cd /news/ai-agents/an-ai-assembled-crew-exfiltrating-er… · home › topics › ai-agents › article
[ARTICLE · art-143845] src=huntback.io ↗ pub= topic=ai-agents verified=true sentiment=↓ negative

An AI-assembled crew exfiltrating ERP data from Spanish SMBs

An intrusion crew exposed its own working environment on the open directory 89.124.67.72 at SERVERS TECH FZCO (AS216071) in the Netherlands, and huntback recovered 10,428 files including a custom Microsoft Dynamics 365 Business Central exfiltration pipeline, a six-product enterprise exploit kit, and 15 GB of data stolen from 10 Spanish small businesses. The crew stole an Azure service-principal secret from a victim's exposed git repository using gitleaks, minted OAuth tokens, and bulk-dumped ERP tenants through the Business Central REST API with a pipeline versioned to v2.0.2, while the operator drove the work through an opencode AI agent. The corpus, whose sensor history places the host between 2026-09-28 and 2026-10-01, also contained a full Active Directory arsenal of 24 tools, Sliver, Havoc and Cobalt Strike C2, and an xmrig Monero miner.

read11 min views2 publishedOct 2, 2026

Open directories are where attackers leak too. On 89.124.67.72 an intrusion crew left its entire working environment exposed to the internet, and we recovered 10,428 files: the operator's shell history, a custom Microsoft Dynamics 365 Business Central exfiltration pipeline, a six-product enterprise exploit kit, a full Active Directory arsenal, a Sliver C2, a Monero miner, and 15 GB of data stolen from a cluster of Spanish small businesses. The tradecraft is Russian-speaking and visibly AI-assisted. This report is built from that corpus.

Handling note. Victim organisations are anonymised to entity types; specific names and localities are withheld. Live credentials recovered in the corpus (an Azure app secret, private keys, API tokens) and personal data (payment-card numbers, IBANs, health records) are redacted throughout and are not reproduced here. Exploit techniques are described for defenders; working payloads are not republished.

Key findings #

  • One exposed server, the whole operation. 10,428 files across the crew's working tree, shell history included, recovered from an open directory the operator exposed themselves.
  • Cloud-API exfiltration, not malware. The crew stole anAzure service-principal secret from a victim's exposed git repository (viagitleaks ), minted OAuth tokens, and bulk-dumped every tenant through theBusiness Central REST API with a purpose-built pipeline (bc_full_dump.py /bc_export.sh , versioned to v2.0.2, with run logs).
  • A six-product exploit kit. Custom modules for SonicWall SMA1000 (CVE-2026-15409/15410, CVSS 10), JetBrains TeamCity (CVE-2026-63077), BeyondTrust (CVE-2026-1731), KEMP LoadMaster (CVE-2026-8037), SmarterMail (CVE-2026-24423) and an on-prem SharePoint key-dump.
  • Full Active Directory arsenal. 24 tools including mimikatz, secretsdump, DCSync, BloodHound, impacket, responder, ntlmrelayx and certipy, plus Sliver, Havoc and Cobalt Strike C2, chisel/gost/ngrok tunneling, and anxmrig Monero miner.
  • Assembled, not authored, and AI-assisted. The operator drives the work through anopencode AI agent; the borrowed PoCs are a polyglot of English, Russian and Chinese, one README credits ChatGPT. Running these tools establishes use, not authorship.
  • Data at scale. 15 GB from 10 Spanish SMBs: full ERP tenants plus payment-card numbers, IBANs and health records.

Discovery #

huntback indexes malicious open directories across high-risk hosting and bulletproof ASN space, and correlates them with attacker activity on our deception network. This host, 89.124.67.72 at SERVERS TECH FZCO (AS216071) in The Netherlands, surfaced as an open HTTP directory and was promoted to a full harvest because its listing scored unambiguously malicious: offensive tooling, an exploit-labelled payload and a Sliver artifact next to bulk ERP exports is not something a legitimate server exposes. We recovered 10,428 files and classified the contents automatically, extracting secrets, victim identifiers, tooling and language markers into the dossier this report is built from. Our sensor history places the host between 2026-09-28 and 2026-10-01.

