Hackers Built an AI-Powered Attack Machine and Accidentally Left the Control Panel Open
ThreatMon exposed a Blackhatsect0r server holding 16,415 credentials and roughly 498,000 target URLs.
ThreatMon reported that a crew linked to Blackhatsect0r and DXQRTXX left an attack server exposed without authentication, revealing 16,415 credential records, about 498,000 target URLs, and 449 French government subdomains. The operators used a Go command-and-control framework and a Python discovery engine that queried certificate records, DNS data, and subdomains. They attempted token forgery against France’s ANTAI traffic-fine system and pursued account access and withdrawals at the Coinstable cryptocurrency exchange after finding a readable environment file. ThreatMon said the activity shows automated discovery, not proof that AI directed each intrusion.
- Exposed server held 16,415 credentials and about 498,000 target URLs.
- Target list included 449 French government subdomains.
- Crew used a Go C2 framework and Python discovery engine.
- ANTAI token-forging and Coinstable withdrawal preparation were documented.
- Report attributes discovery to automation, not proven AI control.
Indicators of compromiseauto-extracted · verify before use · export allAll →
| Type | Indicator | Context |
|---|---|---|
| ipv4 | 212.27.13.112 | g secret associated with the Coinstable activity IP address 212.27.13.112 Coinstable backend bypassing CDN IP address 90.102.74.9 F5- |
| ipv4 | 90.102.74.9 | s 212.27.13.112 Coinstable backend bypassing CDN IP address 90.102.74.9 F5-fronted ANTAI backend Note: IP addresses and domains are |
Full article836 words · extracted from cybersecuritynews.com · click to collapse
A criminal crew linked to Blackhatsect0r and DXQRTXX built an automated system designed to find weaknesses across the internet. Its exposed server revealed a credential vault, source code, chat logs, fraud notes, and a target list, offering a rare look inside an operation in progress.
The group combined mass discovery with focused work against selected targets. Its infrastructure sought exposed services, leaked credentials, and weak application settings, then organized the results for later use.
Researchers found 16,415 credential records and roughly 498,000 target URLs, including 449 French government subdomains. ThreatMon analysts identified the publicly reachable environment after its internal directories were left accessible without authentication.
ThreatMon said in a report shared with Cyber Security News (CSN) that the error was striking because the group had discussed operational security in its own Telegram channel, yet exposed files that mapped its activities.
The case shows how routine configuration mistakes can magnify automated attacks. Rather than depending on a novel zero-day, the operators looked for exposed files, predictable credentials, and secrets placed where applications could reveal them. Small oversights became opportunities.
Hackers Built an AI-Powered Attack Machine
The recovered material describes an operation built for persistence rather than one-off attempts. The crew developed a command-and-control framework in Go and a Python discovery engine that continually searched for systems.
It queried certificate records, reviewed DNS data, and tested subdomains repeatedly, supplying potential targets. Automation surfaced candidates while operators studied valuable systems.
Earlier reporting on AI linked this same crew to an AI-assisted workflow, but ThreatMon’s account documents automated discovery rather than proving AI directed each attempted intrusion. The exposed environment also revealed the attackers’ playbook.
The server held operational material, not a lone malware sample. It contained database, email, cloud, and developer credentials, plus research and exploitation logs.
.webp)
A Telegram export recorded coordination among several handles, supporting the assessment that a small crew with separate roles ran the activity.
The channel became active in May and soon posted alleged stolen data before shifting toward offensive tools. By mid-August, subscribers voted for tools over databases.
That change suggests an effort to spread capabilities, potentially making basic access and scanning tools available to a wider range of actors.
The exposure laid bare the group’s operational environment. Its failure shows that sophisticated code does not offset poor access controls.
Automated Scanning Meets Weak Secrets
Researchers highlighted two targeted efforts that show the move from discovery to attempted abuse. One involved France’s ANTAI traffic-fine payment system, where the group examined browser-delivered application code and tried to create authentication tokens, test request handling, and enumerate payment records.
The activity shows why signing material must stay off client-side systems. The other campaign targeted a cryptocurrency exchange after operators found a readable environment file.
They sought elevated access, reviewed accounts and balances, and prepared withdrawals. Recent reporting on Vite server credential theft likewise shows how public development and configuration files can expose cloud keys, passwords, and routes to broader compromise.
Neither chain depended on a confirmed zero-day, according to the report. Both relied on exposed configuration files, hardcoded secrets, and applications that disclosed sensitive information to browsers.
The danger grows when attackers can search constantly instead of waiting for a person to begin each scan. Security teams should remove configuration and version-control files from public paths, retain token-signing keys only on servers, replace weak or default secrets, and rotate any credential that may have been exposed.
They should review logs for repeated reconnaissance, restrict administration interfaces, and monitor their external footprint continuously.
Guidance on hardcoded token signing keys reinforces that a predictable secret can let an intruder manufacture trusted-looking access.
Organizations should investigate matching indicators quickly, preserve relevant logs, and check authentication activity for signs that stolen credentials or forged tokens were used.
The chief lesson is not that every group will create an extensive platform. It is that patient, automated discovery makes known mistakes easier to find.
Regular exposure checks, timely remediation, and prompt review of suspicious requests can shrink the window these operations need.
Indicators of compromise (IoCs):-
| Type | Indicator | Description |
|---|---|---|
| File name | ghost_token_forger.py | Script referenced in the ANTAI targeting activity |
| File name | coinstable_admin.py | Script referenced in the cryptocurrency-exchange activity |
| File name | coinstable_drain.py | Script referenced in the cryptocurrency-exchange activity |
| JWT passphrase | troiscitronbosechatjouerbelierlawingssourisfermentpoids | JWT_BLOB value associated with the ANTAI activity |
| JWT signing secret | secret | JWT signing secret associated with the Coinstable activity |
| IP address | 212.27.13.112 | Coinstable backend bypassing CDN |
| IP address | 90.102.74.9 | F5-fronted ANTAI backend |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC
Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.