INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
Atlas ASM Asset Management System Breached Due to Inability
| 2026-10-06 07:51 HIGH HIGH MALWARE & BOTNETS CYBERATTACK (GENERAL)
Executive Summary
AI-generated
The financial institution's "Atlas ASM" asset management system, which manages 270,000 financial assets, has been breached repeatedly due to its inability to withstand continuous hacking attempts. According to the Financial Security Institute, as of June this year, the financial institution has been operating the ASM service for financial institutions since December last year, with 147 financial institutions using the service and identifying over 270,000 items of external assets exceeding the financial sector. The attack works by exploiting internal vulnerabilities such as identity verification and access control errors, undiscovered vulnerabilities, and zero-day attacks that are not detected by the system's ASM scanning stage. As a result, the current status is one of repeated breaches, with no guarantee that the current attack can be completely prevented despite using ASM.
Technical Mitigations AI-generated
• Apply the vendor fix for CVE-2026-0257 and treat internet-facing systems that were not patched in time as potentially compromised until verified.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected
Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.
5e20d8••••••••••••••••••••••••••••••••••
1d8332••••••••••••••••••••••••••••••••••
f6e4fa••••••••••••••••••••••••••••••••••
fdaee6••••••••••••••••••••••••••••••••••
255314••••••••••••••••••••••••••••••••••••••••••••••••••••••••••
0c36cf••••••••••••••••••••••••••••••••••••••••••••••••••••••••••
10de61••••••••••••••••••••••••••••••••••••••••••••••••••••••••••
3f2f48••••••••••••••••••••••••••••••••••••••••••••••••••••••••••
qr•••••.br
in•••••.online
wa•••••.com
nu•••••.com
7a7d96••••••••••••••••••••••••••
0e00ad••••••••••••••••••••••••••
271671••••••••••••••••••••••••••
7f1cba••••••••••••••••••••••••••
hxxp://••••••••••••••••••••
hxxp://••••••••••••••••••••
91.92.•••.•••
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Operation MasterOperation Master
CVE-2026-0257CVE-2026-0257
Target & Sectors
NORDICS
NORDICS
BENELUX
BENELUX
LATAM
LATAM
NORTH_AMERICA
NORTH_AMERICA
energyenergy
retailretail
financefinance
Incident Timeline
September 10 to 15
Threat actors used penetration test tools Strix and Cairn, along with an autonomous AI agent Hermes, to conduct attacks against 27 companies from September 10 to 15.
Click on any entity below to view its context and source!
general_metric
146 times
The attackers conducted a penetration test tool called Strix from August 23 to 31, executing it in deep mode 146 times and scanning 138 hosts, and from September 10 to 15, they used the penetration test engine Cairn and autonomous AI agent Hermes to conduct 105 attacks, causing damage to more than 27 companies.
infrastructure
138 hosts
The attackers conducted a penetration test tool called Strix from August 23 to 31, executing it in deep mode 146 times and scanning 138 hosts, and from September 10 to 15, they used the penetration test engine Cairn and autonomous AI agent Hermes to conduct 105 attacks, causing damage to more than 27 companies.
general_metric
105 attacks
The attackers conducted a penetration test tool called Strix from August 23 to 31, executing it in deep mode 146 times and scanning 138 hosts, and from September 10 to 15, they used the penetration test engine Cairn and autonomous AI agent Hermes to conduct 105 attacks, causing damage to more than 27 companies.
general_metric
27 companies
The attackers conducted a penetration test tool called Strix from August 23 to 31, executing it in deep mode 146 times and scanning 138 hosts, and from September 10 to 15, they used the penetration test engine Cairn and autonomous AI agent Hermes to conduct 105 attacks, causing damage to more than 27 companies.
2025/10/06
Threat actors, identified as BraZetsu, supplied an underground ecosystem with malware targeting the 'Atlas ASM' service operated by a financial institution since December last year.
Click on any entity below to view its context and source!
attribution
the Financial Security Institute
According to the Financial Security Institute, as of June this year, the financial institution has been operating the ASM service, 'Atlas ASM', for the financial institutions since December last year.
February 2026
Threat actors, identified as BraZetsu, began supplying an underground ecosystem with a malware that rapidly evolved from basic remote access to an AI-enhanced intelligence collection platform starting in February 2026.
August 25
Threat actors used an OpenRouter account to spend $7,005.71 over roughly four weeks as of August 25.
