roles by reasoning complexity, with explicit cost-benefit logic: the payload-generation role receives the highest token budget and reasoning effort, while cheaper roles handle search and installation tasks. The deliberate sizing shows an operator treating AI spend as a real operational investment, likely offset by the sale of exfiltrated data.
How the Actor Worked Around Model Refusals
The most significant finding for defenders is what the session logs reveal about AI safety evasion. A cross-functional agent built a complete fictional authorization protocol, an “authorized pentest on my own infrastructure” narrative, designed to reduce the chance the model refuses. The same ownership claim appears verbatim across four unrelated victims and two different tools, which marks it as a rehearsed script rather than a genuine engagement. This is context engineering; it does not technically bypass the model, it reframes the request.

Russian-language prompts from the session logs repeating the “my own site” ownership claim
The second technique is architectural. Model safety controls act on the context of a session, not on the model weights, so a refusal in one session does not carry into the next. When an agent refused a task, the actor reopened a fresh session with the authorization framing preloaded and tried again. The logs also record genuine refusals that held: across four iterations the model declined to install a backdoor, disable a firewall, move laterally, and deploy a webshell, and in a separate episode it refused a scan four consecutive times and correctly rejected a forged ownership token.

Session log showing a refused vulnerability scan and the actor’s switch to Russian
The practical implication is that these session logs are the functional equivalent of a keylogger for offensive activity. They recorded every task the actor planned, every target evaluated, every refusal received, and every evasion attempted. Organizations deploying AI agents with access to terminals, networks, or sensitive data should treat agent session logs with the same retention, encryption, and access controls as credential logs or cryptographic keystores.
Attribution and Operator Profile
Attribution rests on three converging lines of evidence. The open directory contained an account file recording the operator’s AI account data; the session logs captured the actor trying to validate ownership of a Dread forum by pointing the model at a post written under the CyberXero alias; and external verification confirmed that post was published by CyberXero and describes, in the first person, the same progression of techniques seen across the infrastructure, from database dumping to an attempted move into digital card skimming.
A chain of OPSEC failures made the operator traceable. The exposed directory was the root failure. On top of it, the paid AI subscription tied to a personal email and billing provider created multiple independent paths to the operator’s identity, a cover persona used for competitor-suppression abuse reports was linked to a real email in the same source file, and the Dread verification episode confirmed the forum alias. Identity resolution drew on five independent platforms, and activity timing and language analysis place the operator in the Moscow time zone, working primarily in Russian. To reduce harm, the specific personal identifiers are kept in the full report rather than reproduced here.
Victimology
The victim set cannot be explained by a single threat model. The opportunistic pipeline produces a broad, pattern-less spread across e-commerce, ISPs, CRM, and content platforms, consistent with an IAB selling access independent of sector. The directed pipeline concentrates on energy and utilities in one country at war. Confirmed exfiltration covers four Ukrainian organizations, totaling more than 628,000 records tied to Ukrainian individuals, while seven more energy-sector entities were under curated reconnaissance without confirmed compromise.

Geographic distribution of confirmed CyberXero victims
Beyond Ukraine, Poland recorded the second-highest activity, with confirmed e-commerce compromises and WordPress exploitation attempts against state administration entities among 284 scanned domains. A separate Chinese cluster was compromised through Redis exploitation and worked over Cobalt Strike with China-specific tooling, and two Pakistani national-security entities were targeted with WAF bypass and credential spraying without a confirmed result. The result is more than 40 affected organizations worldwide.

Sector distribution of confirmed CyberXero victims
Detection and Hunting Guidance
Organizations running WordPress, Magento, or PrestaShop, exposing Redis to the internet, or with outbound traffic to the Team Server on the C2 ports have concrete reasons to run the checks below.
