research poc
AI-Agent-Driven Autonomous Crypto-Theft Campaign Exposed via Open DirectoryAI-Agent Crypto-Theft Campaign
CloudSEK discovered an exposed directory belonging to a Chinese-speaking operator who used AI coding agents, Telegram, and a self-hosted LLM proxy to run autonomous intrusions against WordPress sites, crypto/DeFi targets, and wallet-bearing phishing databases. The operator also built a blockchain-based C2 and credential-harvesting infrastructure, leading to mass wallet and credential compromise.