Autonomous AI Agents Hack Online Retailers for $25 Per Target, Steal 600,000 Credit Cards
Operator using open-source AI agents Strix, Cairn, and Hermes compromised hundreds of retailers, stealing 600,000+ credit cards at about $25 per target.
Gambit Security uncovered an ongoing campaign, active since July 2026, in which a financially motivated operator used three open-source agents—Strix for reconnaissance, Cairn for autonomous exploitation, and Hermes for orchestration—to attack online retailers, stealing over 600,000 unexpired card records from two confirmed victims. Between September 10-15, 2026, the operator launched 105 attack projects and compromised at least 27 organizations, spending $7,005.71 via OpenRouter over four weeks with per-target costs of $3.13-$79.31. Web skimmers were injected via JavaScript bundles, Google Tag Manager blocks, database edits, and cloud content poisoning, followed by destructive cleanup including wiping payment fields and deleting 180 Magento tables. Operators issued brief Chinese-language prompts while agents autonomously performed scanning, exploitation, web-shell deployment, and data theft, with DNS exfiltration to staging infrastructure.
- 600,000+ unexpired card records stolen; 27+ organizations compromised September 10-15.
- Agents Strix, Cairn, Hermes automated recon, exploitation, skimming, and cleanup.
- Campaign cost roughly $12,000-$18,000, averaging $25.46 per completed target.
- Destructive automation wiped payment fields and deleted 180 Magento database tables.
Indicators of compromiseauto-extracted · verify before use · export allAll →
| Type | Indicator | Context |
|---|---|---|
| domain | b8t.shop | nd DNS exfiltration Domain traffic-analyzer[.]net C2 Domain b8t[.]shop Skimmer host Domain cdn[.]netlfjs[.]com Skimmer host Doma |
| domain | cdn.js-static.com | ]co Skimmer host Domain static-js[.]com Skimmer host Domain cdn[.]js-static[.]com Skimmer host Domain js-static[.]com Skimmer host Domain |
| domain | cdn.netlfjs.com | fic-analyzer[.]net C2 Domain b8t[.]shop Skimmer host Domain cdn[.]netlfjs[.]com Skimmer host Domain x1opay[.]co Skimmer host Domain sta |
| domain | jsnetlify.com | com Skimmer host Domain js-static[.]com Skimmer host Domain jsnetlify[.]com Skimmer host Domain netlifyjs[.]com Skimmer host Domain n |
| domain | js-static.com | immer host Domain cdn[.]js-static[.]com Skimmer host Domain js-static[.]com Skimmer host Domain jsnetlify[.]com Skimmer host Domain n |
| domain | medbooksource.com | IP 172.245.224.188 C2 IP 172.245.89.137 Skimmer host Domain medbooksource[.]com Operator console, OOB and DNS exfiltration Domain traffic |
Full article714 words · extracted from gbhackers.com · click to collapse
A financially motivated threat actor used open-source autonomous AI agents to target hundreds of online retailers, stealing over 600,000 unexpired credit card records.
The average cost per completed target is estimated at $25.46. This campaign, uncovered by Gambit Security, has been active since July 2026 and is still ongoing.
Gambit Security reported that it recovered the operator’s staging infrastructure and reconstructed an operation that automated key activities such as vulnerability discovery, exploitation, data theft, payment card skimming, and, in some cases, destructive cleanup actions.
Between September 10 and 15 alone, the operator launched 105 attack projects and compromised at least 27 organizations to varying degrees.
AI-Driven Attack Chain
The campaign combined three open-source agent tools:
| AI harness | Role in campaign | Reported activity |
|---|---|---|
| Strix | Vulnerability discovery and reconnaissance | Conducted deep-mode scanning and generated reports for follow-on exploitation |
| Cairn | Autonomous exploitation | Pursued objectives such as shell access or administrative access over hours |
| Hermes | Orchestration and operator interface | Launched jobs, retained persistent context, and directed impact-stage actions |
The human operator reportedly used brief prompts in Chinese to initiate attacks, direct deeper investigations, request web-shell access, validate exploitation paths, and deploy skimmer JavaScript. The agents then performed much of the technical work autonomously, enabling attacks on multiple targets daily.
