# CyberXero: AI-Augmented Initial Access Broker Targeting Ukrainian Critical Infrastructure and Global WordPress/E-commerce Platforms

> SOCRadar's STRU reports CyberXero, a Russian-speaking, financially motivated initial access broker that pairs commodity offensive tooling (Cobalt Strike, Impacket, Mimikatz) with an AI orchestration layer of up to 51 Claude Code agents and a PentAGI deployment wired into a Cobalt Strike Team Server. It runs an automated global campaign against WordPress/e-commerce sites and a curated manual campaign against Ukrainian energy and utilities, with confirmed exfiltration of 628,000+ records from four Ukrainian organizations.

- **Published:** 2026-10-07T00:00:00Z
- **Last reviewed:** 2026-10-07T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-2992
- **ID:** TL-2026-2992
- **Severity:** HIGH
- **Category:** THREAT_INTEL
- **Status:** ACTIVE
- **Actor:** CyberXero
- **Detections:** 9 · **IOCs:** 12 (full data via the Threadlinqs MCP server — Purple tier)
- **CVEs:** CVE-2026-4815, CVE-2015-1397

## Description

CyberXero is a Russian-speaking, financially motivated initial access broker (IAB) documented by SOCRadar's Threat Research Unit (STRU) on 2026-10-06. The operation was exposed by a single configuration error: an open directory on 46.21.250.135 (hosted via Zomro, Netherlands) served the actor's live working directory - roughly 90,000 files across ~3,000 subdirectories including victim folders, AI agent configurations, AI session logs, scripts containing plaintext tokens, and exfiltrated victim data. Infrastructure was first observed in July 2026 (secondary reporting notes the actor created AI accounts on 2026-07-01) and the actor was still active at publication. Provisioning tokens, SSH keys and command histories linked eight infrastructure nodes, and attribution to the CyberXero persona rests on a Dread post, a cover persona and billing information across five platforms.

The actor runs two pipelines. The first is an opportunistic, automated global pipeline that mass-exploits WordPress and e-commerce platforms for access and payment data. A single automated execution scanned 4,708 targets, confirmed access to 429 WordPress administration panels and deployed 32 shells within a 61-second window. Reported techniques include blind and time-based SQL injection, PHP deserialization, credential spraying, WAF-bypass attempts, and 'wp2shell' - an internally developed Python package that abuses a desynchronization in the WordPress REST API batch endpoint to inject SQL, create a rogue administrator (username pattern wp2_ followed by eight hex characters) and deploy a WSO-family webshell registered as an active plugin. The actor exploited the time-based SQL injection CVE-2026-4815 in the Support Board WordPress plugin within 30 days of disclosure, tested ~93 Magento domains against CVE-2015-1397, and exploited exposed Redis in a compromise of Chinese infrastructure. Targets span Ukraine, Poland (e-commerce portals), China and Pakistan (national-security entities, outcome unconfirmed) across energy and utilities, e-commerce, telecom and government.

The second pipeline is a directed, manual campaign of deep reconnaissance and exploitation against Ukrainian energy and utilities. Data exfiltration was confirmed from four Ukrainian organizations (628,000+ records tied to Ukrainian individuals, including Kharkiv residents; a Kharkiv district-heating provider accounted for 564,073 subscriber records and 213,340 access logs), alongside curated reconnaissance of seven energy/utilities entities (one target list enumerated 95 subdomains). The purpose of the Ukrainian campaign and any intent to sell access are unconfirmed.

The AI layer is the novel element: up to 51 specialized Claude Code agents on the primary workstation support reconnaissance, exploitation, lateral movement and exfiltration, and a PentAGI deployment is integrated with a Cobalt Strike Team Server through an AI-provider API for payload generation and pentest execution. Session logs show the actor bypassing model refusals with fabricated authorization claims across four unrelated victims and session resets, while some refusals held and blocked backdoor/webshell deployment and lateral-movement attempts. Available reporting does not establish which tasks individual agents performed or their success rates. Note: SOCRadar's page was inaccessible (HTTP 403) during collection; facts derive from search-indexed SOCRadar text and secondary summaries (ITNerd, Mallory, Cyberpress). Secondary reports cite Support Board '3.8.7' for CVE-2026-4815, whereas NVD lists versions prior to 3.7.8 as vulnerable. One search snippet lists Dread, HackForums and Exploit.in alongside the actor; the sources reviewed do not clarify whether these are aliases or forums where the persona is active, so they are not recorded as aliases.

## MITRE ATT&CK

- T1595.002 Vulnerability Scanning
- T1590.002 DNS
- T1588.002 Tool
- T1588.005 Exploits
- T1588.007 Artificial Intelligence
- T1587.004 Exploits
- T1190 Exploit Public-Facing Application
- T1059 Command and Scripting Interpreter
- T1059.006 Command and Scripting Interpreter: Python
- T1505.003 Web Shell
- T1136 Create Account
- T1110.003 Password Spraying
- T1003 OS Credential Dumping
- T1552.001 Credentials In Files
- T1021 Remote Services
- AML.T0054 LLM Jailbreak

## Sources

- [CyberXero: An AI-Augmented Initial Access Broker Targeting Ukrainian Critical Infrastructure (SOCRadar)](https://socradar.io/blog/cyberxero-ai-iab-ukraine-critical-infrastructure/)
- [CyberXero summary of SOCRadar STRU report (ITNerd)](https://itnerd.blog/2026/10/06/cyberxero-an-ai-augmented-initial-access-broker-targeting-ukrainian-critical-infrastructure/)
- [CyberXero Uses AI Agents to Target Ukrainian Infrastructure and Global Web Applications (Mallory)](https://mallory.ai/stories/01a1153b-38a0-712b-9a61-2d050bc47167)
- [CyberXero Uses 51 AI Agents to Target Ukrainian Critical Infrastructure and Mass-Exploit WordPress (Cyberpress)](https://cyberpress.org/cyberxero-weaponizes-ai-agents/)
- [NVD: CVE-2026-4815 Support Board SQL injection](https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2026-4815)
- [INCIBE-CERT: Multiple vulnerabilities in Support Board (Schiocco)](https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-support-board-schiocco)
- [Critical wp2shell WordPress flaws exploited to install webshells (BleepingComputer; related context, CyberXero not named)](https://www.bleepingcomputer.com/news/security/critical-wp2shell-wordpress-flaws-exploited-to-install-webshells/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-2992
