Lone Operator Uses AI Agents

31273589484?profile=RESIZE_400xA financially-motivated threat actor recently deployed open-source AI agent frameworks to attack hundreds of online retailers at scale, compromising more than 100 e-commerce websites and exfiltrating over 600,000 credit card records.  Active since July 2026, the campaign has leveraged three specialized AI tools to execute the complete attack chain across target networks with minimal human intervention.[1]

The automated framework relied on Strix, an AI penetration testing framework that conducted 633 hours of vulnerability scanning in a nine-day window across 138 targeted hosts.  Upon identifying exploitable entry points, the operator deployed Cairn, an autonomous exploitation engine tasked with obtaining administrative access and system shells.  Campaign orchestration was then governed by Hermes, an AI agent configured with a specialized red team operator persona containing 78 distinct attack-related skills. 

Once a human operator supplied a target list and brief tactical objectives, the AI agents autonomously navigated custom software architectures and selected an attack path in real time through probing.

To harvest payment data, the autonomous agents injected digital skimmers across compromised environments by adding malicious code to legitimate JavaScript files, poisoning cloud storage buckets, altering Kubernetes deployments, and establishing persistence via scheduled cron jobs.

After exfiltrating credit card records, Hermes executed automated cleanup routines that systematically wiped source database fields in batches, inflicting severe operational data loss on victim retailers.

Researchers found that the entire campaign operated at an average cost of just $25 per targeted company. Major targets so far include a Fortune 500 hospitality firm, a major US airline, an online fashion retailer, and an industrial supplies distributor.

31273589668?profile=RESIZE_584xTimeline of attacks orchestrated by Cairn between September 10-15 2026 (Source: Gambit)

This article used AI to craft the contents and is shared at no charge for educational and informational purposes only.

Red Sky Alliance is a Cyber Threat Analysis and Intelligence Service organization.  We provide indicators of compromise information (CTI) via a notification/Tier I analysis service (RedXray) or an analysis service (CTAC).  For questions, comments or assistance, please contact the office directly at 1-844-492-7225, or feedback@redskyalliance.com    

Weekly Cyber Intelligence Briefings:

Weekly Cyber Intelligence Briefings:

REDSHORTS - Weekly Cyber Intelligence Briefings

https://attendee.gotowebinar.com/register/7855487668891299929

[1] https://www.sentinelone.com/blog/the-good-the-bad-and-the-ugly-in-cybersecurity-week-39-8/

E-mail me when people leave their comments –

You need to be a member of Red Sky Alliance to add comments!