
A financially motivated threat actor is using open-source AI agent frameworks to attack hundreds of online retailers at scale, stealing more than 600,000 credit card records.
The campaign has been active since at least July and is ongoing as of September 22. In just five days, the threat actor compromised at least 27 companies and launched more than 100 attacks.
Despite the broad targeting, findings from cybersecurity startup Gambit indicate that the attacker stole more than 600,000 valid card details from two companies and deployed skimmer malware on the websites of five other organizations to collect payment data.
The researchers say that the campaign is powered by three AI tools to execute the attack chain against tens of companies every day:
- Strix — penetration testing framework for scanning and vulnerability discovery
- Cairn — autonomous exploitation engine, tasked with objectives such as obtaining a shell or admin access. It should not be confused with the same-name AI malware analysis tool Cisco Talos released yesterday
- Hermes — for campaign orchestration, post-exploitation work, tactical decisions, and directing the malicious activity using claude-opus-4.6
Strix ran 146 times against 138 hosts between August 23 and 31, accumulating 633 scanning hours, the researchers found.
Hermes contained a persona called “SOUL – Red Team Operator” and 121 skills, including 78 attack-related skills.
The researchers report that the human operator, who appears to be Chinese, gave the AI agents brief instructions on the operation’s goals, then let them handle the rest.
Between September 10 and 15, the attacker reportedly launched 105 distinct attack waves, succeeding to varying degrees on at least 27.

Source: Gambit
The skimmers were injected into target websites using various methods that depended on the level of access, identified vulnerabilities, and architecture.
Observed methods include appending malicious code to legitimate JavaScript files, adding script tags to checkout pages or Google tag blocks, poisoning S3/CDN content and server-side caches, modifying database fields, altering Kubernetes deployments, and using cron jobs to restore the skimmer after it was removed.

Source: Gambit
Gambit researchers gained access to a staging server operated by the attacker and retrieved direct evidence.
In total, the campaign has compromised at least 119 websites with credit card skimmers, and the threat actors breached large organizations such as a Fortune 500 hospitality company, a major U.S. airline, a large U.S. industrial supplies distributor, and an online fashion retailer.
The attacker used a website traffic-ranking service to find valuable targets in the list Strix produced and prioritized those running custom software, presumably because they were more likely to be vulnerable.

Source: Gambit
During the investigation, Gambit researchers discovered that the attacker instructed the AI agent to run cleanup procedures that removed card data from Magento databases after exfiltration.
The instruction is present in one of the Hermes agent’s skill files: “After extracting and downloading all card data, wipe the source fields in batches.”
This caused operational disruptions at several retailers due to data losses, the researchers note.
Low per-target costs
Gambit researchers also gained insight into the costs for running this operation. They found an OpenRouter account showing $7,005.71 spent over roughly four weeks as of August 25.
Based on subsequent usage, the researchers estimate the total costs between $12,000 and $18,000. This adds up to an average cost of $25 for each target.
“Spread over the companies attacked, this is a marginal cost of a few US dollars to a few tens of US dollars for each targeted company,” Gambit explains.
“The operator’s own cost review gives a similar figure, a mean of $25.46 over 101 completed scans, from $3.13 for the cheapest target to $79.31 for the most expensive.”
The researchers say that automation and low cost make it easy for threat actors, even less skilled ones, to deploy such attacks. In many cases, access was obtained in just a few hours, with AI tools doing the work based on short instructions the operator provided between autonomous runs.
Gambit warn that organization looking to defend against this type of attack should also plan against potential data loss as a side effect of the attacker’s cleanup routine.
Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.

