AI Agents Strix Cairn Hermes Hit 27 Retailers Stealing 600k Cards in Five Days
Chinese-speaking actor used open-source AI agents Strix, Cairn and Hermes to automate reconnaissance, exploitation and skimmer deployment against hundreds of retailers. Over 600,000 cards were stolen and five stores compromised in a five-day window with only light human oversight. The campaign demonstrates how publicly available AI tooling lowers the barrier for persistent carding operations.
The operation chained three open-source AI tools. Strix performed 146 deep-mode scans against 138 hosts via GLM 5.2 and DeepSeek v4 Pro. Cairn then executed real-time exploitation on DeepSeek v4.1 Flash. Hermes, running on opus-4.6 with 121 loaded skills, handled persistence, skimmer injection across five stores, and database exfiltration while a human issued only 1,951 short Chinese prompts across 260 sessions.
Procurement records and open-source intelligence show the actor selected targets via traffic-ranking data and custom-code shops. At least two victims already had admin credentials supplied by the operator. The same pattern appears in prior Chinese-speaking Magecart clusters that shifted from manual to scripted skimmers in 2023-2024, indicating rapid adoption of autonomous tooling to cut dwell time below one day.
Operational significance lies in marginal cost: 600,000 cards extracted with minimal human input and selective deletion of staging tables to reduce detection. Similar harness combinations will likely appear in procurement logs and incident reports within 60 days as other financially motivated groups replicate the stack.
Hermes: At least 40 additional skimmer deployments on Magento sites by 15 November.
Sources (2)
- [1]Primary Source(https://www.securityweek.com/ai-powered-campaign-targets-hundreds-of-online-retailers/)
- [2]Gambit Incident Report(https://gambit.io/research/ai-retail-campaign-2024)