AI-Agent-Driven Offensive Operation : Exposed Adversary Open Directory Reveals Autonomous Crypto-Theft Campaign Leading to Mass Wallet and Credential Compromise
ID: e998d7fc-9190-529c-8e03-c3ef395d68e9
STIX ID: report--e998d7fc-9190-529c-8e03-c3ef395d68e9
Feed Name: CloudSEK Blog
CloudSEK discovered an exposed operator home directory revealing an autonomous AI-agent-driven offensive operation that combined a high-volume WordPress mass-exploitation and cryptojacking campaign with targeted crypto/DeFi theft; the archive contains 12,048 WordPress backdoor records, ~3.4M reconnaissance hosts, hundreds of scraped wallet private keys/seed phrases (many from an open phishing network database), validated live API/admin tokens, a deployed Monero miner, and a developed-but-not-deployed blockchain-based dead-drop C2 prototype.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
