Hackers Built an AI-Powered Attack Machine and Accidentally Left the Control Panel Open
ThreatMon exposed a Blackhatsect0r server holding 16,415 credentials and roughly 498,000 target URLs.
ThreatMon reported that a crew linked to Blackhatsect0r and DXQRTXX left an attack server exposed without authentication, revealing 16,415 credential records, about 498,000 target URLs, and 449 French government subdomains. The operators used a Go command-and-control framework and a Python discovery engine that queried certificate records, DNS data, and subdomains. They attempted token forgery against France’s ANTAI traffic-fine system and pursued account access and withdrawals at the Coinstable cryptocurrency exchange after finding a readable environment file. ThreatMon said the activity shows automated discovery, not proof that AI directed each intrusion.