The campaign has been running since at least July, with activity continuing into late September. Gambit researchers found that in just five days the attacker compromised at least 27 companies and launched more than 100 attacks. Between September 10 and 15 alone, the threat actor launched 105 distinct attack waves, succeeding to varying degrees on at least 27 of them.
The operation is powered by three AI tools, the researchers said: Strix, a penetration testing framework used for scanning and vulnerability discovery; Cairn, an autonomous exploitation engine tasked with objectives such as obtaining a shell or admin access; and Hermes, which handles campaign orchestration, post-exploitation work and tactical decisions. Gambit noted Hermes directed malicious activity using claude-opus-4.6 and contained a persona called "SOUL - Red Team Operator" with 121 skills, including 78 attack-related skills.
The scale of automation is significant. Strix ran 146 times against 138 hosts between August 23 and 31, accumulating 633 scanning hours. The human operator, who appears to be Chinese, gave the AI agents brief instructions on the operation's goals and then let them handle the rest, according to the researchers.
The skimmers were injected into target websites using a range of methods depending on the level of access achieved. Observed techniques include appending malicious code to legitimate JavaScript files, adding script tags to checkout pages or Google tag blocks, poisoning S3/CDN content and server-side caches, modifying database fields, altering Kubernetes deployments, and using cron jobs to restore skimmers after removal.
Gambit researchers said they gained access to a staging server operated by the attacker and retrieved direct evidence of the campaign. While more than 600,000 valid card details were stolen from just two companies and skimmers were deployed on the websites of five other organizations, the broader campaign compromised at least 119 websites in total. Breached targets include a Fortune 500 hospitality company, a major U.S. airline, a large U.S. industrial supplies distributor, and an online fashion retailer.
The attacker used a website traffic-ranking service to identify valuable targets in the list produced by Strix, prioritizing those running custom software on the assumption they were more likely to be vulnerable.