AI agent frameworks used to deploy skimmer malware against online retailers
A threat actor is leveraging three AI tools—Strix, Cairn, and Hermes—to conduct large-scale automated attacks against hundreds of online retailers. The campaign, active since July 2026, utilizes these agents for scanning, exploitation, and orchestration to inject skimmer malware into websites. By appending malicious code to JavaScript files and poisoning S3/CDN content, the actor has successfully exfiltrated massive amounts of payment data while using automated cleanup routines to wipe database fields.
- First seen
- 2026-07-01
- Last seen
- 2026-09-23
- Threat actors
- —
- Malware
- skimmer malware
- Sectors
- Retail, Hospitality, Transportation, Manufacturing
- Countries
- United States
How it works
The attacker uses the Strix framework to scan hosts for vulnerabilities and identifies high-value targets via website traffic-ranking services. Once targets are identified, the Cairn exploitation engine is used to obtain shells or administrative access. The Hermes orchestration tool directs the campaign and executes post-exploitation tasks, such as injecting skimmer malware into JavaScript files, Kubernetes deployments, or S3/CDN content. Finally, the attacker uses automated cleanup procedures to delete stolen card data from Magento databases to evade detection.
Techniques (MITRE ATT&CK)
- T1595.001 · reconnaissanceScanning IP BlocksThe Strix framework is used to perform scanning and vulnerability discovery against target hosts.
- T1059.003 · executionWindows Command ShellThe attacker utilizes website traffic-ranking services to identify valuable targets from scanning results.
- T1137.001 · persistenceOffice Template MacrosThe threat actor employs cron jobs to restore skimmer malware after it has been removed from a system.
- T1070.004 · defense_evasionFile DeletionThe attacker instructs AI agents to run cleanup procedures that wipe card data from Magento databases after exfiltration.
What to do
- Hunt for AI-powered attack patterns, such as the use of Strix, Cairn, and Hermes, in your network.
- Verify exposure of custom software and vulnerable infrastructure, particularly those running Magento and JavaScript-based applications.
- Prioritize patching and securing S3/CDN content, server-side caches, and Kubernetes deployments.
- Block the injection of malicious code into legitimate JavaScript files and checkout pages.
- Review and update controls to detect and prevent the use of cron jobs to restore skimmers after removal.