AI-Assisted Access Broker CyberXero Exposed by a Single Configuration Error, With Ukrainian Data Stolen
SOCRadar's Threat Research Unit has documented CyberXero, a Russian-speaking, financially motivated Initial Access Broker (IAB). An IAB breaks into organisations and sells that access to other criminals instead of profiting directly. What sets CyberXero apart is an AI orchestration layer, running on its own infrastructure, that is wrapped around commodity offensive tools. According to the researchers, this lets a single operator run campaigns at a scale that would normally require a team.
The operation runs two pipelines at once. One is a global, automated campaign against WordPress and e-commerce platforms. The other is a curated, manual campaign against Ukrainian energy and critical infrastructure. SOCRadar reports that more than 628,000 Ukrainian individuals have confirmed data in the actor's possession, including residents of Kharkiv, a city on an active war front.
The whole operation came to light because of one configuration error. An open directory with no access control served the actor's live working directory: more than 90,000 files across 3,000 subdirectories. It held AI session logs, scripts with plaintext tokens, exploitation toolkits, reconnaissance output and exfiltrated victim data. That mistake let researchers pivot across the rest of the infrastructure. CyberXero was still active at the time of publication. SOCRadar's full report contains the detailed technical analysis and indicators of compromise.