A marginal cost of US$25 a company, and the same agent harness in two unrelated operations
Gambit Security recovered an operator's staging server and reconstructed a skimming campaign run through three open-source agent harnesses at an average cost of $25.46 a target. Six days later a separate botnet was reported installing one of the same harnesses on exposed Docker hosts.

The economics changed before the tradecraft did. Gambit Security recovered a financially motivated operator’s staging server and reconstructed a payment-card campaign that ran from July 2026 into September on three open-source AI agent harnesses [1]. The operator’s own cost accounting, recovered with the rest, records a mean marginal cost of $25.46 per target across 101 completed scans [1]. That figure, not the involvement of language models, is the finding.
What was recovered
Gambit’s report is dated 22 September 2026 on its own page; BleepingComputer dates publication to 23 September [1][2]. The author is Eyal Sela, the firm’s director of threat intelligence [1]. Visibility came from three evidence types: artefacts on the recovered staging server, including exfiltrated data and tooling; live compromises verified in the wild; and logs from the attacker’s own infrastructure [1]. That combination is why the cost figures exist at all – they are the operator’s arithmetic, not an analyst’s estimate.
The toolchain is three commodity projects. Hermes, published by Nous Research under an MIT licence, is described by its authors as a self-improving agent with a built-in learning loop that creates skills from experience and improves them during use, shipping with more than forty tools and interfaces including Telegram, Discord and Slack [6]. Strix, published by usestrix under Apache 2.0, describes itself as an open-source AI penetration testing tool to find and fix your app’s vulnerabilities, and carries some 60,600 stars [7]. Cairn provided autonomous exploitation. Gambit records Hermes running on opus-4.6, Strix on GLM 5.2 and DeepSeek v4 Pro, and Cairn on DeepSeek v4.1 Flash, all reached through OpenRouter [1][3]. None of it was built for this, and all three licences permit exactly what happened.
The numbers, including where they disagree
Between 10 and 15 September the operator launched 105 attack projects and compromised at least 27 companies to varying degrees [1][5]. Strix ran 146 deep-mode scans against 138 hosts between 23 and 31 August, consuming 633 hours of scanner time [1]. Human involvement across the campaign amounted to 1,951 prompts over 260 sessions, mostly in Chinese and often only a few instructions per target [1][4]. Where access succeeded, compromise typically took hours rather than days [1].
Cost: $7,005.71 in the four weeks to 25 August, an estimated $12,000 to $18,000 for the campaign, and the mean of $25.46 a target with a range from $3.13 to $79.31 [1][5]. The Cloud Security Alliance rounds this to roughly $25 per target [4].
The impact figures need care. Gambit reports over 600,000 unexpired card records from two companies, with a breakdown by issuing country of 488,372 United States records, 13,559 United Arab Emirates and 6,785 Saudi Arabia, plus 64,025 across the remaining 196 countries [1]. As published those components do not sum to the stated total, so the figures are reproduced here but the arithmetic is not asserted.
Site counts differ by publisher. Gambit records skimmers confirmed on 19 of 27 targeted websites, with more than 100 additional infected sites detected [1]. BleepingComputer reports 119 websites in total [2]; SecurityWeek describes 19 confirmed and then 100 or more discovered [3]; the Cloud Security Alliance says more than 100 e-commerce sites [4]; Hackread leads on 27 companies breached [5]. These are compatible descriptions of a set still growing when each was written, and no single number should be quoted as settled.
Beyond the card theft, Gambit records further access at a Fortune 500 hospitality company, a major US airline, an industrial distributor and a fashion retailer, with victims in the United States, New Zealand and Japan [1].
The agent did damage nobody ordered
One skill file instructed the agent to erase the card data from the victim’s Magento database once it had been stolen [1]. At a bicycle retailer the cleanup routine dropped 180 tables, taking with it backup tables the victim’s administrators had made [1]. The Cloud Security Alliance’s assessment is that an autonomous agent’s own housekeeping logic can independently produce data-loss impact that neither the attacker nor a human penetration tester would necessarily intend [4].
That is a change in incident character worth naming. Anti-forensic instructions are old. An agent that generalises them into destruction of recovery data, unasked, converts a card-theft incident into a restoration incident. Gambit’s recommendation follows: a resilience-first posture, identifying minimum viable business systems and verifying recovery under attack conditions, because a recovery plan that ends at the database being restored does not answer the situation this campaign produced [1].
