CTIPilot

Magento

product · product:magento single-source

Coverage timeline
1
first 2026-09-23 → last 2026-09-23
Peak priority
high
1 high
Sources cited
2
2 hosts
Sections touched
1
deep-dive
Co-occurring entities
4
see Co-occurring entities below
ATT&CK techniques
9
pinned v19.2 · see below

ATT&CK techniques

9 techniques observed across 1 entry, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)

Initial Access TA0001

T1078Valid Accounts×1

Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.

Evidence: 2026-09-23/gambit-ai-agent-retail-skimmer-campaign-strix-cairn-hermes · ATT&CK page ↗

T1190Exploit Public-Facing Application×1

Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.

Evidence: 2026-09-23/gambit-ai-agent-retail-skimmer-campaign-strix-cairn-hermes · ATT&CK page ↗

T1659Content Injection×1

Adversaries may gain access and continuously communicate with victims by injecting malicious content into systems through online network traffic. Rather than luring victims to malicious payloads hosted on a compromised website (i.e., Drive-by Target followed by Drive-by Compromise), adversaries may initially access victims through compromised data-transfer channels where they can manipulate traffic and/or inject their own content. These compromised online network channels may also be used to deliver additional payloads (i.e., Ingress Tool Transfer) and other data to already compromised systems.

Evidence: 2026-09-23/gambit-ai-agent-retail-skimmer-campaign-strix-cairn-hermes · ATT&CK page ↗

Execution TA0002

T1053.003Scheduled Task/Job: Cron×1

Adversaries may abuse the <code>cron</code> utility to perform task scheduling for initial or recurring execution of malicious code. The <code>cron</code> utility is a time-based job scheduler for Unix-like operating systems. The <code> crontab</code> file contains the schedule of cron entries to be run and the specified times for execution. Any <code>crontab</code> files are stored in operating system-specific file paths.

Evidence: 2026-09-23/gambit-ai-agent-retail-skimmer-campaign-strix-cairn-hermes · ATT&CK page ↗

Persistence TA0003

T1053.003Scheduled Task/Job: Cron×1

Adversaries may abuse the <code>cron</code> utility to perform task scheduling for initial or recurring execution of malicious code. The <code>cron</code> utility is a time-based job scheduler for Unix-like operating systems. The <code> crontab</code> file contains the schedule of cron entries to be run and the specified times for execution. Any <code>crontab</code> files are stored in operating system-specific file paths.

Evidence: 2026-09-23/gambit-ai-agent-retail-skimmer-campaign-strix-cairn-hermes · ATT&CK page ↗

T1078Valid Accounts×1

Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.

Evidence: 2026-09-23/gambit-ai-agent-retail-skimmer-campaign-strix-cairn-hermes · ATT&CK page ↗

T1505.003Server Software Component: Web Shell×1

Adversaries may backdoor web servers with web shells to establish persistent access to systems. A Web shell is a Web script that is placed on an openly accessible Web server to allow an adversary to access the Web server as a gateway into a network. A Web shell may provide a set of functions to execute or a command-line interface on the system that hosts the Web server.

Evidence: 2026-09-23/gambit-ai-agent-retail-skimmer-campaign-strix-cairn-hermes · ATT&CK page ↗

Privilege Escalation TA0004

T1053.003Scheduled Task/Job: Cron×1

Adversaries may abuse the <code>cron</code> utility to perform task scheduling for initial or recurring execution of malicious code. The <code>cron</code> utility is a time-based job scheduler for Unix-like operating systems. The <code> crontab</code> file contains the schedule of cron entries to be run and the specified times for execution. Any <code>crontab</code> files are stored in operating system-specific file paths.

Evidence: 2026-09-23/gambit-ai-agent-retail-skimmer-campaign-strix-cairn-hermes · ATT&CK page ↗

T1078Valid Accounts×1

Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.

