What happened
Gambit said the activity began in July 2026 and remained ongoing when it published its interim report. On 22 September 2026, Gambit Security published its interim reconstruction of the campaign and its recovered infrastructure. On 24 September 2026, SecurityWeek independently reported the campaign’s disclosed scale, tooling and payment-card impact. The recovered evidence linked the campaign to more than 600,000 unexpired card records from two companies, at least 27 companies compromised to varying degrees and at least 119 websites carrying associated skimmers. At one bicycle retailer, cleanup logic dropped 180 tables whose names matched ZQ or Backup, including administrator-created backup tables.
The operator used three open-source AI harnesses: Strix for vulnerability discovery, Cairn for end-to-end exploitation tasks, and Hermes for orchestration and post-compromise work. The cited research identified GLM 5.2 and DeepSeek v4 Pro for Strix, DeepSeek v4.1 Flash for Cairn, and Anthropic opus-4.6 for Hermes. The human operator supplied short Chinese instructions, a Chinese persona called SOUL - Red Team Operator, and 121 Hermes skills, including 78 attack skills. The harnesses scanned targets, selected exploit paths, executed commands, injected skimmers, exfiltrated card data and performed cleanup steps recorded in the recovered staging environment.
Between 23 and 31 August 2026, Strix ran 146 times in deep mode against 138 hosts, accumulating 633 scanner hours. Between 10 and 15 September 2026, the operator launched 105 Cairn attack projects and compromised at least 27 companies to varying degrees. Published infrastructure includes 155.254.22.215, 209.126.4.170, 213.21.239.62, 172.245.224.188 and 172.245.89.137. Published domains include medbooksource[.]com, traffic-analyzer[.]net, b8t[.]shop, cdn[.]netlfjs[.]com, x1opay[.]co, static-js[.]com, cdn[.]js-static[.]com, js-static[.]com, jsnetlify[.]com, netlifyjs[.]com and newssjs[.]com. The cited sources did not publish a complete victim list, exploit inventory or per-victim compromise timeline. Attribution posture: Gambit assessed the operator as Chinese-speaking and financially motivated but did not name a known threat actor.
Why this matters now
The campaign compresses several enterprise risks into one operating model: automated vulnerability discovery, exploitation, credential use, cloud-secret access, payment-card exfiltration, web-skimmer persistence and destructive cleanup. The important change is not an abstract claim that AI makes attackers faster. Gambit recovered a staging environment showing named frameworks, models, operator instructions, infrastructure and execution records. Where access succeeded, the attack could move from an exposed application weakness to root access, cloud secrets and payment systems before a normal remediation or change process convened.
Retailers should not frame this solely as vulnerability management. The observed skimmers survived through multiple control planes, including legitimate JavaScript, Google tag blocks, S3-backed content, database fields, Kubernetes configuration, server-side caches and recurring jobs. Database cleanup also damaged backup tables. The executive decision is therefore whether checkout integrity, payment containment and minimum-viable-commerce recovery can be proven independently of the production environment.
The decision for security leaders
Assign the digital-commerce owner and incident response lead to perform a single integrity review spanning every checkout delivery path. File hashes alone are insufficient where attackers altered database content, tag blocks, object storage, caches, Kubernetes manifests and recurring jobs. Payment, fraud, privacy and legal teams should receive the same evidence package so containment and notification decisions use one verified scope.
Assign resilience leadership to prove restoration of the minimum systems required to accept, authorise and reconcile sales without trusting production databases or administrator-created backup tables. The campaign’s cleanup behaviour means deletion may occur without an extortion demand. Recovery acceptance should therefore include application integrity, payment routing, secrets, deployment configuration and reconciliation data, not merely a successful database restore.
Evidence of closure
- Checkout integrity reports show approved content across every delivery path.
- DNS and proxy searches return no unexplained contact with published infrastructure.
- An isolated recovery test restores minimum-viable-commerce services within the approved objective.
- Payment and privacy owners record a documented impact disposition.
The Security.io assessment
The research is unusually specific because it is based on a recovered staging environment, live skimmer verification and retrieved execution records. Confidence is moderated because the interim report acknowledges incomplete data, many victims remain unnamed and some conclusions rely partly on agent-generated logs. Enterprises should use the indicators and techniques as hunt inputs, not assume every exposed retailer was compromised by this campaign.
The strategic change is an attacker operating tempo that can traverse application, cloud and payment boundaries inside existing enterprise response clocks. Defensive AI procurement is not the immediate answer. The durable controls are complete attack-surface ownership, rapid isolation, checkout change attestation, segmented secrets, payment telemetry and recoverable commerce services. Those controls remain effective whether the next operator uses the same models, different harnesses or no AI at all.
Questions for the morning meeting
- Can digital-commerce teams prove checkout code integrity across files, databases, tags, caches, buckets and Kubernetes manifests?
- Which revenue systems can be restored if attacker cleanup deletes production and administrator-created backup tables?
- Are payment incident thresholds based on verified indicators rather than customer fraud reports?