إلى الخلف
جدول المحتوى
أيوش بانوار
Cybersecurity Consultant who loves hacking, breaking things, and learning new ways to secure them.
لم يتم العثور على أية عناصر.

Executive Summary

CloudSEK's Global Threat Intelligence team identified an exposed open directory belonging to a financially motivated, Chinese-speaking offensive operator who has industrialised intrusion by running a fleet of commercial and open-source AI coding agents as an autonomous hacking crew. The directory served the operator's full working home folder to the public internet, exposing the tooling, methodology, credentials, and stolen data behind two parallel campaigns: internet-wide opportunistic exploitation and targeted theft against crypto and DeFi organisations.

  • Autonomous AI attack fleet: The operator drives multiple AI coding agents (Claude Code, Codex, and the open-source Hermes and pi agents) in full-auto mode with every safety approval disabled, tasking and monitoring them entirely over Telegram. Human-typed prompts recovered from the agents' own session transcripts show a reusable Chinese "authorized pentest" template used purely as a jailbreak wrapper, with no real authorization.
  • Confirmed mass compromise: Working files contain over 12,000 real WordPress backdoor records (each a unique attacker-created admin account), a separate set of 66 genuinely harvested (non-backdoor) database admin credentials, and a 3.4 million host reconnaissance corpus, produced by an automated WordPress-to-webshell exploitation pipeline.
  • Direct wallet-key and seed-phrase holding: The operator holds private keys, seed phrases, and live balances for hundreds of end-user cryptocurrency wallets. The bulk of this material was scraped with zero authentication from one phishing clone network's misconfigured cloud database (the users are victims of that phishing operation), while a smaller set of key material was retrieved directly from his own targets. He separately holds numerous validated live API keys and admin tokens for crypto exchanges, DeFi protocols, and blockchain infrastructure providers.
  • Blockchain C2 and cryptojacking: The operator was developing an EtherHiding-style, takedown-resistant command-and-control system that hides commands on a public blockchain, and separately deploys a disguised Monero miner onto compromised hosts for ongoing illicit revenue.

Analysis

Reconstructed from file modification times, shell history, and agent session transcripts, the observed activity window runs from 10 July 2026 to 28 July 2026, peaking around 12 to 13 July.

Operation timeline 

A compressed view of the roughly three-week active window, from bulk crypto and DeFi sweeps through wallet-key consolidation to blockchain-C2 development.

  • 10 to 13 July, bulk targeting: Heaviest phase of automated report generation, dozens of targeted crypto and DeFi sweeps per day, and the earliest recovered agent tasking against named targets.
  • Around 13 July, mining setup: Build and test of the Monero miner, followed by pushing binaries to worker hosts.
  • 16 to 20 July, mass campaign matures: The WordPress mass-exploitation pipeline scales up, alongside the strongest wallet-theft evidence from targeted trading-bot ecosystems and open cloud databases.
  • 20 to 23 July, loot consolidation: Wallet private keys and seed phrases are consolidated into combined datasets, with sensitive-data scan reports produced.
  • 25 to 28 July, C2 development: The blockchain command-and-control research paper and project are written, the miner is deployed, and WordPress monitoring continues. The last shell-history write is 28 July.

Discovery: An exposed operator staging host

The investigation began with an open directory served on a non-standard port of a single staging host. Directory listing was enabled and the root of the operator's home folder was browsable without authentication. Mapping the listing recovered a working environment of tens of thousands of directories and well over a hundred thousand files, including AI-agent session transcripts, configuration files, reconnaissance corpora, per-target engagement folders, and per-finding evidence with harvested credentials and stolen data.

The nature of the host was unambiguous from its contents: a blockchain-C2 development project, an autonomous-agent orchestration stack, a WordPress mass-exploitation toolkit, a deserialization RCE kit, a cryptocurrency miner, and harvested credentials from a large number of victims. Targeting skewed heavily toward crypto and DeFi organisations.

Note: All findings in this report are grounded in artifacts the operator left in his own working directory: saved API responses, exported databases, agent session transcripts, and shell history. No attacker code was executed and no outbound connection was made to attacker or victim infrastructure during analysis. Everything substantive was extracted from the static local capture.

End-to-end operation attack chain 

The operator tasks an AI-agent fleet over Telegram, which runs the full intrusion lifecycle unattended against opportunistic and targeted victims, feeding stolen credentials, wallet keys, and mining revenue back to the operator.

Threat Actor Infrastructure

Primary Staging Host

مدونات ذات صلة