安全公司Gambit称,一名攻击者利用三个开源AI智能体框架入侵了至少27家公司,并窃取了超过60万条信用卡记录。受害者包括一家财富500强酒店业公司、一家主要美国航空公司、一家大型美国私营工业用品分销商以及一家美国在线时尚零售商。
An attacker used three open-source AI agent frameworks to break into at least 27 companies and steal more than 600,000 credit card records, security company Gambit says. The victims include a Fortune 500 hospitality company, a major US airline, a large private US industrial supplies distributor and a US online fashion retailer.
Gambit威胁情报总监Eyal Sela在9月22日发布的报告中详细阐述了这些发现。Gambit恢复了攻击者的暂存服务器,并基于其日志、被盗数据以及其在实时网站上验证的入侵情况,重建了整个攻击行动。TNW尚未独立核实这些发现。
Eyal Sela, Gambit’s director of threat intelligence, set out the findings in a report published on 22 September. Gambit recovered the attacker’s staging server and rebuilt the campaign from its logs, the stolen data and compromises it verified on live sites. TNW has not independently verified the findings.
三个智能体,四个模型:开源渗透测试工具Strix负责扫描目标弱点。它最初运行在Z.ai的GLM 5.2上,随后切换至DeepSeek V4 Pro。自主渗透测试智能体Cairn在DeepSeek V4.1 Flash上执行了从开始到结束的完整攻击。
Three agents, four models Strix, an open-source penetration testing tool, scanned targets for weaknesses. It ran on Z.ai’s GLM 5.2 and later on DeepSeek V4 Pro. Cairn, an autonomous penetration testing agent, carried out attacks from start to finish on DeepSeek V4.1 Flash.
Hermes负责指挥整个行动,并直接对目标发起黑客攻击,使用的是Anthropic的Claude Opus 4.6。它拥有121项技能,其中78项用于攻击。人类操作员在260个会话中输入了1951条提示词,Gambit表示,这意味着每个目标仅需几条提示词。操作员通过OpenRouter访问这些模型。
Hermes ran the campaign and also hacked targets directly, using Anthropic’s Claude Opus 4.6. It held 121 skills, 78 of them for attacks. The human operator typed 1,951 prompts across 260 sessions, which Gambit says came to only a few prompts per target. The operator reached the models through OpenRouter.
Sela写道:“一旦获得访问权限,通常耗时不到一天,在许多情况下仅需几个小时。”
“Where access was achieved, it usually took less than a day, and in many cases just a few hours,” Sela wrote.
每次扫描约25美元:操作员在四周内通过OpenRouter账户支出了7005.71美元。Gambit估计整个行动的成本在12000美元至18000美元之间。一次完整的扫描平均成本为25.46美元,区间在3.13美元至79.31美元之间。
About $25 a scan The operator’s OpenRouter account spent $7,005.71 over four weeks. Gambit estimates the whole campaign cost $12,000 to $18,000. A completed scan cost $25.46 on average, and between $3.13 and $79.31.
该行动始于7月。仅在9月10日至15日期间,操作员就启动了105个攻击项目,并入侵了至少27家公司。Gambit在19家被点名的受害者处确认存在信用卡盗刷器(skimmers),并在另外100多个网站上发现了此类盗刷器。
The campaign began in July. Between 10 and 15 September alone, the operator launched 105 attack projects and compromised at least 27 companies. Gambit confirmed card skimmers at 19 of the named victims and found skimmers on more than 100 other websites.
这60万张银行卡信息来自两家公司,其中79%属于美国持卡人。这些侧录程序(skimmer)隐藏在jQuery等JavaScript库、谷歌标签以及Kubernetes容器中。在一家美国葡萄酒零售商的网站上,一个定时任务(cron job)会在网站重新部署后的每两分钟内自动将侧录程序重新植入。
The 600,000 cards came from two companies, and 79% belonged to US cardholders. The skimmers hid in JavaScript libraries such as jQuery, in Google tags and in Kubernetes containers. At one US wine retailer, a cron job put the skimmer back every two minutes after the site was redeployed.
中文提示词与删除备份:测试服务器加载了一个名为“SOUL – 红队操作员”的系统角色,操作员用中文输入了简短的指令。Gambit并未将此次攻击行动与任何特定的组织或国家挂钩。
Prompts in Chinese, and deleted backups The staging server loaded a system persona called “SOUL – Red Team Operator”, and the operator typed short instructions in Chinese. Gambit does not tie the campaign to any named group or country.
攻击者的清理程序还销毁了数据。在一家自行车零售商的系统中,他们删除了180个数据库表,其中包括受害者管理员自行创建的备份。
The agents’ cleanup routines also destroyed data. At a bicycle retailer, they dropped 180 database tables, including backups the victim’s own administrators had made.
Gambit表示,他们已联系了许多受影响的机构,并在Shadowserver基金会的协助下帮助拆除了相关基础设施。Overwatch Data目前正在负责向发卡机构进行欺诈报告。
Gambit said it contacted many of the affected organisations and helped take down the infrastructure, with help from the Shadowserver Foundation. Overwatch Data is handling fraud reporting to card issuers.
AI智能体与安全:该报告增加了近期涉及AI智能体的一系列安全事件。OpenAI花费了约2.5小时才阻止了一个逃离沙箱的智能体,而OpenAI的智能体在5月份还曾攻击过RubyGems。Anthropic本月发布的威胁情报报告详细说明了Claude如何被滥用于监视和武器制造。
AI agents and security The report adds to a run of incidents involving AI agents. OpenAI took about 2.5 hours to stop an agent that escaped its sandbox, and OpenAI agents attacked RubyGems in May. Anthropic’s own threat intelligence report this month detailed how Claude was misused for surveillance and weapons.