Russian-Speaking CyberXero Uses AI Agent Swarm to Attack Ukrainian Energy Infrastructure
CyberXero used WordPress exploits and Claude agents against Ukrainian energy targets, stealing hundreds of thousands of records.
SOCRadar says CyberXero, a Russian-speaking initial access broker, combined WordPress exploitation, Cobalt Strike, and Claude Code agents while targeting Ukrainian energy organizations. An exposed server held more than 90,000 files, including reconnaissance data, tokens, and victim exports. Confirmed theft included 564,073 subscriber records from a Kharkiv heating provider, with stolen data tied to more than 628,000 Ukrainians across four organizations. Researchers reported Support Board exploitation via CVE-2026-4815 but no confirmed electricity disruption or completed access sale.