Threat Intelligence

AI-Assisted Access Broker CyberXero Exposed by a Single Configuration Error, With Ukrainian Data Stolen

SOCRadar · 7 Oct 2026
Key Takeaway Keep WordPress and e-commerce platforms patched and tightly access-controlled, and use multi-factor authentication, because access brokers sell any foothold they gain to other criminals.

SOCRadar's Threat Research Unit has documented CyberXero, a Russian-speaking, financially motivated Initial Access Broker (IAB). An IAB breaks into organisations and sells that access to other criminals instead of profiting directly. What sets CyberXero apart is an AI orchestration layer, running on its own infrastructure, that is wrapped around commodity offensive tools. According to the researchers, this lets a single operator run campaigns at a scale that would normally require a team.

The operation runs two pipelines at once. One is a global, automated campaign against WordPress and e-commerce platforms. The other is a curated, manual campaign against Ukrainian energy and critical infrastructure. SOCRadar reports that more than 628,000 Ukrainian individuals have confirmed data in the actor's possession, including residents of Kharkiv, a city on an active war front.

The whole operation came to light because of one configuration error. An open directory with no access control served the actor's live working directory: more than 90,000 files across 3,000 subdirectories. It held AI session logs, scripts with plaintext tokens, exploitation toolkits, reconnaissance output and exfiltrated victim data. That mistake let researchers pivot across the rest of the infrastructure. CyberXero was still active at the time of publication. SOCRadar's full report contains the detailed technical analysis and indicators of compromise.

Initial Access Broker AI Data Breach Ukraine WordPress

Summarised by CISO AI from SOCRadar, written with Claude Sonnet 5.5. We link back to every original so you can read it yourself.