OffPerimeter · Threat advisories
Campaign advisory
mediumPublished 2026-09-27 · 0 indicators

AI agent frameworks used to deploy skimmer malware against online retailers

A threat actor is leveraging three AI tools—Strix, Cairn, and Hermes—to conduct large-scale automated attacks against hundreds of online retailers. The campaign, active since July 2026, utilizes these agents for scanning, exploitation, and orchestration to inject skimmer malware into websites. By appending malicious code to JavaScript files and poisoning S3/CDN content, the actor has successfully exfiltrated massive amounts of payment data while using automated cleanup routines to wipe database fields.

ShareXLinkedInWhatsApp
First seen
2026-07-01
Last seen
2026-09-23
Threat actors
—
Malware
skimmer malware
Sectors
Retail, Hospitality, Transportation, Manufacturing
Countries
United States

How it works

The attacker uses the Strix framework to scan hosts for vulnerabilities and identifies high-value targets via website traffic-ranking services. Once targets are identified, the Cairn exploitation engine is used to obtain shells or administrative access. The Hermes orchestration tool directs the campaign and executes post-exploitation tasks, such as injecting skimmer malware into JavaScript files, Kubernetes deployments, or S3/CDN content. Finally, the attacker uses automated cleanup procedures to delete stolen card data from Magento databases to evade detection.

Techniques (MITRE ATT&CK)

What to do

References

ShareXLinkedInWhatsApp