- Rogue WordPress administrators: accounts whose username matches wp2_ followed by eight hexadecimal characters were created by wp2shell, not by a legitimate user
- wp2shell plugin path: the plugin directory pattern /wp-content/plugins/wp2shell_[0-9a-f]{8}/ indicates a deployed webshell
- WSO webshell variant: the deployed shell is a WSO-family variant obfuscated with the R00t-Shell.com 2.0.15 obfuscator and was undetected on VirusTotal at analysis time; its header carries a characteristic obfuscator string suitable for a YARA signature
- Redis authorized-keys injection: unexpected entries in ~/.ssh/authorized_keys on internet-exposed Redis hosts, consistent with the rogue-replication (SLAVEOF) technique
- AI agent session logs: treat agent session logs as sensitive material; an exposed log is an operational intelligence breach, and the session-reset evasion is best managed through logging and auditing at the infrastructure layer rather than at the model
| SOCRadar detection rules: SOCRadar publishes YARA rules for the wp2shell artifacts and the obfuscated WSO variant. The full rule set, hashes, and additional indicators are in the report appendix and on the SOCRadar platform. |
|---|
Indicators of Compromise
Infrastructure
| Indicator | Role |
|---|---|
| 46.21.250.135 | Primary workstation, open directory seed node (AS204601, Zomro NL) |
| 45.88.106.2 | Provisioning server, port 1500 (AS204601, Zomro NL) |
| 212.193.31.189 | Multi-chain CryptoPay gateway (AS202799) |
| 42.193.227.214 | Cobalt Strike Team Server and PentAGI, port 9995 (AS45090, Tencent Cloud) |
| 91.208.184.148 | Secondary workstation (AS200019) |
| 45.88.106.78 | Mass scanning server (AS204601, Zomro NL) |
| 49.234.12.182 | Staging and payload delivery, Chinese cluster (AS45090, Tencent Cloud) |
| 42.193.100.94 | Redis exploitation node and PentAGI agents (AS45090, Tencent Cloud) |
| 42.193.227.214:1002 | Cobalt Strike beacon, HTTPS |
| 42.193.227.214:8044 | Cobalt Strike HTTP staging |
| 42.193.227.214:8033 | Cobalt Strike PowerShell IEX stager delivery |
Malware and Hacktool Hashes (SHA-256)
| Hash | File | Description |
|---|---|---|
| 92a789444708fa1cb4cc5a89e0aa6cc7a279b62a7b8a4d2857255a18197d0090 | stager32.bin | CS x86 stager, Pwn3rs Team build 4.9.1 |
| a5ae0aab352871bc0b038b3aa43b03eb223425628c884af7b9fc592cd34eb86c | WSO-Shell.php | WSO obfuscated with R00t-Shell.com 2.0.15, undetected at analysis time |
| 71e21094c1ac1cf0275c91ed377965e248bca1c12711f6dd20e2682681fc1192 | 1.bin | Chinese-cluster staging payload (N007) |
| 59c535f47ab4d35f6d9fc8b8aec4a72438ea0b89e5a4dcea74b05d2d32cfa483 | config.bin | Chinese-cluster staging payload (N007) |
Behavioral Indicators
| Value | Description |
|---|---|
| wp2_[0-9a-f]{8} | Rogue WordPress administrator username pattern created by wp2shell |
| /wp-content/plugins/wp2shell_[0-9a-f]{8}/ | wp2shell webshell plugin path pattern |
| UpdSvc | Persistence service created via svc.cna, binPath pointing to a C2 IEX download |
| http://42.193.227.214:8033/[a-z0-9]{13} | PowerShell stager download URL pattern |
Weaponized CVEs
| CVE | Product | CVSS | Use |
|---|---|---|---|
| CVE-2026-63030 | WordPress REST API batch endpoint | N/A | wp2shell primary exploitation chain |
| CVE-2026-60137 | WordPress batch handler | N/A | wp2shell secondary chain |
| CVE-2026-4815 | Support Board 3.8.7 | 8.8 | Time-based SQLi with anti-detection technique |
| CVE-2015-1397 | Magento CE | N/A | Magento cluster, approx. 93 domains tested |
| MS17-010 (EternalBlue) | Windows SMB | 9.8 | Patch verification on Chinese network; exploitation not confirmed |
MITRE ATT&CK TTPs
| Tactic | Technique | Procedure |
|---|---|---|
| TA0043 Reconnaissance | T1595.002 Active Scanning: Vulnerability Scanning | masscan, nuclei, and wpscan against global IP ranges and curated Ukrainian and Polish domain lists |
| TA0043 Reconnaissance | T1590.002 Gather Victim Network Information: DNS | Enumeration of 95 subdomains of Ukrainian energy targets |
| TA0042 Resource Development | T1588.002 Obtain Capabilities: Tool | Cobalt Strike 4.9.1 from an unauthorized Pwn3rs Team build |
| TA0042 Resource Development | T1588.005 Obtain Capabilities: Exploits | Weaponization of CVE-2026-63030, CVE-2026-4815, CVE-2015-1397 within 30 days of disclosure |
| TA0001 Initial Access | T1190 Exploit Public-Facing Application | wp2shell against WordPress REST API; blind SQLi, CVE-2026-4815, and WAF bypass against further targets |
| TA0001 Initial Access | T1078.003 Valid Accounts: Local Accounts | Direct authentication to a district heating service using a hardcoded administrator credential |
| TA0001 Initial Access | T1110.003 Brute Force: Password Spraying | Password spraying against named employee accounts; default-credential attempts against a ZTE router |
| TA0002 Execution | T1059.001 Command and Scripting Interpreter: PowerShell | IEX stager delivery from C2:8033; UpdSvc persistence |
| TA0002 Execution | T1047 Windows Management Instrumentation | WMI remote execution against Chinese-cluster hosts using a blank-password account |
| TA0002 Execution | T1072 Software Deployment Tools | PentAGI orchestrating Cobalt Strike operations on the Team Server via API |