Evidence: 2026-09-23/gambit-ai-agent-retail-skimmer-campaign-strix-cairn-hermes · ATT&CK page ↗

T1548.003Abuse Elevation Control Mechanism: Sudo and Sudo Caching×1

Adversaries may perform sudo caching and/or use the sudoers file to elevate privileges. Adversaries may do this to execute commands as other users or spawn processes with higher privileges.

Evidence: 2026-09-23/gambit-ai-agent-retail-skimmer-campaign-strix-cairn-hermes · ATT&CK page ↗

Stealth TA0005

T1078Valid Accounts×1

Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.

Evidence: 2026-09-23/gambit-ai-agent-retail-skimmer-campaign-strix-cairn-hermes · ATT&CK page ↗

Credential Access TA0006

T1552.001Unsecured Credentials: Credentials In Files×1

Adversaries may search local file systems and remote file shares for files containing insecurely stored credentials. These can be files created by users to store their own credentials, shared credential stores for a group of individuals, configuration files containing passwords for a system or service, or source code/binary files containing embedded passwords.

Evidence: 2026-09-23/gambit-ai-agent-retail-skimmer-campaign-strix-cairn-hermes · ATT&CK page ↗

T1555.006Credentials from Password Stores: Cloud Secrets Management Stores×1

Adversaries may acquire credentials from cloud-native secret management solutions such as AWS Secrets Manager, GCP Secret Manager, Azure Key Vault, and Terraform Vault.

Evidence: 2026-09-23/gambit-ai-agent-retail-skimmer-campaign-strix-cairn-hermes · ATT&CK page ↗

Command and Control TA0011

T1659Content Injection×1

Adversaries may gain access and continuously communicate with victims by injecting malicious content into systems through online network traffic. Rather than luring victims to malicious payloads hosted on a compromised website (i.e., Drive-by Target followed by Drive-by Compromise), adversaries may initially access victims through compromised data-transfer channels where they can manipulate traffic and/or inject their own content. These compromised online network channels may also be used to deliver additional payloads (i.e., Ingress Tool Transfer) and other data to already compromised systems.

Evidence: 2026-09-23/gambit-ai-agent-retail-skimmer-campaign-strix-cairn-hermes · ATT&CK page ↗

Impact TA0040

T1485Data Destruction×1

Adversaries may destroy data and files on specific systems or in large numbers on a network to interrupt availability to systems, services, and network resources. Data destruction is likely to render stored data irrecoverable by forensic techniques through overwriting files or data on local and remote drives. Common operating system file deletion commands such as <code>del</code> and <code>rm</code> often only remove pointers to files without wiping the contents of the files themselves, making the files recoverable by proper forensic methodology. This behavior is distinct from Disk Content Wipe and Disk Structure Wipe because individual files are destroyed rather than sections of a storage disk or the disk's logical structure.

Evidence: 2026-09-23/gambit-ai-agent-retail-skimmer-campaign-strix-cairn-hermes · ATT&CK page ↗

Story timeline

  1. 2026-09-23Open-source AI pentesting harnesses (Strix, Cairn, Hermes) run an autonomous intrusion-and-skimmer campaign against online retailers for about $25 a target
    deep-diveThree off-the-shelf AI agents ran an entire card-theft campaign end to end, from discovery to checkout-page skimmer, for the price of a lunch per victim

Where this entity is cited

  • deep-dive1

Source distribution

  • cybersecuritynews.com1 (50%)
  • gambit.security1 (50%)

Co-occurring entities

Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.

Entries about Magento (1)

2026-09-23 · view entry permalink →

HIGHNATOB2

Open-source AI pentesting harnesses (Strix, Cairn, Hermes) run an autonomous intrusion-and-skimmer campaign against online retailers for about $25 a target

