AI-Agent-Driven Offensive Operation : Exposed Adversary Open Directory Reveals Autonomous Crypto-Theft Campaign Leading to Mass Wallet and Credential Compromise

AI-Agent-Driven Offensive Operation : Exposed Adversary Open Directory Reveals Autonomous Crypto-Theft Campaign Leading to Mass Wallet and Credential Compromise
CloudSEK found an exposed directory belonging to a Chinese-speaking operator who used AI coding agents, Telegram, and a self-hosted LLM proxy to run autonomous intrusions against WordPress sites, crypto/DeFi targets, and wallet-bearing phishing databases. The operator also built a blockchain-based DeadDropC2 concept and deployed a disguised Monero miner, while leaving behind over 12,000 WordPress backdoors, harvested credentials, and large sets of wallet keys and seed phrases. #WordPress #DeadDropC2 #Monero #Telegram #ClaudeCode #Codex #Hermes #pi #ZhipuGLM

Keypoints

  • The investigation began with an open directory on IP 80[.]96[.]109[.]64:18080 that exposed the operator’s full working home folder.
  • The operator ran multiple AI coding agents in full-auto mode, with approvals disabled, and controlled them through Telegram.
  • A reusable Chinese “authorized pentest” prompt was used as a jailbreak wrapper to make the agents carry out offensive tasks.
  • The mass exploitation pipeline produced 12,048 WordPress compromise records across 8,996 unique sites, plus 66 harvested database admin credential sets.
  • The operator also held hundreds of cryptocurrency wallet private keys and seed phrases, much of it scraped from a misconfigured phishing clone database.
  • Evidence showed targeted theft against crypto and DeFi services, including validated API keys, admin tokens, and real wallet data.
  • The operator was developing DeadDropC2, an EtherHiding-style blockchain command-and-control system, and separately deployed a disguised Monero miner.

MITRE Techniques

  • [T1595 ] Active Scanning – Used FOFA, ProjectDiscovery tools, and broad internet sweeps to enumerate targets and exposure (‘Phase 1: Asset mapping via FOFA’ and ‘ProjectDiscovery-style reconnaissance suite’).
  • [T1190 ] Exploit Public-Facing Application – Used WordPress-to-webshell exploitation and fastjson2 deserialization RCE against exposed services (‘WordPress-to-webshell mass exploitation’ and ‘fastjson2 deserialization RCE kit’).
  • [T1110 ] Brute Force – The prompt instructed agents to try default credentials and weak passwords during automated testing (‘try default credentials’ and ‘weak passwords’).
  • [T1552 ] Unsecured Credentials – Harvested admin creds, API keys, SSH keys, wallet keys, seed phrases, and tokens from exposed directories, databases, and bundles (‘credentials, cloud AK/SK, payment keys’ and ‘live API keys and admin tokens’).
  • [T1105 ] Ingress Tool Transfer – Dropped and pushed miner binaries and other tooling to worker hosts and compromised systems (‘pushing binaries to worker hosts’ and ‘staged through a public file-sharing service’).
  • [T1021 ] Remote Services – Reused a recovered SSH key and accessed systems via SSH-based workflows (‘Single recovered SSH key reused for root on multiple cloud hosts’ and ‘over SSH’).
  • [T1074 ] Data Staged – Consolidated stolen wallet keys, seed phrases, credentials, and evidence files into working datasets (‘loot consolidation’ and ‘combined datasets’).
  • [T1041 ] Exfiltration Over C2 Channel – Sent results and stolen data back through Telegram-controlled agent bridges and operator workflows (‘tasking and monitoring them entirely over Telegram’).
  • [T1059 ] Command and Scripting Interpreter – Used shell commands, automation scripts, and agent-directed command execution during offensive operations (‘shell execution’ and shell history evidence).
  • [T1505 ] Server Software Component: Web Shell – Generated a large inventory of WordPress backdoors and unique attacker-created admin accounts (‘12,048 real compromise records’ and ‘backdoor admin account’).
  • [T1587 ] Develop Capabilities – Built DeadDropC2, a custom blockchain-based C2 kit, and a Monero miner workflow (‘The operator was developing an EtherHiding-style command-and-control system’ and miner setup).
  • [T1090 ] Proxy – Used a self-hosted Zhipu GLM proxy via LiteLLM/llmio and rotating infrastructure to broker requests (‘self-hosted Zhipu GLM proxy via LiteLLM/llmio’).
  • [T1496 ] Resource Hijacking – Deployed a disguised Monero miner onto compromised hosts for illicit revenue (‘deploys a disguised Monero miner onto compromised hosts’).
  • [T1611 ] Escape to Host – Disabled AI-agent safety approvals and full-auto controls to run tasks unattended (‘all safety approval disabled’ and ‘all actions default to allow’).
  • [T1106 ] Native API – Queried Firestore REST APIs, GraphQL endpoints, and blockchain RPC interfaces directly to retrieve data (‘public Firestore REST API with zero authentication’ and ‘GraphQL indexer’).

Indicators of Compromise

  • [IP address ] exposed staging and pivot infrastructure – 80[.]96[.]109[.]64:18080, 103[.]236[.]54[.]207, and other worker-host IPs mentioned in the article.
  • [File names ] tooling, evidence, and C2 artifacts – recovered_key.txt, DeadDropC2.sol, DeadDropC2.bin, and other project files referenced in the dump.
  • [Domains ] blockchain RPC and service endpoints – bsc-testnet-rpc.publicnode.com, bsc-testnet.drpc.org, and bsc-testnet.bnbchain.org.
  • [Wallet addresses ] blockchain test and operator addresses – 0x399E…bCE7c and 0x5eA7…ed2B80, both described as having zero mainnet activity.
  • [API/service names ] exposed cloud and platform targets – Firestore, LiteLLM/llmio, Zhipu GLM, and Telegram bot infrastructure.
  • [Hashes/credentials ] redacted but explicitly present – ED25519 SSH host key, live bot token, FOFA API keys, and 2 Monero payout wallet addresses.


Read more: https://www.cloudsek.com/blog/ai-agent-driven-offensive-operation-crypto-wallet-credential-compromise