| TA0003 Persistence | T1505.003 Server Software Component: Web Shell | WSO and wp2shell webshells; wp2shell registered as an active WordPress plugin |
| TA0003 Persistence | T1098.004 Account Manipulation: SSH Authorized Keys | SSH public key injected via rogue Redis replication server |
| TA0003 Persistence | T1136.001 Create Account: Local Account | Rogue administrators following the wp2_ pattern on compromised WordPress installs |
| TA0005 Defense Evasion | T1027 Obfuscate or Encode Files or Information | WSO obfuscated with R00t-Shell.com 2.0.15; XOR cipher on staging payloads |
| TA0006 Credential Access | T1056.003 Input Capture: Web Portal Capture | Card skimmer endpoint built and tested against a production payment flow |
| TA0006 Credential Access | T1539 Steal Web Session Cookie | Active session tokens extracted from a gas provider user table |
| TA0008 Lateral Movement | T1550.002 Use Alternate Authentication Material: Pass the Hash | PTH across multiple internal segments via scan_pth.cna |
| TA0009 Collection | T1213 Data from Information Repositories | Full dump of MySQL, MongoDB, and Redis at an e-commerce target |
| TA0011 Command and Control | T1102.002 Web Service: Bidirectional Communication | Telegram bot used as a real-time operational notification channel |
| TA0011 Command and Control | T1090.003 Proxy: Multi-Hop Proxy | VLESS/Xray node layer anonymizing attack traffic across campaigns |
| TA0040 Impact | T1565.001 Data Manipulation: Stored Data Manipulation | Administrator and superadministrator passwords overwritten at e-commerce targets |
Conclusion
CyberXero shows what a single financially motivated operator can now assemble: commodity tooling, internally developed exploitation frameworks, conventional C2, and an AI layer that compresses the work of a team into one workstation. The industrial scale is real, 429 panels compromised in a single day while the operation stayed active, and the numbers were still growing at the close of the analysis.
The part that does not fit a conventional IAB is the curated focus on Ukrainian energy and critical infrastructure, with civilian data from a city on an active front sitting in the actor’s possession. Whether that activity is access brokering to a specific buyer or something else, its objective remains unresolved. For defenders, the clearest takeaway beyond the indicators is that AI agent session logs are sensitive material, and the evasion patterns seen here are managed at the infrastructure layer, not the model.
Download the full CyberXero report (PDF) for the complete infrastructure analysis, the Chinese-cluster Cobalt Strike operation, the PentAGI model configuration, the profiling section, and the full indicator set.
Frequently Asked Questions
What is CyberXero?
CyberXero is the alias of a Russian-speaking, financially motivated Initial Access Broker that compromises organizations and sells access. It stands out for wrapping its toolset in an AI orchestration layer and for running a curated campaign against Ukrainian critical infrastructure alongside its opportunistic global operation.
How was CyberXero discovered?
Through an exposed open directory that served the actor’s live working directory, including more than 90,000 files: AI session logs, scripts with plaintext tokens, provisioning configurations, and exfiltrated victim data. That single OPSEC failure enabled the pivot across eight infrastructure nodes.
How does CyberXero use AI?
In two layers. A swarm of 51 specialized Claude Code agents runs on the primary workstation for reconnaissance, exploitation, and post-exploitation tasks, and a PentAGI framework is wired into a Cobalt Strike Team Server through an AI provider API for payload generation and pentest execution.
Did the AI models refuse the actor’s requests?
Yes. The session logs record multiple genuine refusals that held, including declining to install a backdoor, disable a firewall, move laterally, and deploy a webshell, and a repeated refusal to scan a forum along with rejection of a forged ownership token. The actor used context engineering and session resets to work around other requests, which reframe the prompt rather than bypassing the model.
What is the most actionable indicator of a wp2shell compromise?
A WordPress administrator account whose username matches wp2_ followed by eight hexadecimal characters. That pattern is created by the wp2shell tool, not by legitimate users, and signals that the host may have been compromised.
Who did CyberXero target?
A global opportunistic campaign hit WordPress and e-commerce platforms across many countries, while a directed campaign focused on Ukrainian energy and utilities. More than 628,000 Ukrainian individuals have confirmed data in the actor’s possession, with further confirmed or attempted activity in Poland, China, and Pakistan.
Why do AI agent session logs matter for defenders?
They function as a keylogger for offensive activity, recording every task, target, refusal, and evasion attempt. Organizations running AI agents with access to terminals, networks, or sensitive data should give agent session logs the same retention, encryption, and access controls as credential logs or cryptographic keystores.


