
A financially motivated threat actor is using autonomous AI agents to compromise online retailers at a reported average cost of roughly $25 per target.
The campaign, active since at least July 2026, has reportedly stolen more than 600,000 unexpired payment card records, deployed web skimmers, and accessed systems belonging to major retailers, travel companies, and industrial firms.
Gambit Security Director of Threat Intelligence Eyal Sela said the company reconstructed the operation after gaining access to the attacker’s staging server. Between September 10 and 15, researchers observed 105 attack projects, with at least 27 organizations compromised to varying degrees.
The attacker relied on three open-source AI tools: Strix for vulnerability discovery, Cairn for autonomous exploitation, and Hermes for campaign orchestration and post-compromise tasks.
Hermes served as the operator’s primary control interface and contained 121 custom skills, including 78 focused on offensive security operations. The attacker issued relatively short instructions in Chinese, while the agent handled much of the reconnaissance, exploitation, persistence, and cleanup independently.
Cairn, meanwhile, was tasked with objectives such as obtaining administrator access or a shell and could operate for hours without human intervention. In one documented intrusion, the agent chained an unauthenticated SQL injection flaw into MFA bypass, administrative access, arbitrary file upload, privilege escalation, NFS access, WordPress compromise, AWS Secrets Manager extraction, and eventually access to a Magento database containing encrypted payment data.
Gambit estimated the attacker spent between $12,000 and $18,000 on AI model access across the campaign. An internal cost review recovered from the server showed an average expenditure of $25.46 per completed scan, ranging from $3.13 to $79.31 per target.

Gambit Security
Researchers also found evidence that the automation could cause destructive side effects. One Hermes skill instructed the agent to erase payment-card data from Magento databases after exfiltration. At another victim, a bicycle retailer, an overly broad cleanup routine reportedly dropped 180 database tables, including administrator-created backups.
Card-stealing JavaScript was deployed using several techniques, including modifying legitimate JavaScript bundles, injecting foreign script tags, poisoning S3-hosted content, altering database fields, modifying Kubernetes deployments, and planting cron jobs that restored malicious code after legitimate deployments removed it.
Gambit said skimmers were ordered against at least 27 named organizations and confirmed on 19 during the campaign. Working with security researcher Varys, the company also identified more than 100 additional websites carrying infrastructure-linked skimmer code.







Leave a Reply