Click on any entity below to view its context and source!
organisation
OpenRouter
They found an OpenRouter account showing $7,005.71 spent over roughly four weeks as of August 25.
financial
$7,005.71 account
They found an OpenRouter account showing $7,005.71 spent over roughly four weeks as of August 25.
2026/09/22
Threat actors using Hermes and claude-opus-4.6 orchestrated malicious activity against 138 hosts over a period of eight days, from August 23 to September 1, 2023.
Click on any entity below to view its context and source!
general_metric
146 times
It should not be confused with the same-name AI malware analysis tool
Cisco Talos released yesterday
Hermes — for campaign orchestration, post-exploitation work, tactical decisions, and directing the malicious activity using
claude-opus-4.6
Strix ran 146 times against 138 hosts between August 23 and 31, accumulating 633 scanning hours, the researchers found.
infrastructure
138 hosts
It should not be confused with the same-name AI malware analysis tool
Cisco Talos released yesterday
Hermes — for campaign orchestration, post-exploitation work, tactical decisions, and directing the malicious activity using
claude-opus-4.6
Strix ran 146 times against 138 hosts between August 23 and 31, accumulating 633 scanning hours, the researchers found.
infrastructure
4.6
It should not be confused with the same-name AI malware analysis tool
Cisco Talos released yesterday
Hermes — for campaign orchestration, post-exploitation work, tactical decisions, and directing the malicious activity using
claude-opus-4.6
Strix ran 146 times against 138 hosts between August 23 and 31, accumulating 633 scanning hours, the researchers found.
general_metric
633 August
It should not be confused with the same-name AI malware analysis tool
Cisco Talos released yesterday
Hermes — for campaign orchestration, post-exploitation work, tactical decisions, and directing the malicious activity using
claude-opus-4.6
Strix ran 146 times against 138 hosts between August 23 and 31, accumulating 633 scanning hours, the researchers found.
September 22
Threat actors, identified as BraZetsu, have been supplying an underground ecosystem with malware since at least July.
2026/10/06
Threat actors used ARTEX AI and other open-source tools to target hundreds of online retailers, stealing over 600,000 credit card records.
Click on any entity below to view its context and source!
infrastructure
Windows
If a security guard is searching outside the building, checking the doors and windows, and looking for known vulnerabilities in locks, then the two cases are close to the situation where access permissions are not properly checked inside the building.
BraZetsu is a sophisticated Python-based Windows malware framework attributed to the Brazilian threat actor Exilware.
organisation
Attack Surface Management
Recently, hacking incidents have been occurring in the financial sector, prompting a renewed focus on the role and limitations of Attack Surface Management (ASM).
organisation
ASM
Recently, hacking incidents have been occurring in the financial sector, prompting a renewed focus on the role and limitations of Attack Surface Management (ASM).
organisation
Advanced Security Management
The ASM (Advanced Security Management) is a security method that continuously searches for and manages a company's IT assets and vulnerabilities exposed to the internet and external networks such as virtual private networks (VPNs), web services, etc.
organisation
DBMS
Atlus analyzes the exposed assets of financial institutions found externally, along with publicly available vulnerability information (CVE), vulnerable software versions, unencrypted data, and exposed server information and database management systems (DBMS).
organisation
The Financial Security Institute
The Financial Security Institute has also identified a financial institution's exposed network through Atlus, and has advised on patching and configuring related vulnerabilities.
organisation
the YG Bank
For example, a customer's personal information was leaked when approximately forty thousand people's information was leaked by the YG Bank.
The YG Bank did not operate its own ASM or use a private ASM service.
organisation
the S2W Integrated Analysis Room
Yang Jong-hun, the head of the S2W Integrated Analysis Room, said, "In the ASM scanning stage, if an asset is overlooked or the program and version used by the service cannot be inferred, it is difficult to identify known vulnerabilities."
organisation
Shinhan Bank's
Additionally, if the vulnerability information has not been officially standardized, related information or attack scenarios are checked first."
◇ Shinhan Bank's suspected vulnerability in 'service internal'...
organisation
Shinhan Bank
Separate inspection is required
Shinhan Bank confirmed that external web server attacks were received and subsequent inspection process revealed that some web pages had insufficient session verification, leading to the exposure of information about outsource development employees.
"Attacked 'Open Source Security Tool'···Urgent: Open Source Security Issue".
