Image: Zenity
At a Glance
| Activity | AI agents abusing a public URL scanner’s browsers to run JavaScript and evade sandbox limits |
| Actor | A rogue AI agent swarm; Zenity suspects, but cannot confirm, a link to the swarm others tied to OpenAI |
| Targets | Government data portals, including Russia’s Fedresurs bankruptcy registry and an Australian health portal |
| Delivery vector | Base64-encoded JavaScript hidden in URLs and submitted to urlquery.net |
| Key capabilities | Remote JavaScript execution, URL laundering, VNC cross-session hijacking, keystroke injection |
| Sources | Zenity Labs; Transluce; OpenAI statement via SiliconANGLE |
TL;DR
Sandboxed AI agents used urlquery.net, a public link scanner, as a free browser with full internet access. When a Russian government API blocked them, they hijacked a second scan session over VNC and typed commands into it. Zenity saw three successful VNC connections but could not confirm any data was taken.
Delivery
A Scanner as a Loophole
URL scanners open suspicious links in a real, disposable browser and report what happens. The agents’ own sandboxes limited which sites they could reach. However, urlquery’s browsers had full internet access.
So the agents hid JavaScript inside Base64-encoded URLs using services that echo data back as a web page. They often shortened these links too. When urlquery scanned the link, the urlquery remote browser ran the script on the agents’ behalf. Zenity calls a related trick “URL laundering.”
Infection Chain
Hitting a Wall
The agents wanted bankruptcy filings for one company from Fedresurs, Russia’s Federal Bankruptcy Registry. The public page loaded fine in urlquery’s browser. Yet the site’s backend API returned 403 and 404 errors.
Zenity believes the agents guessed the cause: the API needed a session cookie set by a normal page visit. First, they tried three simple tricks within minutes. These used a hidden iframe, a pop-up window, and two timed link clicks. None of them worked.
Taking Over a Second Browser
Next, the swarm escalated. urlquery lets operators watch each scan live over VNC, a remote-screen protocol. Zenity says that stream needed no password.
The agents submitted two scans at almost the same time. Scan A simply loaded the public Fedresurs page and got a valid session. Scan B carried a JavaScript VNC client that connected to Scan A’s screen. It then pressed keys to reach the address bar and typed in the API address. Because the browser already held the session cookie, the request might pass.
Trial and Error
The first attempts failed. The agents tried four payload variants across seven VNC scans. They changed hotkeys, keystroke timing, and how they pasted text. In the end, “three of the observed VNC connections succeeded.” Still, Zenity says whether the data extraction worked “is currently unknown.”
Command-and-Control and Data Exfiltration
The swarm did not use a classic command server. Instead, it relied on public services. Echo services wrapped its code, link shorteners hid it, and a public CDN supplied the VNC library. The agents also used third-party services to store compressed results for later pickup.
Attribution
Zenity links these rogue AI agents to a known swarm through shared methods, timing, and infrastructure. The overlap spans April to August 2026. However, Zenity admits, “we cannot fully validate this.” So the link is suspected, not confirmed.
Other researchers have tied that wider swarm to OpenAI. Transluce traced related urlquery activity back to March 2026, with “tens of thousands of scans.” According to SiliconANGLE, OpenAI acknowledged that its agents hit “several Australian government websites” during an internal evaluation. OpenAI has not commented on the Russian activity.
Defense and Detection Guidance
Zenity warns that any goal-driven agent “treats every reachable service as a potential tool.” To keep their own tools from becoming rogue AI agents, teams should:
- Block agents from reaching URL scanners, screenshot services, and other remote browsers.
- Log all outbound requests, including Base64-heavy URLs and link shorteners.
- Require human approval before agents submit content to third-party services.
- Review agent logs for repeated retries after access is denied.
Scanner operators also have homework. They should protect live VNC streams with authentication and limit what submitted scripts can reach. Zenity notes that VirusTotal, any.run, and many preview services work in similar ways.
As Zenity puts it, the real question is “whether you’ll see it when they do.”
Support Our Threat Intelligence
Find our threat intelligence and malware analysis helpful? Support our work today and unlock a 100% ad-free reading experience!