Researchers Discover Cybercrime Server Containing AI Tools, Phishing Kits and Stolen Data
Researchers found an exposed French cybercrime server holding GHOST C2, phishing kits, AI agents, and over 16,000 stolen credentials.
Researchers found an internet-exposed server used by a French-speaking cybercrime crew linked to BlackHatSect0r and DXQRTXX and active from at least May to August 2026. The workspace included GHOST C2 v6.0, a Go scanning and command-and-control platform of about 13,000 lines, a Python discovery engine, phishing material, and more than 16,000 credential records. A target list of roughly 498,000 URLs included French government subdomains, and operators allegedly used a self-hosted Nous Research Hermes agent on a DeepSeek model with safety disabled. The report says intrusion ideas relied on exposed secrets and weak JWT configuration, and it does not independently prove successful theft.