CyberXero AI-Augmented Attacks Hit Ukrainian Energy Targets
Reporting citing SOCRadar says broker CyberXero used AI agents and WordPress exploits to steal Ukrainian utility data.
SOCRadar's Threat Research Unit documented CyberXero as a Russian-speaking, financially motivated initial access broker described as AI-augmented and focused on Ukrainian critical infrastructure. Later coverage citing SOCRadar is more specific, saying the group targeted Ukrainian energy and utility organizations as well as WordPress, Magento, and e-commerce sites using WordPress exploitation, WSO webshells, Cobalt Strike, PentAGI, and Claude Code agents, including fifty-one agents in one account. An exposed directory of more than 90,000 files reportedly included reconnaissance data, tokens, and victim exports; one described run scanned 4,708 targets, found 429 WordPress admin panels, and deployed 32 shells. Confirmed theft included 564,073 subscriber records from a Kharkiv heating provider, with stolen data tied to more than 628,000 Ukrainians across four organizations, though one report phrases the same figure as more than 628,000 Ukrainian residents. Researchers linked Support Board exploitation to CVE-2026-4815, with one account saying it occurred within 30 days of disclosure, and said there was no confirmed electricity disruption or completed access sale. The earliest account did not name victims, malware, or CVEs, while later reports add those details and say the operator tried to bypass Claude refusals by claiming targets were authorized test systems.
- SOCRadar's Threat Research Unit documented CyberXero as a Russian-speaking, financially motivated initial access broker described as AI-augmented and aimed at Ukrainian critical infrastructure.
- Later reports citing SOCRadar say the group used WordPress exploitation, WSO webshells, Cobalt Strike, PentAGI, and Claude Code agents, including fifty-one agents.
- Targets are described as Ukrainian energy and utility organizations plus WordPress, Magento, and e-commerce sites.
- An exposed server or directory held more than 90,000 files; one reported run scanned 4,708 targets, found 429 WordPress admin panels, and deployed 32 shells.
- Confirmed theft included 564,073 subscriber records from a Kharkiv heating provider and data tied to more than 628,000 Ukrainians across four organizations.
- Support Board exploitation was linked to CVE-2026-4815, with one account saying it occurred within 30 days of disclosure.
- Researchers reported no confirmed electricity disruption or completed access sale.
- One report says the operator tried to bypass Claude refusals by claiming targets were authorized test systems.
Coverage timelineoldest first · each row is one article
- · 2d agoCyberXero: An AI-Augmented Initial Access Broker Targeting Ukrainian Critical Infrastructure
SOCRadar· 74
SOCRadar documents CyberXero, an AI-augmented initial access broker targeting Ukrainian critical infrastructure.
- · 1d agoRussian-Speaking CyberXero Uses AI Agent Swarm to Attack Ukrainian Energy Infrastructure
GBHackers· 84
CyberXero used WordPress exploits and Claude agents against Ukrainian energy targets, stealing hundreds of thousands of records.
- · 1d agoCyberXero Combines Claude Code, PentAGI and Cobalt Strike in AI-Augmented Cyberattacks
Cyber Security News· 82
Vulnerabilities in this storyAll →
- CVE-2026-48158.7<1%A SQL Injection vulnerability has been found in Support Board v3.7.7published · schiocco support board
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-4815 | A SQL Injection vulnerability has been found in Support Board v3.7.7 A SQL Injection vulnerability has been found in Support Board v3.7.7. This vulnerability allows an attacker to retrieve, create, update and delete database via 'calls[0][message_ids][]' parameter in '/supportboard/include/ajax.php' endpoint. NVD description · AI analysis pending |