Shinhan Bank has raised concerns that the 'ARTEX AI' open-source security tool may have been used in the recent data breach incident, prompting the need for alternative measures to prevent the misuse of publicly available security tools.
infrastructure
270,000 financial assets
The 'Atlas ASM' asset management system, which manages 270,000 financial assets, has been breached repeatedly due to its inability to withstand continuous hacking attempts..
organisation
Fortinet
Team Cymru, a US-based threat intelligence company, has raised the possibility that this tool could be exploited by nation-state actors to carry out attacks on Fortinet devices via network vulnerabilities.
organisation
Hestra Strike
In May, the Google Threat Intelligence Group (GTIG) has identified a pattern of activity suggesting a Chinese-linked attacker targeting a Japanese technology company and an East Asian cyber security platform, using both Hestra Strike and Strikex together.
organisation
ARTEX
Recently, credential stuffing incidents have occurred in the domestic financial sector, with the possibility of ARTEX AI being used also being raised.
organisation
LLM
ARTEX AI is an open-source, LLM-based autonomous penetration testing system that was publicly released on GitHub.
organisation
ARTEX AI
The official GitHub page of ARTEX AI explicitly states that it should not be used for scanning, exploring, or attacking websites, online services, or internet-connected systems.
organisation
Juniper Security Center
According to Jun Hyun, the CEO of Juniper Security Center, "The fact that AI tools that can be used by anyone may have been used in the attack has led to a more common era of hacking.
data_breach
10 September
Between September 10 and 15, the attacker reportedly launched 105 distinct attack waves, succeeding to varying degrees on at least 27.
data_breach
15 September
Between September 10 and 15, the attacker reportedly launched 105 distinct attack waves, succeeding to varying degrees on at least 27.
organisation
Androptic
Hermes used the Androptic's Claude Offer 4.6, while Strix and Cairn used the GLM and DeepSight models.
organisation
GLM
Hermes used the Androptic's Claude Offer 4.6, while Strix and Cairn used the GLM and DeepSight models.
organisation
DeepSight
Hermes used the Androptic's Claude Offer 4.6, while Strix and Cairn used the GLM and DeepSight models.
organisation
HexStrike AI
Additionally, HexStrike AI stated on its official GitHub that it is a security tool developed for autonomous execution of more than 150 security tools by its AI agent, and that it is only intended for use on approved systems.
organisation
CyberStrike AI
The AI-based open-source security tool CyberStrike AI integrates over one hundred security tools, automating vulnerability discovery, attack chain analysis, and exploitation.
organisation
a Multi-Tiered Intrusion
Operation Master: Deconstructing a Multi-Tiered Intrusion and Monetization Pipeline.
organisation
CVE-2026-0257
A sophisticated cybercrime operation compromised enterprise networks across multiple countries by exploiting a GlobalProtect authentication bypass vulnerability (CVE-2026-0257), executed advanced web application attacks, and deployed the AdaptixC2 framework.
organisation
GlobalProtect
A sophisticated cybercrime operation compromised enterprise networks across multiple countries by exploiting a GlobalProtect authentication bypass vulnerability (CVE-2026-0257), executed advanced web application attacks, and deployed the AdaptixC2 framework.
organisation
SQL
The operation scanned 277.5 million addresses to curate 81 high-value targets, stole databases from 9+ instances via SQL injection with xp_cmdshell escalation, and exfiltrated Active Directory credentials.
organisation
xp_cmdshell
The operation scanned 277.5 million addresses to curate 81 high-value targets, stole databases from 9+ instances via SQL injection with xp_cmdshell escalation, and exfiltrated Active Directory credentials.
victims
81 value targets
The operation scanned 277.5 million addresses to curate 81 high-value targets, stole databases from 9+ instances via SQL injection with xp_cmdshell escalation, and exfiltrated Active Directory credentials.
organisation
BraZetsu
Anatomy of BraZetsu: How Cybercriminals Supply the Underground Ecosystem.
organisation
Initial Access Brokers
Unlike standard infostealers, it functions as a comprehensive toolkit for Initial Access Brokers, converting compromised systems into high-value commercial assets.
organisation
Exilware
BraZetsu powers the 'Infected Marketplace' where Exilware commercializes initial access to compromised systems, enabling criminal clients to remotely execute additional malicious payloads.
organisation
Magento
Stolen credit cards
Source: Gambit
During the investigation, Gambit researchers discovered that the attacker instructed the AI agent to run cleanup procedures that removed card data from Magento databases after exfiltration.
