Autonomous AI Agent Operation (Strix, Cairn, Hermes) Steals 600K+ Payment Cards and Injects Skimmers into 100+ E-Commerce Sites
Autonomous AI Agent Operation (Strix, Cairn, Hermes) Steals (TL-2026-2633), also tracked as AI agent Magecart campaign, is a critical-severity malware campaign, first published 2026-09-23. It is linked to a China-nexus actor with low confidence, affects Custom-coded E-commerce storefronts and checkout pages, maps to 19 MITRE ATT&CK techniques (T1027.013, T1036.005, T1048.003), and is covered by 9 detection rules and 31 indicators of compromise.
Key facts for TL-2026-2633
- Threat ID
- TL-2026-2633
- Also known as
- AI agent Magecart campaign, Strix-Cairn-Hermes campaign
- Severity
- CRITICAL
- Status
- ACTIVE
- Category
- MALWARE
- First published
- 2026-09-23
- Last reviewed
- 2026-09-23
- Attribution confidence
- LOW
- Nation-state nexus
- China
- Motivation
- FINANCIAL
- Target sectors
- retail, ecommerce, hospitality, aviation, travel, industrial-distribution, manufacturing
- Target regions
- North America, Global
- Detection rules
- 9
- Indicators of compromise
- 31
Malware and tooling in Autonomous AI Agent Operation (Strix, Cairn, Hermes) Steals
Malware and tooling: Hermes, Cairn, Hermes, Strix
Gambit Security reconstructed a financially motivated, Chinese-speaking operator's campaign from an exposed staging server, showing open-source AI agents (Strix, Cairn, Hermes) used to breach online retailers at an average model cost of about $25 per target. Since July 2026 the operation has stolen more than 600,000 unexpired payment card records, planted Magecart-style web skimmers on 119+ sites, and in several cases destroyed victim database data after exfiltration.
How Autonomous AI Agent Operation (Strix, Cairn, Hermes) Steals works
Gambit Security published research on 2026-09-22 describing a payment-card theft campaign active since at least July 2026 and still ongoing at publication. The researchers obtained access to the attacker's exposed staging and command server (155.254.22.215), which hosted an AI operator console. From it they reconstructed an operation in which a single operator directed three open-source AI agent frameworks: Strix for vulnerability discovery, Cairn as an autonomous penetration-testing engine given a target and an objective (shell or admin access), and Hermes as the orchestration harness. Hermes carried a persistent 'SOUL - Red Team Operator' persona and 121 custom skills, 78 of them offensive. The operator typed 1,951 prompts across 260 sessions, mostly in Chinese, and accessed models through OpenRouter. Reporting names Anthropic Opus 4.6 plus DeepSeek and Kimi as the models used.
Scale and economics: between 2026-08-23 and 2026-08-31, Strix ran 146 deep-mode scans against 138 hosts, consuming 633 scanner-hours within 195 hours of clock time. Between 2026-09-10 and 2026-09-15, Gambit counted 105 attack projects. At least 27 named organizations were compromised to varying degrees and 19 skimmer infections were confirmed. Victims include a Fortune 500 hospitality company, a major U.S. airline, a U.S. industrial supplies distributor, and online retailers selling fashion, beauty, wine, bicycles, firearms, print-on-demand goods and photo printing, plus travel booking sites. More than 600,000 unexpired card records were stolen from two companies, about 79% of them belonging to U.S. cardholders. Beyond the direct targets, Gambit found 100+ other websites loading skimmer code from the same infrastructure. Model spend was about $7,005.71 over four weeks, with $12,000-$18,000 estimated in total. The mean was $25.46 per completed scan, ranging from $3.13 to $79.31 per target. Custom-coded shops were preferred over hosted platforms.
