AI-Agent-Driven Offensive Operation : Exposed Adversary Open Directory Reveals Autonomous Crypto-Theft Campaign Leading to Mass Wallet and Credential Compromise
CloudSEK's Global Threat Intelligence team identified an exposed open directory belonging to a financially motivated, Chinese-speaking offensive operator who has industrialised intrusion by running a fleet of commercial and open-source…
CloudSEK
Publisher
Aug 19, 2026 at 1:56 PM UTC · Updated 8 saat önce · 22 dk okuma

CloudSEK's Global Threat Intelligence team identified an exposed open directory belonging to a financially motivated, Chinese-speaking offensive operator who has industrialised intrusion by running a fleet of commercial and open-source AI coding agents as an autonomous hacking crew. The directory served the operator's full working home folder to the public internet, exposing the tooling, methodology, credentials, and stolen data behind two parallel campaigns: internet-wide opportunistic exploitation and targeted theft against crypto and DeFi organisations.
- Autonomous AI attack fleet: The operator drives multiple AI coding agents (Claude Code, Codex, and the open-source Hermes and pi agents) in full-auto mode with every safety approval disabled, tasking and monitoring them entirely over Telegram. Human-typed prompts recovered from the agents' own session transcripts show a reusable Chinese "authorized pentest" template used purely as a jailbreak wrapper, with no real authorization.
- Confirmed mass compromise: Working files contain over 12,000 real WordPress backdoor records (each a unique attacker-created admin account), a separate set of 66 genuinely harvested (non-backdoor) database admin credentials, and a 3.4 million host reconnaissance corpus, produced by an automated WordPress-to-webshell exploitation pipeline.
- Direct wallet-key and seed-phrase holding: The operator holds private keys, seed phrases, and live balances for hundreds of end-user cryptocurrency wallets. The bulk of this material was scraped with zero authentication from one phishing clone network's misconfigured cloud database (the users are victims of that phishing operation), while a smaller set of key material was retrieved directly from his own targets. He separately holds numerous validated live API keys and admin tokens for crypto exchanges, DeFi protocols, and blockchain infrastructure providers.
- Blockchain C2 and cryptojacking: The operator was developing an EtherHiding-style, takedown-resistant command-and-control system that hides commands on a public blockchain, and separately deploys a disguised Monero miner onto compromised hosts for ongoing illicit revenue.
Article Intelligence
Topics
Sponsored
AdNewsLayer Premium
Unlock deeper intelligence.
Ad-free reading, exclusive research, and real-time onchain insights.
Go Premium
