Threat reportThreat IntelligenceTL-2026-2992
CyberXero: AI-Augmented Initial Access Broker Targeting Ukrainian Critical Infrastructure and Global WordPress/E-commerce Platforms
CyberXero: AI-Augmented Initial Access Broker Targeting (TL-2026-2992) is a high-severity tracked intrusion set, first published 2026-10-07. It is attributed to CyberXero with low confidence, affects Schiocco Support Board (WordPress plugin), references 2 CVEs (CVE-2026-4815, CVE-2015-1397), maps to 16 MITRE ATT&CK / ATLAS techniques (AML.T0054, T1003, T1021), and is covered by 9 detection rules and 12 indicators of compromise.
- Severity
- HIGHAssessed severity
- CVEs
- 2Referenced vulnerabilities
- Techniques
- 16MITRE ATT&CK / ATLAS
- Actors
- 1CyberXero
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 12Indicators of compromise
Key facts for TL-2026-2992
- Threat ID
- TL-2026-2992
- Severity
- HIGH
- Status
- ACTIVE
- Category
- THREAT_INTEL
- First published
- Last reviewed
- Attribution
- CyberXero
- Attribution confidence
- LOW
- Motivation
- FINANCIAL
- Target sectors
- energy, utilities, critical-infrastructure, ecommerce, telecom, government administration
- Target regions
- ukraine, poland, china, pakistan
- Detection rules
- 9
- Indicators of compromise
- 12
Malware and tooling in CyberXero: AI-Augmented Initial Access Broker Targeting
Malware and tooling: Cobalt Strike, MimiKatz, WSO webshell, Claude Code, Cobalt Strike, Impacket - S0357, Mimikatz, PentAGI
How CyberXero: AI-Augmented Initial Access Broker Targeting works
SOCRadar's STRU reports CyberXero, a Russian-speaking, financially motivated initial access broker that pairs commodity offensive tooling (Cobalt Strike, Impacket, Mimikatz) with an AI orchestration layer of up to 51 Claude Code agents and a PentAGI deployment wired into a Cobalt Strike Team Server. It runs an automated global campaign against WordPress/e-commerce sites and a curated manual campaign against Ukrainian energy and utilities, with confirmed exfiltration of 628,000+ records from four Ukrainian organizations.
CyberXero is a Russian-speaking, financially motivated initial access broker (IAB) documented by SOCRadar's Threat Research Unit (STRU) on 2026-10-06. The operation was exposed by a single configuration error: an open directory on 46.21.250.135 (hosted via Zomro, Netherlands) served the actor's live working directory - roughly 90,000 files across ~3,000 subdirectories including victim folders, AI agent configurations, AI session logs, scripts containing plaintext tokens, and exfiltrated victim data. Infrastructure was first observed in July 2026 (secondary reporting notes the actor created AI accounts on 2026-07-01) and the actor was still active at publication. Provisioning tokens, SSH keys and command histories linked eight infrastructure nodes, and attribution to the CyberXero persona rests on a Dread post, a cover persona and billing information across five platforms.
The actor runs two pipelines. The first is an opportunistic, automated global pipeline that mass-exploits WordPress and e-commerce platforms for access and payment data. A single automated execution scanned 4,708 targets, confirmed access to 429 WordPress administration panels and deployed 32 shells within a 61-second window. Reported techniques include blind and time-based SQL injection, PHP deserialization, credential spraying, WAF-bypass attempts, and 'wp2shell' - an internally developed Python package that abuses a desynchronization in the WordPress REST API batch endpoint to inject SQL, create a rogue administrator (username pattern wp2_ followed by eight hex characters) and deploy a WSO-family webshell registered as an active plugin. The actor exploited the time-based SQL injection CVE-2026-4815 in the Support Board WordPress plugin within 30 days of disclosure, tested ~93 Magento domains against CVE-2015-1397, and exploited exposed Redis in a compromise of Chinese infrastructure. Targets span Ukraine, Poland (e-commerce portals), China and Pakistan (national-security entities, outcome unconfirmed) across energy and utilities, e-commerce, telecom and government.
The second pipeline is a directed, manual campaign of deep reconnaissance and exploitation against Ukrainian energy and utilities. Data exfiltration was confirmed from four Ukrainian organizations (628,000+ records tied to Ukrainian individuals, including Kharkiv residents; a Kharkiv district-heating provider accounted for 564,073 subscriber records and 213,340 access logs), alongside curated reconnaissance of seven energy/utilities entities (one target list enumerated 95 subdomains). The purpose of the Ukrainian campaign and any intent to sell access are unconfirmed.
The AI layer is the novel element: up to 51 specialized Claude Code agents on the primary workstation support reconnaissance, exploitation, lateral movement and exfiltration, and a PentAGI deployment is integrated with a Cobalt Strike Team Server through an AI-provider API for payload generation and pentest execution. Session logs show the actor bypassing model refusals with fabricated authorization claims across four unrelated victims and session resets, while some refusals held and blocked backdoor/webshell deployment and lateral-movement attempts. Available reporting does not establish which tasks individual agents performed or their success rates. Note: SOCRadar's page was inaccessible (HTTP 403) during collection; facts derive from search-indexed SOCRadar text and secondary summaries (ITNerd, Mallory, Cyberpress). Secondary reports cite Support Board '3.8.7' for CVE-2026-4815, whereas NVD lists versions prior to 3.7.8 as vulnerable. One search snippet lists Dread, HackForums and Exploit.in alongside the actor; the sources reviewed do not clarify whether these are aliases or forums where the persona is active, so they are not recorded as aliases.