Intrusion and impact: reported initial access came through web application flaws such as SQL injection, chained to MFA bypass, admin access, web shells and database extraction. The attacker decrypted stored card numbers using stolen AWS Secrets Manager credentials. Skimmer persistence depended on the access level obtained. Methods included loader code appended to legitimate JavaScript libraries such as jQuery with the file timestamps restored, foreign script tags on checkout pages, loaders hidden inside Google Analytics / tag-manager blocks, S3 buckets behind CDNs poisoned using compromised AWS credentials, loaders appended to product descriptions in the database, Kubernetes deployments modified with an injected initContainer, poisoned server-side cached checkout pages, and a self-healing cron job in a JBoss log directory that re-injected the skimmer every two minutes. The injected loader follows the pattern new Function(atob('<7 junk chars><base64>'.slice(7)))(). Skimmer payloads were served from typosquatted CDN-lookalike domains (netlfjs, js-static, static-js, jsnetlify, netlifyjs, newssjs, x1opay, b8t.shop). Data was exfiltrated over DNS and HTTP listeners, with medbooksource.com used as the operator console and for out-of-band/DNS exfiltration. Attacks were routed through the IPRoyal, 711proxy and 1024proxy residential proxy services.
Destructive side effects: a Hermes skill titled 'Database Wipe After Extraction' told the agent to wipe payment-card source fields in Magento databases in batches once the data was downloaded. At one bicycle retailer, an overly broad cleanup routine dropped 180 database tables, including backups the administrators had created. Gambit coordinated takedowns with the Shadowserver Foundation and Cloudflare, but the operator repeatedly rebuilt the infrastructure. Defender priorities: hunt for the listed skimmer domains and URLs in page resources and CSP reports; look for integrity drift in first-party JS bundles, tag-manager containers, S3/CDN objects, database content fields, Kubernetes pod specs and cron tables; watch for high-entropy DNS to medbooksource.com; and plan for data-loss recovery, not just breach notification.
MITRE ATT&CK techniques used in TL-2026-2633
Defense Evasion
T1027.013 Obfuscated Files or Information: Encrypted/Encoded File; T1036.005 Masquerading: Match Legitimate Resource Name or Location; T1070.006 Indicator Removal: Timestomp; T1078.004 Valid Accounts: Cloud Accounts
Exfiltration
T1048.003 Exfiltration Over Alternative Protocol: Exfiltration Over Unencrypted Non-C2 Protocol
Persistence
T1053.003 Scheduled Task/Job: Cron; T1505.003 Server Software Component: Web Shell
Collection
T1056.003 Input Capture: Web Portal Capture; T1213.006 Data from Information Repositories: Databases
Execution
T1059.007 Command and Scripting Interpreter: JavaScript; T1610 Deploy Container
Command and Control
T1090.002 Proxy: External Proxy
Initial Access
T1190 Exploit Public-Facing Application
Impact
T1485 Data Destruction; T1565.001 Data Manipulation: Stored Data Manipulation
Credential Access
T1555.006 Credentials from Password Stores: Cloud Secrets Management Stores
Resource Development
T1583.001 Acquire Infrastructure: Domains; T1588.007 Obtain Capabilities: Artificial Intelligence
Reconnaissance
Affected products and versions in Autonomous AI Agent Operation (Strix, Cairn, Hermes) Steals
- Custom-coded — E-commerce storefronts and checkout pages
Vulnerable versions: custom applications with SQL injection / authentication flaws - Adobe — Magento / Adobe Commerce
Vulnerable versions: deployments compromised via admin access (card fields wiped after exfiltration) - Amazon Web Services — S3 / CloudFront-hosted static assets and Secrets Manager
Vulnerable versions: accounts with compromised access keys - Red Hat — JBoss application server hosts
Vulnerable versions: hosts where cron persistence was planted - Kubernetes — E-commerce workloads (Deployments)
Vulnerable versions: deployments modified with a malicious initContainer
Remediation for Autonomous AI Agent Operation (Strix, Cairn, Hermes) Steals
Patches
- No CVE was attributed. Patch and fix SQL injection and authentication flaws in custom e-commerce code and keep Magento/Adobe Commerce and JBoss deployments on supported, patched releases
Immediate actions
- Block and hunt for the published skimmer domains, URLs and C2 IPs (medbooksource.com, traffic-analyzer.net, b8t.shop, netlfjs/js-static/static-js/jsnetlify/netlifyjs/newssjs/x1opay domains, 155.254.22.215, 209.126.4.170, 213.21.239.62, 172.245.224.188, 172.245.89.137) in DNS, proxy and CSP report logs