Attack chain #

Two paths run from the same working directory. A cloud path turns stolen credentials into a clean API dump of each victim's ERP; an intrusion path exploits exposed enterprise appliances and pivots through Active Directory. Both feed the same loot tree, sorted one folder per victim.

OSINT & recon

Secret theft (gitleaks) BC API token mint

ERP bulk exfil

Appliance exploit + AD pivot

C2, mining, loot sort

The operator's shell history shows the sequence directly: dirsearch sweeps of a target dental company's subdomains, then a working folder /opt/pentest/findings/spain-dental-osint/ holding 02-infra-map.md, a gitleaks-report.json over a recovered git repository, and a finding file literally named 03-CRITICAL-azure-bc-creds.md.

The exfiltration pipeline #

The theft needs no malware on the victim. From the leaked git repository the crew recovered an Azure Entra ID application's client credentials, then ran the standard OAuth client-credentials grant to mint tokens and read the Business Central REST API directly, exactly as a legitimate integration would. The commands are preserved verbatim in the shell history (secrets and tenant redacted):

Around that core sits a real engineering effort: bc_full_dump.py and bc_export.sh (kept in versioned backups up to v2.0.2, plus a bc_export_windowed.sh variant), an export step that lands the data as JSON/JSONL, and a stack of run logs (bc_full_dump_run1-3.log, bc_export_run.log) recording the pulls. A single generalLedgerEntries export reached 3.9 GB. This is the whole financial system of each business: customers, ledgers, invoices and attachments, not a sample.

The exploit arsenal #

Parallel to the cloud theft, the crew carries a bundle of ready exploits for internet-facing enterprise appliances, each with its own README, and most tagged with a 2026 CVE on, or heading for, CISA's KEV list:

Product CVE Technique Notes
SonicWall SMA1000 CVE-2026-15409 + CVE-2026-15410 SSRF → Erlang RCE → root privesc CVSS 10.0, CISA KEV
JetBrains TeamCity CVE-2026-63077 Unauthenticated RCE (XStream deserialization) public Rapid7 PoC
BeyondTrust RS / PRA CVE-2026-1731 Pre-auth RCE (WebSocket argument injection) variant of CVE-2024-12356
Progress KEMP LoadMaster CVE-2026-8037 Unauthenticated command injection Chinese-language PoC + nuclei template
SmarterMail CVE-2026-24423 Unauth SSRF → RCE (ConnectToHub) PoC credited to ChatGPT

| Microsoft SharePoint (on-prem) | key-dump module | Machine-key theft (ToolShell-class) | PowerShell | The quality and provenance vary tellingly. The SonicWall module is a polished SSRF-to-root chain (tunnel through wsproxy into the appliance's internal Erlang distribution service, authenticate with a hardcoded cookie, execute via os:cmd, then escalate through an AMC path traversal). The TeamCity exploit is lifted from a public Rapid7 proof-of-concept. The KEMP and SmarterMail modules carry Chinese-language READMEs, and the SmarterMail one credits its authorship to ChatGPT. This is a kit assembled from many hands, not one author's work.

AI-assembled tradecraft #

The shell history opens with the operator installing the opencode AI coding agent (curl -fsSL https://opencode.ai/install | bash), authenticating it and wiring up its config, and the 772 MB opencode.db sits in the loot. The crew drives reconnaissance, code and exploitation through that agent, and the borrowed PoCs, English, Russian and Chinese, one explicitly "made by ChatGPT", show the same pattern: large-language-model assembly of public offensive code into a working pipeline. Alongside it we recovered licensed OpenText / Fortify SAST and Metasploit Pro, nuclei (a 944-template scanning library), and katana. It is a commercial-grade, AI-accelerated operation, not a commodity botnet.