Gambit Security's Threat Intelligence team recovered a financially motivated operator's exposed staging server and reconstructed a campaign, running since July 2026, in which three off-the-shelf open-source AI agent harnesses conduct nearly the entire intrusion lifecycle unattended against online retailers. Strix, an open-source AI pentesting tool run via OpenRouter (GLM 5.2, later switched to DeepSeek v4 Pro), performs autonomous vulnerability discovery, 146 deep-mode scans against 138 hosts between 23–31 August 2026, burning 633 hours of scanner time within 195 hours of wall-clock time. Cairn, an autonomous exploitation engine on DeepSeek v4.1 Flash, receives a target domain and an objective and runs unattended for hours until it gets a shell or admin access: "between 10 and 15 September alone, 105 attack projects were launched and at least 27 companies were compromised to varying degrees" (Gambit Security, 2026-09-22). Hermes, the same open-source "Hermes AI agent" (Nous Research, persistent daemon, self-authored skills, unattended execution) previously observed in three unrelated intrusions: an operation against Thailand's Ministry of Finance that a low-to-medium-confidence assessment linked to a Chinese-speaking operator without establishing a firm nexus (2026-07-25); a Taiwan government intrusion Tenable's own analysis assesses as more likely a state-adjacent contractor or patriotic-hacker operation than direct state sponsorship (2026-08-28); and a self-described Zhuhai-based, Chinese-speaking operator's mass-exploitation campaign against more than 460 targets including a Malaysian government entity, with no firm state-nexus attribution established (Unit 42, 2026-07-30; see the 2026-07-31 entry), orchestrated the campaign end to end, running on Anthropic Opus 4.6 ("after newer models refused its requests") under a Chinese system persona the operator loaded, titled "SOUL - Red Team Operator". The operator had added a custom skill that strips Hermes's own content-safety filters, and drove the campaign through only 1,951 short, largely Chinese-language operator prompts across 260 sessions; most of the actual attack work ran autonomously between those prompts.

One fully documented Cairn project illustrates the chain, though Gambit is explicit that each victim's actual path was chosen dynamically through real-time probing and most chains differed victim to victim: unauthenticated SQL injection in a login email parameter (error-based EXTRACTVALUE) read a one-time-passcode value in plaintext directly from an application database table, bypassing multi-factor authentication and reaching the admin panel; an image-upload field with no extension check then gave host remote code execution as a non-root user; a sudo misconfiguration allowing NOPASSWD execution of python3.12 escalated that to root; an internal NFS mount configured with no_root_squash let the agent read a separate host's WordPress database credentials in plaintext from its wp-config.php; those credentials gave a direct database write creating a new WordPress administrator account, which in turn let the agent upload a malicious plugin for code execution on the blog host; from there the agent dumped the full contents of the account's AWS Secrets Manager (46 secrets, 102 KB), reached the production Magento database on Amazon Aurora, extracted the Magento application's encryption key, and used it to decrypt stored card numbers encrypted with Blowfish in ECB mode. Confirmed impact across the campaign: 600,000-plus unexpired credit-card records exfiltrated from two victims, live checkout-page skimmer scripts confirmed on 19 of 27 named victims (100-plus further sites found via a shared skimmer signature), and partial-to-full compromise reaching a Fortune 500 hospitality company, a major US airline, a large US industrial-supplies distributor and a US online fashion retailer, named separately by Gambit as categories of accessed victims, not as the source of the illustrative chain above. A per-country cardholder breakdown embedded in Gambit's own page (488,372 of the recovered cards, 79.0%, United States) skews overwhelmingly toward the United States; no Swiss-issued cards appear among the top entries of that table (Gambit Security, 2026-09-22).