MITRE ATT&CK / ATLAS techniques used in TL-2026-2992
Defense Evasion
Credential Access
T1003 OS Credential Dumping; T1110.003 Password Spraying; T1552.001 Credentials In Files
Lateral Movement
Execution
T1059 Command and Scripting Interpreter; T1059.006 Command and Scripting Interpreter: Python
Persistence
T1136 Create Account; T1505.003 Web Shell
Initial Access
T1190 Exploit Public-Facing Application
Resource Development
T1587.004 Exploits; T1588.002 Tool; T1588.005 Exploits; T1588.007 Artificial Intelligence
Reconnaissance
Affected products and versions in CyberXero: AI-Augmented Initial Access Broker Targeting
- Schiocco — Support Board (WordPress plugin)
Vulnerable versions: prior to 3.7.8 (per NVD; secondary reports cite 3.8.7)
Fixed in: 3.7.8 - Magento — Magento (CVE-2015-1397)
Vulnerable versions: unpatched legacy versions - WordPress — WordPress / WooCommerce-style e-commerce sites
Vulnerable versions: internet-facing sites with vulnerable plugins or exposed REST API batch handling - Redis — Redis (internet-exposed instances)
Vulnerable versions: exposed/unauthenticated instances
Remediation for CyberXero: AI-Augmented Initial Access Broker Targeting
Patches
- Update the Support Board WordPress plugin to 3.7.8 or later (CVE-2026-4815, per NVD)
- Apply Magento patches for CVE-2015-1397
Immediate actions
- Block and hunt for outbound traffic to 46.21.250.135 and to any Cobalt Strike Team Server ports observed in your telemetry
- Audit WordPress for newly created administrator accounts, especially usernames matching wp2_ followed by 8 hex characters, and for unexpected active plugins
- Search web roots and plugin directories for WSO-family webshells and unauthorized plugin installs
- Verify Redis instances are not exposed to the internet and require authentication
Workarounds
- Place a WAF in front of /supportboard/include/ajax.php or disable the Support Board plugin until patched
- Restrict or filter the WordPress REST API batch endpoint where not required
Longer-term hardening
- Patch internet-facing WordPress, Magento and PrestaShop components promptly; this actor weaponized a plugin SQL injection within 30 days of disclosure
- Remove hardcoded credentials and plaintext tokens from scripts and configuration files
- Enforce MFA and rate limiting on WordPress admin and REST API endpoints to blunt credential spraying
- Ukrainian energy/utilities operators: review exposure of customer-data portals and monitor for recon against them
CVEs associated with CyberXero: AI-Augmented Initial Access Broker Targeting
CVE-2026-4815, CVE-2015-1397
Weaknesses (CWE) in CyberXero: AI-Augmented Initial Access Broker Targeting
Timeline of CyberXero: AI-Augmented Initial Access Broker Targeting
- CVE-2026-4815 (Support Board WordPress plugin time-based SQL injection, CWE-89) published to NVD and noted by INCIBE-CERT; later weaponized by CyberXero
- Latest date by which CyberXero exploited CVE-2026-4815, which SOCRadar says occurred within 30 days of disclosure
- CyberXero infrastructure first observed in July 2026; Mallory reports the actor created AI accounts on 1 July 2026, expanding operations (month-level date for first-seen infrastructure; exact day not otherwise reported)
- BleepingComputer reports exploitation of critical wp2shell WordPress flaws to install webshells; related context only - CyberXero is not named, and the link to the actor's internal 'wp2shell' package is unconfirmed
- SOCRadar publishes the CyberXero report; actor still active at time of publication
- Exposed open directory on 46.21.250.135 (~90,000 files, ~3,000 subdirectories incl. AI session logs, plaintext-token scripts and victim data) analyzed by SOCRadar STRU; exfiltration confirmed from four Ukrainian organizations (628,000+ records) and recon of seven energy/utilities entities
- Cyberpress and Mallory publish secondary coverage detailing the 51 Claude Code agents, PentAGI-Cobalt Strike integration, 4,708-target scan and 32 shells deployed in 61 seconds
Sources cited for CyberXero: AI-Augmented Initial Access Broker Targeting
- CyberXero: An AI-Augmented Initial Access Broker Targeting Ukrainian Critical Infrastructure (SOCRadar)
- CyberXero summary of SOCRadar STRU report (ITNerd)
- CyberXero Uses AI Agents to Target Ukrainian Infrastructure and Global Web Applications (Mallory)
- CyberXero Uses 51 AI Agents to Target Ukrainian Critical Infrastructure and Mass-Exploit WordPress (Cyberpress)
- NVD: CVE-2026-4815 Support Board SQL injection
- INCIBE-CERT: Multiple vulnerabilities in Support Board (Schiocco)
- Critical wp2shell WordPress flaws exploited to install webshells (BleepingComputer; related context, CyberXero not named)
Detection coverage for TL-2026-2992
As of 2026-10-07, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2992 across Splunk SPL, Microsoft KQL and Sigma, covering 12 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.