
Cybersecurity company Gambit revealed a large-scale electronic campaign that uses artificial intelligence tools and agents to target stores and websites. This resulted in the theft of more than 600,000 credit card data and the hacking of at least 119 websites.
Investigations revealed that the campaign was supported by a financially motivated entity that relied on open source frameworks for artificial intelligence agents. The attacks led to the theft of more than 600,000 valid cards from two companies, as well as the implantation of malware to steal payment data on the websites of five other institutions.
The campaign relies on three main tools: the “Strix” tool, which is dedicated to scanning systems and discovering vulnerabilities, the “Cairn” tool, which is used to carry out exploitation operations automatically and obtain advanced powers, in addition to the “hermes” tool, which is responsible for coordinating attacks, implementing post-hack operations, and making tactical decisions.
The researchers noted that the role of the human operator was limited in some cases to brief instructions, while artificial intelligence tools carried out the bulk of the operations. The period between September 10 and 15 alone witnessed the implementation of 105 attack waves targeting at least 27 parties.
To carry out their operations, the attackers used various methods to implant card data theft software, including manipulating JavaScript files, databases, and temporary storage systems. In a related context, an artificial intelligence agent was directed to delete card data from the databases of some stores as soon as it was extracted. Resulting in data loss and extensive operational disruptions.