Post-exploitation toolkit #

Once inside, the crew's kit is a textbook Active Directory chain: responder and ntlmrelayx for LLMNR/NBT-NS poisoning and relay; mimikatz, secretsdump and DCSync for credential theft; BloodHound / SharpHound and ldapsearch for mapping; impacket (psexec, wmiexec, smbexec, atexec) for lateral movement; certipy for ADCS certificate abuse; and winPEAS / linPEAS for privilege escalation. For command and control and egress we found Sliver (with a C2 config), Havoc and Cobalt Strike, tunnelled over chisel, gost and ngrok. And purely for profit, an xmrig Monero miner. Recovered secrets include 15 private keys, 10 Azure secrets, AWS and GCP keys, a GitHub token and JWTs.

A note on CVE scope #

The operator's nuclei library references 944 distinct CVEs, most dating back as far as 2000. That number is the breadth of their scanning templates, not their kill list. The CVEs they actually weaponised with bespoke modules are the six in the table above. We separate the two deliberately: carrying a template is not exploiting a flaw, and conflating the scan library with confirmed exploitation would badly overstate the campaign. Where a README's CVE label is a variant or inherited identifier (BeyondTrust's CVE-2026-1731 is a sibling of CVE-2024-12356), we say so rather than taking the label at face value.

Who the victims are #

The operator sorted exfiltration into one folder per victim, 10 distinct organisations, and the corpus tells us the type of entities involved without our needing to name them. The working directory is literally named spain-dental-osint; filenames and documents reference the Spanish commercial registry, regional towns, the national postal service and Spanish-language accounting terms, alongside S.L. (Sociedad Limitada) suffixes. The victims are Spanish small and mid-sized businesses, skewed toward dental and healthcare practices, plus an investment firm and other SMBs. We withhold the individual names and localities. Note the split: the operator is Russian-speaking; the targets are Spanish.

Per entity, the attacker pulled the complete Business Central tenant, and in several cases the document attachments too. The largest single victim alone accounts for 6.6 GB.

Entity Files Exfiltrated Data types
Entity A 24 6.6 GB customer database, document attachments, general ledger, inventory, purchase invoices
Entity B 23 1.4 GB credit memos, general ledger, inventory, purchase orders, sales invoices
Entity C 91 912 MB scanned documents
Entity D 35 630 MB scanned documents
Entity E 17 487 MB credit memos, purchase invoices, purchase orders, sales invoices
Entity F 119 241 MB scanned documents
Entity G 10 232 MB customer database, general ledger, inventory, purchase invoices, sales invoices
Entity H 24 194 MB scanned documents
Entity I 7 181 MB customer database, general ledger, inventory, purchase invoices, purchase orders
Entity J 1 55 MB sales invoices

What this means #

A full Business Central dump plus intrusion access is a total compromise of a small business:

  • Personal-data breach (GDPR). Beyond thecustomers databases, the corpus holdsthousands of payment-card numbers, hundreds of IBANs and health records , reportable under Spanish and EU law and acutely sensitive for the dental/healthcare cluster.
  • Invoice and BEC fraud. Full sales and purchase invoices, orders and supplier details enable supplier impersonation and payment redirection.
  • Extortion and financial exposure. The general ledger is every transaction, bank movement and balance, direct leverage and a complete map of the business.
  • Onward access. Stolen Azure app secrets, private keys and tokens mean the exposure outlives any single password reset until every credential is rotated.

Attribution #

Tooling, directory names and operator notes are in Russian; the recovered vocabulary is offensive-operations language:

Captured term Meaning
ВАЖНО important
жертв victims
пентест pentest
уязвимост vulnerability
фаззинг fuzzing
эксплойт exploit

A working directory named project1488 also appears; 1488 is a numeric code associated with white-supremacist movements. We record it as an artifact of this operator's environment, not a confirmed group affiliation. Consistent with responsible practice, the Russian-language markers place a Russian-speaking operator or crew behind the infrastructure; language and borrowed-PoC artifacts are an attribution lead, not a link to a named group or state. The polyglot, AI-assembled toolkit is more consistent with an assembled crew than a single bespoke author.