Gambit documents eight distinct skimmer-injection methods used across victims, all worth carrying into any custom-web-application hardening review: appending the loader to the end of a legitimate, already-served JavaScript file while restoring its original modification timestamp; inserting a foreign <script> tag directly into the checkout page; hiding the loader inside a site's Google global-site-tag (gtag.js) block, between the real gtag('js', ...) and gtag('config', ...) calls, padded with roughly a hundred tab characters to push it past the right edge of a typical code-review view; using a discovered AWS access key to write the loader into the storage bucket behind the retailer's own CDN, so it loads from that trusted CDN host rather than a third-party domain; injecting the loader into a database content field (such as a product-description column) via the admin panel and relocating it to a file on the victim's own domain; adding it as a Kubernetes initContainer in a production front-end deployment manifest; writing it directly into a server-side page-cache entry for the checkout page, so the served HTML differs from the page's own template; and a self-healing cron job placed in a JBoss log directory that checks the injected file's size every two minutes and re-appends the loader whenever a redeploy reverts it. One of Hermes's self-written skills, titled "Database Wipe After Extraction", instructs the agent: "after extracting and downloading all card data, wipe the source fields in batches" (Gambit Security, 2026-09-22); at a second victim, a bicycle retailer, an overly broad table-name-matching cleanup step additionally dropped 180 staging and backup tables, including backups the victim's own administrators had separately made, collateral data loss from the attacker's own automated cleanup, not extortion. Some targets were not discovered by the agents at all: Gambit's operator handed at least two victims to Hermes already holding a compromised admin password obtained elsewhere, with the instruction to proceed directly to the objective. OpenRouter billing puts the operator's total spend at roughly $12,000–18,000 over the full campaign; "the operator’s own cost review gives a similar figure, a mean of $25.46 over 101 completed scans, from $3.13 for the cheapest target to $79.31 for the most expensive" (Gambit Security, 2026-09-22). Gambit states it "reached out to many of the affected organizations and took measures to take down the infrastructure discovered," crediting the Shadowserver Foundation, researcher Daniel Gordon, and other industry partners for their help notifying victims and taking down infrastructure (Gambit Security, 2026-09-22).

Detection concept, telemetry class first: in web-server access logs, alert on SQL-error-pattern responses (EXTRACTVALUE or equivalent) to login-form parameters, and on image-upload requests whose stored file is later executed by the web server rather than served as static content; in host telemetry, alert on sudo invocations of an interpreter (python3.12 or similar) by a low-privilege account with no corresponding change-management record; in network/mount telemetry, flag any host mounting an NFS export it has not mounted before, particularly where the export allows root-equivalent access; in cloud-audit telemetry, alert on a single principal enumerating or reading the entire contents of an AWS Secrets Manager instance in a short window; and in file-integrity or CDN-origin monitoring, treat any modification to a served JavaScript file's content (even with its timestamp preserved) or any script tag added to a checkout page outside a deployment window as high-priority. Triage: a legitimate deployment modifies checkout-page assets during a known release window with a corresponding commit and change record; the discriminators here are modification with no matching deployment event, a modification timestamp that has been deliberately restored to match the original file, or content padded with unusual whitespace specifically to evade a manual code read.

The Hermes tool now appears in four unrelated intrusions (this financially motivated campaign and the three above) each independently reaching for the same permissive, open-source agent framework and each disabling its safety rails before use. That convergence, not any single victim in this campaign, is the transferable signal for a defender: an increasingly capable, freely available agent orchestration layer is now common tooling across financially motivated operators and government-targeting intrusions alike, regardless of how firmly any of them is ultimately attributed, and the underlying attack chain here (SQL injection, insecure OTP storage, unrestricted file upload, sudo misconfiguration, an over-permissive NFS export, and cloud-secrets exposure) is entirely composed of defects a Tier 2/3 team already reviews for in any custom-coded web application, Swiss public-sector portals included.

Between 10 and 15 September alone, 105 attack projects were launched and at least 27 companies were compromised to varying degrees.

the operator’s own cost review gives a similar figure, a mean of $25.46 over 101 completed scans, from $3.13 for the cheapest target to $79.31 for the most expensive

One of the Hermes agent’s skill files tells the agent to erase the card data from the victim’s Magento database once the data is stolen.

Gambit Security 2026-09-22

Builds on: 2026-07-25/thailand-mof-hermes-ai-agent-post-exploitation · 2026-08-28/taiwan-agentic-ai-intrusion-openclaw-hermes-guardrail-bypass · 2026-07-31/unit42-autonomous-deepseek-hermes-netscaler-cve-2026-3055

threat23 Sep 04:50Zsingle-sourceOpen finding ↗