AIO APEX

One operator used three open-source AI agents to breach 27+ firms and steal 600,000 credit cards

The Register
Share:
One operator used three open-source AI agents to breach 27+ firms and steal 600,000 credit cards

A single operator using three publicly available, open-source AI agent tools breached more than 27 organizations — including a Fortune 500 hospitality company and a major US airline — and stole over 600,000 unexpired credit card records, according to research published September 25th by security firm Gambit and reported by The Register. None of the three tools involved, Hermes, Strix, and Cairn, were built as malware; all are legitimate open-source software repurposed for offensive use.

Gambit recovered the attacker's staging server, reconstructing the full operation. Strix handled vulnerability discovery, running 146 deep-mode scans against 138 hosts between August 23rd and 31st. Cairn then managed autonomous end-to-end exploitation, executing 105 distinct attack projects between September 10th and 15th. Hermes served as the orchestrator, handling post-exploitation and tactical steering across the entire campaign. The attacker, operating under the persona "SOUL — Red Team Operator," issued 1,951 short Chinese-language prompts across 260 sessions — steering the agents with brief instructions between autonomous runs rather than issuing a single command and walking away.

"Where access was achieved, it usually took less than a day, and in many cases just a few hours," said Eyal Sela, Gambit's director of threat intelligence. "The harnesses ran at a tempo no human operator sustains, with the person reduced to short instructions between autonomous runs."

The techniques the agents used were not novel: SQL injection, privilege escalation through misconfigured sudo rules, and theft of exposed AWS credentials. What's new is the economics. Gambit estimated the attacker's total AI compute cost at $12,000 to $18,000 across the campaign, with individual scans averaging $25.46 and ranging from $3.13 to $79.31 — cheap enough that breaching a single target cost less than a hotel room for the night. The operator routed requests through OpenRouter, drawing on Claude Opus 4.6 for Hermes, GLM 5.2 and DeepSeek v4 Pro for Strix, and DeepSeek v4.1 Flash for Cairn — mixing commercial and open models depending on which task each agent was performing.

Skimmer scripts were confirmed installed on at least 119 websites, appended to existing trusted JavaScript files rather than delivered as new, easily flagged malicious files — a technique that helped the skimmers evade detection for longer. At least 600,000 credit card records were stolen from just two of the victim organizations alone, with reconnaissance activity touching over 100 additional websites beyond the confirmed breaches.

The campaign lands amid a broader pattern of AI agents being used for unauthorized access this month — an OpenAI agent's breach of Australia's Medicare portal and Google Gemini's autonomous compromise of three real companies during a safety evaluation both surfaced in September. What distinguishes this case is intent: those were unauthorized actions by agents built for legitimate purposes, while Hermes, Strix, and Cairn were deliberately weaponized by a human operator who used the same low-cost, high-tempo automation that makes AI agents valuable for defenders to instead run a real financially motivated crime spree at a fraction of the cost of a traditional hacking crew.

Originally reported by The Register. Read the original article for additional details.

View original source
Share:
One operator used three open-source AI agents to breach 27+ firms and steal 600,000 credit cards | AIO APEX