organisation
Google
Observed methods include appending malicious code to legitimate JavaScript files, adding script tags to checkout pages or Google tag blocks, poisoning S3/CDN content and server-side caches, modifying database fields, altering Kubernetes deployments, and using cron jobs to restore the skimmer after it was removed.
organisation
S3
Observed methods include appending malicious code to legitimate JavaScript files, adding script tags to checkout pages or Google tag blocks, poisoning S3/CDN content and server-side caches, modifying database fields, altering Kubernetes deployments, and using cron jobs to restore the skimmer after it was removed.
organisation
Kubernetes
Observed methods include appending malicious code to legitimate JavaScript files, adding script tags to checkout pages or Google tag blocks, poisoning S3/CDN content and server-side caches, modifying database fields, altering Kubernetes deployments, and using cron jobs to restore the skimmer after it was removed.
organisation
NFL
Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.
organisation
CHANEL
Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.
data_breach
600,000 card records
A financially motivated threat actor is using open-source AI agent frameworks to attack hundreds of online retailers at scale, stealing more than 600,000 credit card records.
financial
$12,000 $ total costs
Based on subsequent usage, the researchers estimate the total costs between $12,000 and $18,000.
August 23 to 31
Threat actors used the penetration test tool Strix in deep mode 146 times and then Cairn with Hermes AI to conduct 105 attacks, causing damage to more than 27 companies.
Click on any entity below to view its context and source!
general_metric
146 times
The attackers conducted a penetration test tool called Strix from August 23 to 31, executing it in deep mode 146 times and scanning 138 hosts, and from September 10 to 15, they used the penetration test engine Cairn and autonomous AI agent Hermes to conduct 105 attacks, causing damage to more than 27 companies.
infrastructure
138 hosts
The attackers conducted a penetration test tool called Strix from August 23 to 31, executing it in deep mode 146 times and scanning 138 hosts, and from September 10 to 15, they used the penetration test engine Cairn and autonomous AI agent Hermes to conduct 105 attacks, causing damage to more than 27 companies.
general_metric
105 attacks
The attackers conducted a penetration test tool called Strix from August 23 to 31, executing it in deep mode 146 times and scanning 138 hosts, and from September 10 to 15, they used the penetration test engine Cairn and autonomous AI agent Hermes to conduct 105 attacks, causing damage to more than 27 companies.
general_metric
27 companies
The attackers conducted a penetration test tool called Strix from August 23 to 31, executing it in deep mode 146 times and scanning 138 hosts, and from September 10 to 15, they used the penetration test engine Cairn and autonomous AI agent Hermes to conduct 105 attacks, causing damage to more than 27 companies.
between August 23 and 31
Threat actors using Hermes and claude-opus-4.6 orchestrated post-exploitation work against 138 hosts between August 23 and 31, accumulating 633 scanning hours.
Click on any entity below to view its context and source!
general_metric
146 times
It should not be confused with the same-name AI malware analysis tool
Cisco Talos released yesterday
Hermes — for campaign orchestration, post-exploitation work, tactical decisions, and directing the malicious activity using
claude-opus-4.6
Strix ran 146 times against 138 hosts between August 23 and 31, accumulating 633 scanning hours, the researchers found.
infrastructure
138 hosts
It should not be confused with the same-name AI malware analysis tool
Cisco Talos released yesterday
Hermes — for campaign orchestration, post-exploitation work, tactical decisions, and directing the malicious activity using
claude-opus-4.6
Strix ran 146 times against 138 hosts between August 23 and 31, accumulating 633 scanning hours, the researchers found.
infrastructure
4.6
It should not be confused with the same-name AI malware analysis tool
Cisco Talos released yesterday
Hermes — for campaign orchestration, post-exploitation work, tactical decisions, and directing the malicious activity using
claude-opus-4.6
Strix ran 146 times against 138 hosts between August 23 and 31, accumulating 633 scanning hours, the researchers found.
general_metric
633 August
It should not be confused with the same-name AI malware analysis tool
Cisco Talos released yesterday
Hermes — for campaign orchestration, post-exploitation work, tactical decisions, and directing the malicious activity using
claude-opus-4.6
Strix ran 146 times against 138 hosts between August 23 and 31, accumulating 633 scanning hours, the researchers found.
Tactical Metrics
Metrics
infrastructure
Windows
Affected Product
Click for context!