- Search first-party JavaScript bundles, HTML templates, tag-manager/Google Analytics blocks, database content fields (e.g. product descriptions) and cached checkout pages for the loader pattern new Function(atob('...'.slice(7)))()
- Diff S3/CDN-hosted static assets against source control and review CloudTrail for PutObject by unexpected principals
- Inspect Kubernetes deployments for unexpected initContainers and review crontabs, including JBoss log directories, for re-injection jobs
- Rotate AWS access keys and Secrets Manager secrets, admin panel credentials and database credentials on any affected host
- Coordinate with card brands/acquirers for compromised-card notification (PCI DSS incident response)
Workarounds
- Place a WAF in front of custom storefronts to block SQL injection and web-shell upload attempts
- Restrict admin panels to VPN/allow-listed networks and require phishing-resistant MFA
- Apply least-privilege IAM to S3 buckets serving front-end assets (no write access from application credentials)
Longer-term hardening
- Enforce a strict Content-Security-Policy and Subresource Integrity on checkout pages and monitor CSP violation reports (PCI DSS 4.0 req. 6.4.3 and 11.6.1 payment-page script and change monitoring)
- Deploy file-integrity monitoring on web roots and static asset buckets, with timestamp-independent hashing (the attacker restored mtimes)
- Tokenize or externalize card storage so that stored PANs and decryption keys are not reachable from the web tier
- Keep offline, immutable database backups: attacker cleanup routines destroyed both data and admin-created backups
- Tune detection and response for AI-paced intrusions that complete in hours, e.g. alert on sustained high-volume scanning from residential proxy ranges
- Adopt a resilience-first recovery plan that covers business continuity, not only data restoration
Weaknesses (CWE) in Autonomous AI Agent Operation (Strix, Cairn, Hermes) Steals
CWE-89, CWE-494
Timeline of Autonomous AI Agent Operation (Strix, Cairn, Hermes) Steals
- Campaign activity begins (reported as 'since at least July 2026'); tens of companies were targeted by AI-agent-driven intrusions
- Strix deep-mode scanning wave begins: 146 scans against 138 hosts through 2026-08-31 (633 scanner-hours in 195 clock-hours)
- End of the peak Strix vulnerability-scanning window documented by Gambit
- Start of the peak exploitation window: 105 attack projects launched through 2026-09-15
- Peak window ends with at least 27 organizations compromised, including a Fortune 500 hospitality company, a major U.S. airline and a U.S. industrial supplies distributor
- Gambit Security publishes its analysis of the exposed staging server, including IOCs; takedowns coordinated with Shadowserver and Cloudflare, while the operator rebuilds and the campaign continues
- BleepingComputer, HackRead and other outlets report the 600K+ card theft and 100+ skimmer-infected sites
Sources cited for Autonomous AI Agent Operation (Strix, Cairn, Hermes) Steals
- Gambit Security - Autonomous AI agents attacking online retailers (~$25 a company)
- Malicious AI agents steal 600K credit cards, infect 100-plus sites with skimmers
- Autonomous AI Agents Hack Retailers for $25 and Steal 600,000 Credit Cards
- Open-Source AI Agents Breach 27 Companies, Steal 600,000 Credit Card Records
- AI agents steal 600,000 credit cards in attacks on online retailers
- Chinese-speaking hacker used AI agents to steal 600,000 credit cards
- Autonomous AI Agents Hack Online Retailers for $25 a Target, Steal 600,000 Credit Cards
More in malware
- Carbonato botnet: AI-agent-driven worm hijacks unauthenticated Docker daemons on port 2375 and installs the Hermes Agent 'GH0ST' implant
- MacSync macOS infostealer/backdoor: reworked MaaS chain stages stage-two via a public iCloud calendar (SONOMAC1)
- RemControl Android Banking Trojan Targets Italy and France via Fake TVTap IPTV App
- Macfinger ClickFix Campaign Delivers Atomic macOS Stealer (AMOS) via Fake Verification Prompts
- eBPF Rootkit Detection: VoidLink, LinkPro, and Atomic Arch Evade Kernel-Level Monitoring
Detection coverage for TL-2026-2633
As of 2026-09-23, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2633 across Splunk SPL, Microsoft KQL and Sigma, covering 31 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.