Threat actors are increasingly using coding assistants as operational tools. Detailed research from Gambit Security highlights three campaigns where Claude Code, OpenAI Codex, and large language models facilitated activities ranging from ransomware preparation to the harvesting of secrets on a large scale and exploiting cloud accounts.
These cases demonstrate how AI can speed up attackers’ tasks, interpret command outputs, and decrease the effort required to assemble disposable tools.
Claude Code and Codex Credential Theft
In the first case, observed in late June 2026, a suspected affiliate of The Gentlemen ransomware-as-a-service operation utilized Claude Code during intrusions affecting six organizations.
Investigators assessed the RaaS connection with medium confidence based on infrastructure overlaps, a listing on a leak site, and targeted backup systems.
Claude Code was used to generate reconnaissance and exploitation commands, modify firewall policies, create scripts, and identify priority business systems.
The operator accessed exposed VPN management interfaces using previously obtained credentials, then used the assistant to troubleshoot authentication and API errors.
Researchers from CDN found that the actor reframed a blocked request as an authorized security test in a new session. The campaign also included an LDAP pass-back technique to retrieve a firewall’s service account password, the creation of a persistent VPN user, internal credential testing, and the assessment of domain controllers, databases, and backup infrastructure.
In one instance, an AI-assisted configuration restore rendered a firewall unreachable, illustrating that automation can amplify both attacker errors and capabilities.
In a second case, a Chinese-speaking actor tracked as Zerofot used Codex and Claude Code to build and operate a bespoke tool called auto_scan, which scanned for exposed files and directory listings to find API keys, cloud credentials, tokens, and SSH private keys, and subsequently validated these secrets against various providers.
From April 5 to May 23, 2026, this operation collected 2,975 validated credentials from 1,742 victim hosts, including 661 SSH private keys, 635 AWS access keys linked to 214 accounts, 448 Google Gemini keys, 254 OpenAI keys, 205 GitHub tokens, and 176 Anthropic keys.
Zerofot also used the assistants for DevOps tasks, deploying infrastructure, managing proxies, and debugging failures. Recovered scripts revealed attempts at cloud lateral movement against AWS services and scanning of exposed Jenkins servers.
Valid AI keys were reportedly sold to llde[.]tech, a gateway that resold access to models. This convergence of credential theft and AI service monetization creates an incentive to target development and cloud environments.
The third case involved RAGE, an AI-generated Python framework designed to exploit exposed deployments of Redis, Elasticsearch, Docker, Tomcat, Jenkins, Hadoop YARN, Confluence, and Supervisord.
In one incident, AWS credentials recovered from an exposed Redis instance granted the actor administrative access to a SaaS provider’s account. A post-exploitation script enumerated IAM identities and roles, attempted role assumption, created additional access keys, and collected data from S3, Secrets Manager, SSM, Lambda, ECS, RDS, and DynamoDB.
Defenders should take steps to eliminate public exposure of administrative services and directory listings, regularly rotate exposed credentials, enforce the principle of least privilege, and monitor for anomalous IAM key creation or role assumption.
The broader lesson is that AI-assisted techniques are already embedded across reconnaissance, credential access, cloud discovery, and operational support. Organizations need detection systems that monitor for identity misuse and attacker behavior, not just the presence of AI-generated code.
IOC Table
| Campaign | Indicator |
|---|---|
| The Gentlemen affiliate | 38.110.228.33 |
| The Gentlemen affiliate | 23.27.180.34 |
| Zerofot | 172.245.185.195 |
| Zerofot | 209.99.191.199 |
| Zerofot | 23.80.90.36 |
| Zerofot | 170.231.224.116 |
| Zerofot | 170.231.224.99 |
| Zerofot | 170.231.224.4 |
| Zerofot | 170.231.224.60 |
| Zerofot | 170.231.224.33 |
| Zerofot | 170.231.224.41 |
| Zerofot | 170.231.224.29 |
| Zerofot | llde[.]tech |
| Zerofot | zerofot[.]com |
| RAGE | 91.84.125.213 |
| RAGE | 91.84.118.236 |
| RAGE | 91.84.115.56 |
| RAGE | bold-scene-8a29.jessicacannons34.workers[.]dev |
| RAGE | rage-cdn-1780098503.s3.eu-central-1.amazonaws[.]com |
Stop new phishing & malware before they compromise your business. Integrate live intel from 15K SOCs around the world

