CyberXero attacks are combining artificial intelligence with established offensive tools to compromise WordPress and e-commerce sites at speed. The Russian-speaking operation has also pursued selected Ukrainian energy and utility organisations.
SOCRadar publicly disclosed the campaign on 6 October 2026 after investigating an exposed directory on attacker-controlled infrastructure. Its findings indicate that CyberXero operated as a financially motivated initial access broker, obtaining access that could be sold, reused or monetised through further attacks.
CyberXero attacks exposed through an open directory
The investigation began when a misconfigured open directory revealed what appeared to be the operator’s live working folder. The exposed material included more than 90,000 files, according to the original reporting, providing researchers with an unusually detailed view of the operation.
Available files included attack scripts, AI session records, plaintext tokens and data exfiltrated from victims. This material allowed SOCRadar to examine not only the tools involved, but also how the operator organised tasks and interacted with AI systems during live intrusion activity.
SOCRadar said activity continued while its investigation was under way. It assessed CyberXero as active when the research was published, although that status and the detailed operational figures have not yet been independently confirmed by a separate technical investigation.
The first public disclosure appeared on 6 October 2026. On 7 October 2026, technology and security publications began circulating summaries, but these secondary reports did not add new victim information, technical indicators or independently verified findings.
Two intrusion pipelines support the CyberXero attacks
The exposed material indicated that the operation followed two related but distinct pipelines. One pursued large numbers of public-facing websites worldwide, while the other concentrated on a much smaller group of strategically selected organisations in Ukraine.
Automated attacks on WordPress and online shops
The opportunistic pipeline targeted WordPress and unspecified e-commerce platforms. AI-assisted automation handled web discovery, access testing, exploitation activity and rapid deployment of web shells, which are malicious files that provide persistent remote control of a server.
One recorded run demonstrates the scale and speed of the CyberXero attacks. The system scanned 4,708 targets, accessed 429 WordPress administration panels and deployed 32 web shells in only 61 seconds.
These figures suggest that the automation could move quickly from identifying an exposed administration interface to establishing access on vulnerable sites. However, the public summary does not identify which weaknesses enabled entry, or whether individual compromises involved stolen credentials, vulnerable plugins, insecure themes, WordPress core flaws or configuration errors.
No particular WordPress core versions, plugin releases or e-commerce products were named. There are also no actor-specific public proofs of concept cited in the summary, so organisations should not interpret the campaign as involving one newly disclosed vulnerability that can be addressed with a single patch.
Directed operations against Ukrainian infrastructure
The second pipeline was more selective and involved reconnaissance and manual exploitation. SOCRadar linked this activity to seven Ukrainian energy and utility organisations, including the national transmission system operator and the country’s largest private energy holding.
The investigation also found that the actor possessed confirmed data concerning more than 628,000 Ukrainian individuals, including residents of Kharkiv. The public findings do not establish that all this information came directly from the seven infrastructure targets, so the origin and full impact of the dataset remain unclear.
This directed activity differs from the broad website campaign in targeting and execution. Together, the two pipelines show how CyberXero could pursue high-volume commercial access while dedicating additional attention to selected critical infrastructure organisations.
How AI and Cobalt Strike supported the campaign
The CyberXero attacks did not rely on a single autonomous hacking system. Instead, the operator combined multiple AI agents, attack automation and conventional post-exploitation infrastructure into an orchestrated toolchain.
SOCRadar observed up to 51 specialised Claude Code agents on the operator’s primary workstation. These agents appear to have been assigned different tasks within the workflow, allowing discovery, testing and exploitation processes to run concurrently or in rapid succession.
A separate PentAGI deployment was connected through an AI provider application programming interface to a Cobalt Strike Team Server. Cobalt Strike is a legitimate adversary simulation platform, but criminals frequently misuse unauthorised copies for command and control, lateral movement and post-exploitation activity.
Researchers described the related Cobalt Strike infrastructure as clustered on Chinese hosting. This describes the location or concentration of observed infrastructure and does not, by itself, establish that the operators were based in China.
The exposed AI logs also recorded attempts to overcome model safety refusals. According to SOCRadar, the operator used context engineering and session resets to reframe requests and continue tasks after an AI system declined to assist.
The main components identified in the CyberXero attacks were:
- Up to 51 specialised Claude Code agents operating on a primary workstation.
- A separate PentAGI instance used for AI-assisted penetration testing workflows.
- A Cobalt Strike Team Server supporting command, control and post-exploitation.
- Custom automation for scanning sites, testing access and installing web shells.
- Scripts containing plaintext tokens, alongside AI records and stolen victim data.
Current exploitation status and affected organisations
This is an observed in-the-wild campaign, not a theoretical technique. Automated scanning, access to administration panels and successful web shell deployment were recorded, while SOCRadar said the actor remained active during its research window.
The affected population potentially includes any organisation operating an internet-facing WordPress site or one of the unspecified e-commerce platforms being scanned. The campaign is global, while the more carefully directed part of the operation focused on Ukrainian energy and utility targets.
SOCRadar says its full technical report contains infrastructure details and indicators of compromise. The public blog summary does not list specific IP addresses, domains, file hashes or file paths, and no vendor advisory dedicated to the CyberXero attacks had been identified at the time of disclosure.
Why CyberXero attacks matter to UK businesses
Many UK small and medium-sized businesses depend on WordPress and online retail platforms hosted on public-facing servers. The campaign shows that attackers can test thousands of sites and establish persistence within minutes once usable access is found.
The AI element matters because it can help an operator coordinate established techniques at greater speed and scale. It does not remove the need for an exploitable weakness, compromised account or insecure configuration, but it reduces the time defenders may have to notice and interrupt activity.
Actions for WordPress and e-commerce operators
Defensive work should concentrate on the systems and behaviours observed in this campaign. Organisations should prioritise the following checks:
- Update WordPress core, active plugins and themes, and remove components that are unsupported or no longer required.
- Require multifactor authentication for administrator accounts and review all privileged users for unexpected additions or password changes.
- Restrict access to administration interfaces where operationally practical, particularly for accounts that do not require unrestricted internet access.
- Search web directories for unfamiliar PHP files, recently modified scripts and web shell patterns, then compare them with known clean versions.
- Review logs for bulk login attempts, unusual administrator sessions, unexpected plugin installation and outbound connections from the web server.
- Obtain the full SOCRadar indicator set and check relevant network, endpoint and hosting telemetry for matches.
Because the report names no specific vulnerable versions, patching should be paired with authentication reviews and active compromise hunting. Where a web shell or unknown administrator account is found, organisations should treat the server as compromised, preserve evidence and investigate how access was obtained before restoring service.
Originally reported by cybersecuritynews.com.






