This website uses cookies
We use cookies to personalise content and ads, to provide social media features and to analyse our traffic. We also share information about your use of our site with our social media, advertising and analytics partners who may combine it with other information that you’ve provided to them or that they’ve collected from your use of their services.
Consent Selection
Details
  • Necessary cookies help make a website usable by enabling basic functions like page navigation and access to secure areas of the website. The website cannot function properly without these cookies.
  • Preference cookies enable a website to remember information that changes the way the website behaves or looks, like your preferred language or the region that you are in.
    • We do not use cookies of this type.

  • Statistic cookies help website owners to understand how visitors interact with websites by collecting and reporting information anonymously.
    • We do not use cookies of this type.

  • Marketing cookies are used to track visitors across websites. The intention is to display ads that are relevant and engaging for the individual user and thereby more valuable for publishers and third party advertisers.
    • We do not use cookies of this type.

  • Unclassified cookies are cookies that we are in the process of classifying, together with the providers of individual cookies.
    • __emg_sidPending
      Maximum Storage Duration: 1 dayType: HTTP Cookie
      __emg_vidPending
      Maximum Storage Duration: 1 yearType: HTTP Cookie
      nl-read-countPending
      Maximum Storage Duration: PersistentType: HTML Local Storage
Cookie declaration last updated on 8/12/26 by Cookiebot
[#IABV2_TITLE#]
[#IABV2_BODY_INTRO#]
[#IABV2_BODY_LEGITIMATE_INTEREST_INTRO#]
[#IABV2_BODY_PREFERENCE_INTRO#]
[#IABV2_BODY_PURPOSES_INTRO#]
[#IABV2_BODY_PURPOSES#]
[#IABV2_BODY_FEATURES_INTRO#]
[#IABV2_BODY_FEATURES#]
[#IABV2_BODY_PARTNERS_INTRO#]
[#IABV2_BODY_PARTNERS#]
About
Cookies are small text files that can be used by websites to make a user's experience more efficient.

The law states that we can store cookies on your device if they are strictly necessary for the operation of this site. For all other types of cookies we need your permission.

This site uses different types of cookies. Some cookies are placed by third party services that appear on our pages.

You can at any time change or withdraw your consent from the Cookie Declaration on our website.

Learn more about who we are, how you can contact us and how we process personal data in our Privacy Policy.

Please state your consent ID and date when you contact us regarding your consent.
NewsLayer.com
NewsLayer PulseLIVEBTC$71,656+8.75%ETH$2,277+15.65%SOL$86.45+7.01%XRP$1.24+20.10%DOGE$0.0779+9.38%ADA$0.196+11.17%Total Cap$2.55T+9.43%Layer Index80 Extreme Greed

AI 代理驱动的攻击行动:暴露的攻击者开放目录揭示了导致大规模钱包和凭证泄露的自主加密货币盗窃活动

AI 代理驱动的攻击行动:暴露的攻击者开放目录揭示了导致大规模钱包和凭证泄露的自主加密货币盗窃活动 CloudSEK

CloudSEK

Publisher

Aug 19, 2026 at 1:56 PM UTC · Updated 8 小时前 · 22 分钟阅读

AI 代理驱动的攻击行动:暴露的攻击者开放目录揭示了导致大规模钱包和凭证泄露的自主加密货币盗窃活动
NewsLayer editorial artwork

执行摘要

CloudSEK 的全球威胁情报团队发现了一个暴露的开放目录,该目录属于一名受经济利益驱动、讲中文的攻击性操作员。该操作员通过运行由商业和开源 AI 编码代理组成的舰队,将其入侵行为工业化,形成了一个自主黑客团队。该目录向公共互联网公开了操作员完整的个人工作主文件夹,揭露了两个并行运动背后的工具、方法、凭据和窃取的数据:全网机会性漏洞利用以及针对加密货币和 DeFi 组织的针对性窃取。

  • 自主 AI 攻击舰队:该操作员在全自动模式下驱动多个 AI 编码代理(Claude Code、Codex 以及开源的 Hermes 和 pi 代理),禁用了所有安全审批,并完全通过 Telegram 对其进行任务分配和监控。从代理自身的会话记录中恢复的人工输入提示词显示,操作员使用了一个可重复使用的中文“授权渗透测试”模板作为越狱包装器,实际上并无真实授权。
  • 已确认的大规模入侵:工作文件中包含超过 12,000 条真实的 WordPress 后门记录(每条都是攻击者创建的唯一管理员账户)、一套单独的 66 组真实获取的(非后门)数据库管理员凭据,以及由自动化 WordPress 到 WebShell 漏洞利用流水线产生的 340 万个主机侦察语料库。
  • 直接持有钱包私钥和助记词:该操作员持有数百个终端用户加密货币钱包的私钥、助记词和实时余额。这些材料的大部分是从一个配置错误的钓鱼克隆网络云数据库中在无需身份验证的情况下抓取的(用户是该钓鱼行动的受害者),而较少的一组密钥材料是直接从其自身目标中获取的。此外,他还单独持有多个经过验证的加密货币交易所、DeFi 协议和区块链基础设施提供商的实时 API 密钥和管理员令牌。
  • 区块链 C2 和加密货币劫持:该操作员正在开发一种 EtherHiding 风格的、抗下架的命令与控制(C2)系统,该系统将命令隐藏在公共区块链上;此外,他还在受感染的主机上部署伪装的门罗币(Monero)挖矿程序,以获取持续的非法收益。

分析

根据文件修改时间、Shell 历史记录和代理会话记录重建,观察到的活动窗口为 2026 年 7 月 10 日至 7 月 28 日,高峰出现在 7 月 12 日至 13 日左右。

大约三周活动窗口的简图,从大规模加密货币和 DeFi 扫描,到钱包密钥整合,再到区块链 C2 开发。

  • 7 月 10 日至 13 日,大规模针对性行动:自动化报告生成最密集的阶段,每天进行数十次针对加密货币和 DeFi 的扫描,以及最早恢复的针对指定目标的代理任务分配。
  • 7 月 13 日前后,挖矿设置:构建并测试门罗币挖矿程序,随后将二进制文件推送至工作主机。
  • 7 月 16 日至 20 日,大规模运动趋于成熟:WordPress 大规模漏洞利用流水线扩大规模,同时出现了来自针对性交易机器人生态系统和开放云数据库的最强钱包窃取证据。
  • 7 月 20 日至 23 日,战利品整合:将钱包私钥和助记词整合进组合数据集,并生成敏感数据扫描报告。
  • 7 月 25 日至 28 日,C2 开发:编写区块链命令与控制研究论文和项目,部署挖矿程序,并继续进行 WordPress 监控。最后的 Shell 历史记录写入时间为 7 月 28 日。

Article Intelligence

Sponsored

Ad
House — Advertise on NewsLayer
NewsLayerLearn more

NewsLayer Premium

Unlock deeper intelligence.

Ad-free reading, exclusive research, and real-time onchain insights.

Go Premium