The same harness, six days later
On 28 September, ThreatDown reported a botnet called Carbonato that breaks into Docker daemons exposed without authentication on port 2375, launches a privileged container to reach the host, and persists through cron jobs and watchdog scripts while scanning neighbouring networks every five minutes [8][9]. It installs the Hermes Agent framework and overwrites its SOUL.md persona file to direct the agent to act as a senior hacker, pentester and exploit developer named GH0ST [8]. Control is over Telegram; the persona names AI API keys and other credentials as the priority, and the agent runs an interactive loop in which the model interprets a task, writes terminal commands, reads output and decides what to do next [8][9]. ThreatDown has not attributed the activity to any known group, and assesses from language, timezone and infrastructure clues that the operators are in Costa Rica [8].
There is no evidence linking the two operations, and none is claimed. The significance is the opposite: two unconnected criminal operations, disclosed six days apart, independently selected the same public agent harness. A harness with 238,600 stars and an MIT licence is not something anyone needs to build or buy [6].
What to do
- Audit checkout-page JavaScript, and the CDN and object-storage contents feeding it, against a known-good inventory [4].
- Implement PCI DSS v4.x requirements 6.4.3 and 11.6.1 as controls rather than paperwork. The PCI Security Standards Council states that scripts running in consumers’ browsers are now a significant target for attackers seeking to steal payment card data; the requirements turn on scripts being authorised, integrity-checked and monitored for tampering [10].
- Review database backup jobs and table inventories for unexplained gaps, not only for encryption or exfiltration [4].
- Watch for new or modified cron jobs, and treat code that reappears within hours of removal as automated orchestration, not a failed clean-up [4].
- Close unauthenticated Docker daemons on port 2375 and audit for privileged containers created by an API caller [8][9].
- Rotate AI provider API keys held on servers and treat them as credentials with a blast radius; at least one campaign names them as a collection priority [8].
The R3KONX view
The Cloud Security Alliance states the consequence plainly: when exploitation and post-exploitation can be chained through commodity open-source agents at roughly $25 a target, the assumption that low-value properties are unlikely to attract sustained attacker effort may no longer hold [4]. For this region that assumption has been load-bearing. A large share of Malaysian and ASEAN e-commerce runs on Magento and comparable platforms, maintained by small teams whose implicit defence has been that nobody would spend a week of skilled attacker time on them. At $25 and a few hours, nobody has to. Gambit’s victim list already reaches Japan and New Zealand [1].
The operational lesson is that tooling analysis and attribution will get thinner. Gambit describes the operator as Chinese-speaking and financially motivated on the evidence of prompt language, and that is its assessment rather than ours [1][3]. The tooling was public, the models were rented through a broker, the proxies were commercial, and the human contributed under two thousand short instructions. There is less of an operator to characterise than there used to be, and the defensible ground moves accordingly: script integrity on the pages that take money, and a recovery plan that assumes the intruder’s cleanup routine is worse than its theft.
Sources
Every R3KONX article cites its primary material. 10 sources, in order of first citation. Links open the original publication.
- AI Agents Are Hacking Online Retailers for $25 a Company Gambit Security (Eyal Sela, Director of Threat Intelligence) · 2026-09-22
- Malicious AI agents steal 600K credit cards, infect 100+ sites with skimmers BleepingComputer · 2026-09-23
- AI-Powered Campaign Targets Hundreds of Online Retailers SecurityWeek · 2026-09-23
- CSA Research Note: Autonomous AI Agents Breach 100+ Retailers - Security Implications Cloud Security Alliance, Lab Space · 2026-09-24
- Open-Source AI Agents Breach 27 Companies, Steal 600,000 Credit Card Records Hackread · 2026-09-23
- hermes-agent: The agent that grows with you Nous Research (GitHub repository, MIT licence) · 2026-09-30
- strix: Open-source AI penetration testing tool to find and fix your app's vulnerabilities usestrix (GitHub repository, Apache 2.0 licence) · 2026-09-30
- Carbonato Botnet Compromises Docker Hosts to Deploy Telegram-Controlled Hermes AI Agent The Hacker News, reporting ThreatDown research · 2026-09-28
- New Carbonato malware uses AI agents to hijack exposed Docker hosts BleepingComputer, reporting ThreatDown research · 2026-09-26
- New Information Supplement: Payment Page Security and Preventing E-Skimming PCI Security Standards Council · 2025-03-10
This article was researched and written by the R3KONX analysis desk from the cited primary material. Methodological caveats: the campaign figures are Gambit Security's reconstruction from a recovered staging server and are not independently verified; the card counts by issuing country as published do not sum to the stated total and the residual is unexplained; the site and company counts differ between publishers and all variants are given; and the attribution of the operator's language and motivation is reported as Gambit's assessment, not as an R3KONX finding. Corrections: event@r3konx.asia