Indicators of compromise #

Notable file Size SHA-256
generalLedgerEntries.jsonl 3.9 GB 289df29fad549a46f7bc17cfb9b48cc1a188654b2c61faccd6b7a219a88d3ca2
salesInvoices.jsonl 1.2 GB 399e2ad2f6c914b7cd4f269ba6272c0a9e05afb30ac962b90fa386d3b8b80b16
OpenText_SAST_Fortify_Linux_26.1.0.tar.gz 1.2 GB 5ca72a168eda89ee7dc454af38bedb60295783f1e8ddb72cd050a9376a31399e
opencode.db 772 MB 323a7dee4e3d989877a9409e33fa7bae307569d77246f361b411fd7ea7605669
Fortify_Tools_25.4.0_Linux.tar.gz 547 MB a0cbd1ae152d7f29cb87eda1e9be7d33603f08143cd801c1cea7f06a2798e5e8
Metasploit Pro 5.0.0 -L0dxG.rar 309 MB 58f357a942081264a1f8959ef4a474fb1c1b25608decb9eb0efaf406b4fca83c
generalLedgerEntries.json 249 MB ceea53c431f97de6b6081c4a40ebb942bc333f86c0166d75779ce773ab00bc30
generalLedgerEntries.jsonl 222 MB b41e49cbcab79c43720aaf79b2de3f9a8543f4c2618df435cd32fb01489cee98

MITRE ATT&CK #

Technique Name Observed via
T1595.002 Vulnerability Scanning nuclei (944-template library), dirsearch
T1552.001 Credentials in Files gitleaks over an exposed git repo → Azure app secret
T1078.004 Valid Accounts: Cloud stolen Azure service-principal, OAuth client-credentials
T1649 Steal or Forge AD Certificates certipy
T1003 / .001 / .006 OS Credential Dumping (LSASS, DCSync) mimikatz, secretsdump, dcsync
T1087.002 Account Discovery: Domain BloodHound, SharpHound, ldapsearch
T1021.002 Remote Services: SMB impacket psexec / wmiexec / smbexec / atexec
T1557.001 LLMNR / NBT-NS Poisoning and Relay responder, ntlmrelayx
T1071.001 Web-protocol C2 Sliver, Havoc, Cobalt Strike
T1572 Protocol Tunneling chisel, gost, ngrok
T1082 System Information Discovery winPEAS, linPEAS
T1496 Resource Hijacking xmrig (Monero miner)

Mitigations #

  • Treat a leaked service-principal as a breach. Scan your own public and private repositories withgitleaks ; a single committed Azure client secret was the entire entry point here. Rotate and vault app secrets, and prefer workload-identity federation over long-lived secrets.
  • Lock down the Business Central API. Least-privilege API scopes, conditional access on the token endpoint, and alerting on client-credentials grants and bulk OData reads (customers /generalLedgerEntries pulls) from unfamiliar IPs.
  • Patch the weaponised appliances now: SonicWall SMA1000 (CVE-2026-15409 / 15410), JetBrains TeamCity (CVE-2026-63077), BeyondTrust RS/PRA (CVE-2026-1731), KEMP LoadMaster (CVE-2026-8037), SmarterMail (CVE-2026-24423); rotate on-prem SharePoint machine keys.
  • Break the AD chain: disable LLMNR/NBT-NS, enforce SMB signing (relay), monitor DCSync-style replication from non-DCs, and audit ADCS templates (certipy).
  • Watch egress: Sliver/Havoc/Cobalt Strike beacons, chisel/gost/ngrok tunnels, and xmrig mining pools.

Summary #

Operation Open Ledger is a compact illustration of where mid-tier intrusion has gone: a Russian-speaking operator, an AI agent, a folder of borrowed exploits, and a cloud API turned into a bulk-exfiltration tool against small businesses that will never see it in a log. They were undone by the oldest mistake, leaving their own server open, which is exactly how we find them. You can browse the running list of exposed C2 and malware infrastructure on live finds, see the IP profile for 89.124.67.72, or start free and hunt your own.

Hunt attacker infrastructure #

Find exposed C2, open directories and loot servers from your own sensors, free.

── more in #ai-agents 4 stories · sorted by recency
── more on @huntback 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
→ Live at https://your-agent.zahid.host ✓
Get free account → Pricing
from €0/mo · no card required
LIVE [news/an-ai-assembled-crew…] indexed:0 read:11min 2026-10-02 · —