Cyber Security News

Russian-Speaking CyberXero Uses AI Agent Swarm to Attack Ukrainian Energy Infrastructure

CyberXero, a Russian-speaking initial access broker combining conventional exploitation tools with AI agents to pursue global website compromises and targeted intrusions against Ukrainian energy infrastructure.

The findings describe an active, financially motivated operation rather than a confirmed state-sponsored campaign.

Its selective interest in Ukrainian utilities raises questions about potential access buyers, but researchers found no direct evidence of an access sale.

The investigation began with an unprotected HTTP directory at 46.21.250.135 containing the operator’s live Linux working environment.

More than 90,000 files across 3,000 subdirectories exposed reconnaissance results, exploitation scripts, plaintext tokens, AI configurations, session histories, and victim database exports.

Researchers correlated provisioning tokens, SSH artifacts, command histories, and staging logs to map eight infrastructure nodes across three autonomous systems and two regions.

European nodes supported workstation, provisioning, and monetization functions, while Tencent Cloud hosted Cobalt Strike, staging, and Redis exploitation infrastructure.

The recovered timeline indicates that conventional exploitation preceded the introduction of AI augmentation in late July 2026.

CyberXero remained active throughout the investigation and at publication, according to SOCRadar.

CyberXero’s global pipeline centered on wp2shell, an internally developed Python package targeting WordPress.

SOCRadar describes REST API batch desynchronization leading to SQL injection, rogue administrator creation, and deployment of a WSO-family webshell as an active plugin.

The administrator naming pattern, wp2_ followed by eight hexadecimal characters, provides a distinctive investigation lead. Telegram notifications supplied real-time compromise updates.

One execution reportedly scanned 4,708 targets, confirmed 429 accessible administration panels, and deployed 32 shells within 61 seconds; the broader target collection exceeded 56,000 URLs.

Threat actor card of CyberXero (Source : SOCRadar).

SOCRadar Investigators observed that, evidence of stolen data on more than 628,000 Ukrainian individuals, although reconnaissance against additional energy organizations did not result in a confirmed compromise.

CyberXero Uses AI Agent Swarm

Parallel activity targeted Magento and other commerce platforms, including reported exploitation of Support Board vulnerability CVE-2026-4815.

The Ukrainian pipeline involved curated reconnaissance against seven energy and utilities entities, including the national transmission operator and largest private energy holding.

A target list contained 95 subdomains spanning email, VPN, dispatch, and data systems.

File-confirmed exfiltration affected four Ukrainian organizations. At a Kharkiv district heating provider, a hardcoded credential enabled extraction of 564,073 subscriber records and 213,340 access-log entries.

Exposed addresses and account information create potential risks beyond financial fraud for civilians near an active conflict front.

The primary workstation contained definitions for 51 specialized Claude Code agents covering reconnaissance, exploitation, lateral movement, and exfiltration.

Specialized Claude Code agent definitions in the agent directory on the primary workstation (Source : SOCRadar).

Separately, PentAGI connected AI-assisted pentesting workflows to a Cobalt Strike Team Server through an AI provider API.

Recovered configurations allocated models and token budgets by task complexity.

These artifacts demonstrate deliberate orchestration, but agent names alone do not prove successful industrial-control-system manipulation or disruption of electricity delivery.

Session logs documented repeated fictional authorization claims and fresh-session retries after refusals.

Some safeguards held: models rejected backdoor installation, firewall disabling, lateral movement, webshell deployment, and forged ownership assertions.

Sector distribution of confirmed CyberXero victims (Source : SOCRadar).

The report highlights both AI-enabled scaling and conventional security failures.

Defenders investigating this activity can prioritize rogue WordPress accounts, unexpected plugins, exposed credentials, and unusual database extraction.

Agent session histories also warrant sensitive-log handling because they can disclose targets, secrets, and operational intent.

IOCs

IndicatorRole
46.21.250.135Primary workstation, open directory seed node (AS204601, Zomro NL)
45.88.106.2Provisioning server, port 1500 (AS204601, Zomro NL)
212.193.31.189Multi-chain CryptoPay gateway (AS202799)
42.193.227.214Cobalt Strike Team Server and PentAGI, port 9995 (AS45090, Tencent Cloud)
91.208.184.148Secondary workstation (AS200019)

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Stops Cyber threats before impact with 21 min faster MTTR. Integrate ANYRUN’s Sandbox in your SOC.

Mayura Kathir

Mayura Kathir is a cybersecurity reporter at GBHackers News, covering daily incidents including data breaches, malware attacks, cybercrime, vulnerabilities, zero-day exploits, and more.

Recent Posts

Insignary Launches Clarity AIR to Detect Undeclared Open-Source and AI-Written Code

Toronto, Canada, October 8th, 2026, CyberNewswire Insignary Launches Clarity AIR: Closing the Blind Spot Between…

26 minutes ago

Hackers Hijack Tensorlake Package to Spread Shai-Hulud Supply Chain Malware

A threat actor published a malicious version of the tensorlake npm package on October 8,…

2 hours ago

PoC Exploit Released for Zammad Vulnerability Enabling Session Hijacking and Remote Code Execution

A proof-of-concept (PoC) exploit has been released for CVE-2026-102489, a critical vulnerability in Zammad that…

2 hours ago

Critical LMCache RCE Vulnerability Remains Unpatched, Public PoC Exploit Available

A critical vulnerability in LMCache allows unauthenticated attackers to execute arbitrary code against reachable multi-process…

2 hours ago

16 Malicious Firefox Extensions Impersonate Crypto Wallets to Steal Seed Phrases and Private Keys

16 malicious Firefox extensions that impersonate cryptocurrency wallets to intercept recovery phrases and private keys…

3 hours ago

Exposed DarkSword iOS Servers Reveal Crypto Wallet Theft From Compromised iPhones

Exposed directories on five servers have revealed an operational DarkSword/Coruna exploitation platform built to compromise…

4 hours ago