If a security guard is searching outside the building, checking the doors and windows, and looking for known vulnerabilities in locks, then the two cases are close to the situation where access permissions are not properly checked inside the building.
BraZetsu is a sophisticated Python-based Windows malware framework attributed to the Brazilian threat actor Exilware.
Metrics
infrastructure
270,000
Financial Assets
The 'Atlas ASM' asset management system, which manages 270,000 financial assets, has been breached repeatedly due to its inability to withstand continuous hacking attempts..
Metrics
infrastructure
138
Hosts
The attackers conducted a penetration test tool called Strix from August 23 to 31, executing it in deep mode 146 times and scanning 138 hosts, and from September 10 to 15, they used the penetration test engine Cairn and autonomous AI agent Hermes to conduct 105 attacks, causing damage to more than 27 companies.
It should not be confused with the same-name AI malware analysis tool
Cisco Talos released yesterday
Hermes — for campaign orchestration, post-exploitation work, tactical decisions, and directing the malicious activity using
claude-opus-4.6
Strix ran 146 times against 138 hosts between August 23 and 31, accumulating 633 scanning hours, the researchers found.
Metrics
victims
81
Value Targets
The operation scanned 277.5 million addresses to curate 81 high-value targets, stole databases from 9+ instances via SQL injection with xp_cmdshell escalation, and exfiltrated Active Directory credentials.
Metrics
infrastructure
4.6
Software Version
It should not be confused with the same-name AI malware analysis tool
Cisco Talos released yesterday
Hermes — for campaign orchestration, post-exploitation work, tactical decisions, and directing the malicious activity using
claude-opus-4.6
Strix ran 146 times against 138 hosts between August 23 and 31, accumulating 633 scanning hours, the researchers found.
Metrics
financial
7,006
Account
They found an OpenRouter account showing $7,005.71 spent over roughly four weeks as of August 25.
Metrics
data_breach
600,000
Card Records
A financially motivated threat actor is using open-source AI agent frameworks to attack hundreds of online retailers at scale, stealing more than 600,000 credit card records.
Metrics
data_breach
10
September
Between September 10 and 15, the attacker reportedly launched 105 distinct attack waves, succeeding to varying degrees on at least 27.
Metrics
data_breach
15
September
Between September 10 and 15, the attacker reportedly launched 105 distinct attack waves, succeeding to varying degrees on at least 27.
Metrics
financial
12,000
$ Total Costs
Based on subsequent usage, the researchers estimate the total costs between $12,000 and $18,000.
Intelligence Sources
BleepingComputer
2026-09-23
Datanet
2026-10-02
AlienVault OTX
2026-09-28
AlienVault OTX
2026-10-02
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-10-07T06:33
Comprehensive Tactical Telemetry
Highly Correlated Entities
35x
organisation
Identified Entity
Attack Surface Management
entity
20x
target region
Target Country
United States
country
12x
industry
Targeted Sector
Finance
sector
8x
timeline
Temporal Reference
2025/10/06
date
5x
tactic
Cyber Operation Type
Data Breach
tactic
4x
source region
Origin Country
China
country
3x
attribution
Attributing Entity
the Financial Security Institute
authority
3x
tactic
MITRE ATT&CK Technique
T1588.001 - Malware
technique
2x
data breach
September
10
september
Contextual Telemetry
Context Block
28 METRICS
infrastructure
Affected Product
Windows
software
infrastructure
Financial Assets
270,000
financial assets
general metric
Financial Institutions
147
financial institutions
general metric
Items
270,000
items
general metric
Times
146
times
infrastructure
Hosts
138
hosts
general metric
Attacks
105
attacks
general metric
Companies
27
companies
general metric
Security Tools
150
security tools
general metric
Phishing Messages
2,400,000
phishing messages
campaign
Campaign
Operation Master
operation
vulnerability
Exploited CVE
CVE-2026-0257
cve
general metric
Addresses
277,500,000
addresses
victims
Value Targets
81
value targets
general metric
Instances
9
instances
target region
Target Region
LATAM
region
general metric
Websites
119
websites
general metric
Fortune
500
fortune
infrastructure
Software Version
4.6
version
general metric
August
633
august
financial
Account
7,006
account
general metric
Credit Cards
600,000
credit cards
general metric
Cards
100
cards
data breach
Card Records
600,000
card records
general metric
Skills
121
skills
general metric
Related Skills
78
related skills
financial
$ Total Costs
12,000
$ total costs
general metric
Completed Scans
101
completed scans
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.