CyberXero Combines Claude Code, PentAGI and Cobalt Strike in AI-Augmented Cyberattacks
CyberXero used Claude Code, PentAGI and Cobalt Strike to breach sites and steal Ukrainian data.
SOCRadar says Russian-speaking initial-access broker CyberXero combined Claude Code agents, PentAGI and Cobalt Strike against WordPress and e-commerce sites and Ukrainian energy and utility organizations. An exposed directory of more than 90,000 files showed one run scanning 4,708 targets, finding 429 WordPress admin panels and deploying 32 shells. Confirmed stolen data included more than 628,000 Ukrainian residents and 564,073 records from a Kharkiv heating provider. The actor exploited Support Board CVE-2026-4815 within 30 days of disclosure and tried to bypass Claude refusals by claiming targets were authorized test systems.