Gambit stated that the operator relied on OpenRouter for model access and incurred recorded spending of $7,005.71 over four weeks. Based on increased activity afterward, researchers estimated the overall campaign cost to be between $12,000 and $18,000, with the cost per completed target ranging from $3.13 to $79.31.
Researchers confirmed the theft of over 600,000 card records from two victims. The actor employed various techniques to deploy web skimmers, including appending loaders to legitimate JavaScript bundles, inserting third-party script tags into checkout flows, modifying Google Tag Manager blocks, poisoning cloud-hosted content, altering database content, and creating persistence mechanisms.
The investigation also unveiled instances of destructive automation. One Hermes skill commanded the agent to wipe payment card fields in Magento databases after exfiltration. In another case, cleanup activity deleted 180 tables that matched broad deletion criteria, including backup tables created by the victims’ administrators.

This raises risks beyond fraud and data theft: autonomous intrusion tools can cause operational outages or irreversible data loss through an attacker’s cleanup logic.
This activity demonstrates how AI-assisted operations can significantly reduce the time between exposure and compromise. Instead of relying on a large team of operators, a threat actor can assign agents specific goals, allowing them to probe targets autonomously and intervene only with brief tactical instructions.
For online retailers, immediate priorities should include monitoring checkout and JavaScript changes, restricting access to administrative and cloud storage, rotating exposed credentials, reviewing Magento payment data protections, and validating recovery procedures for production databases and payment workflows.
Organizations should also search for unauthorized external script loads, recently modified web bundles, suspicious cron jobs, anomalous database exports, and unauthorized access to cloud secrets.
IoC
| Type | IOC | Context |
|---|---|---|
| IP | 155.254.22.215 | Staging and command server; AI console |
| IP | 209.126.4.170 | DNS exfiltration, catch-all mail, HTTP listeners |
| IP | 213.21.239.62 | C2 |
| IP | 172.245.224.188 | C2 |
| IP | 172.245.89.137 | Skimmer host |
| Domain | medbooksource[.]com | Operator console, OOB and DNS exfiltration |
| Domain | traffic-analyzer[.]net | C2 |
| Domain | b8t[.]shop | Skimmer host |
| Domain | cdn[.]netlfjs[.]com | Skimmer host |
| Domain | x1opay[.]co | Skimmer host |
| Domain | static-js[.]com | Skimmer host |
| Domain | cdn[.]js-static[.]com | Skimmer host |
| Domain | js-static[.]com | Skimmer host |
| Domain | jsnetlify[.]com | Skimmer host |
| Domain | netlifyjs[.]com | Skimmer host |
| Domain | newssjs[.]com | Skimmer host |
| URL | b8t[.]shop/js/sby.js | Skimmer payload |
| URL | cdn[.]netlfjs[.]com/js/cts.js | Skimmer payload |
| URL | cdn[.]netlfjs[.]com/js/vla.js | Skimmer payload |
| URL | x1opay[.]co/js/eut.js | Skimmer payload |
| URL | x1opay[.]co/js/l.js | Skimmer payload |
| URL | static-js[.]com/js/bmws.js | Skimmer payload |
| URL | static-js[.]com/js/nrt.js | Skimmer payload |
| URL | cdn[.]js-static[.]com/js/tgo.js | Skimmer payload |
| URL | cdn[.]js-static[.]com/js/pps.js | Skimmer payload |
| Code pattern | new Function(atob('<random>...'.slice(7)))() | Skimmer insertion technique using a seven-character junk prefix |
| Service | IPRoyal | Proxy provider used against targets |
| Service | 711proxy | Proxy provider used against targets |
| Service | 1024proxy | Proxy provider used against targets |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC
Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.