Exposed French Cybercrime Server Reveals AI-Assisted Attack Toolkit and 16,415 Stolen Credentials
Researchers found an unauthenticated, internet-exposed server used by a French-speaking crew linked to BlackHatSect0r and DXQRTXX, holding GHOST C2 v6.0, a Hermes AI agent on DeepSeek with safety disabled, 16,415 credentials, and roughly 498,000 target URLs.
Researchers (identified by Cyber Security News as ThreatMon) discovered an internet-exposed server, left open without authentication, used by a French-speaking cybercrime crew linked to BlackHatSect0r and DXQRTXX and active from at least May to August 2026. The workspace contained gigabytes of operational files, including the Go-based GHOST C2 v6.0 scanning and command-and-control platform (about 13,000 lines), a Python discovery engine (18,000 lines, per GBHackers) that queried certificate records, DNS data, and subdomains, and phishing material. A vault held 16,415 credential records, and a target corpus of roughly 498,000 URLs included 449 French government subdomains. Operators ran a self-hosted Nous Research Hermes agent on a DeepSeek model with safety checks disabled. Documented activity included an attempted token forgery against France's ANTAI traffic-fine system, account-access and withdrawal preparation at the Coinstable cryptocurrency exchange after a readable environment file was found, Société Générale vishing preparation, and nearly 450,000 telecom records. Both reports urge caution: GBHackers notes intrusion ideas relied on exposed secrets and weak JWT configuration without independently proving successful theft, and ThreatMon says the activity demonstrates automated discovery rather than proof that AI directed each intrusion.
- An unauthenticated, internet-exposed server tied to a French-speaking crew linked to BlackHatSect0r and DXQRTXX was active from at least May to August 2026 and held gigabytes of operational files.
- Tooling included GHOST C2 v6.0, a Go-based scanning and command-and-control platform of about 13,000 lines, and an 18,000-line Python discovery engine (line counts per GBHackers) that queried certificate records, DNS data, and subdomains.
- The vault contained 16,415 credential records (Cyber Security News; GBHackers reports 'over 16,000').
- The target corpus held roughly 498,000 URLs, including 449 French government subdomains.
- Operators self-hosted a Nous Research Hermes agent on a DeepSeek model with safety checks disabled.
- Documented activity included attempted token forgery against France's ANTAI traffic-fine system and account-access/withdrawal preparation at the Coinstable cryptocurrency exchange after a readable environment file was found.
- Additional materials included Société Générale vishing preparation and nearly 450,000 telecom records (GBHackers only).
- Caveats: intrusion ideas relied on exposed secrets and weak JWT configuration; the reports attribute discovery to automation and do not prove that AI directed each intrusion or that thefts succeeded.
Coverage timelineoldest first · each row is one article
- · 4d agoResearchers Discover Cybercrime Server Containing AI Tools, Phishing Kits and Stolen Data
GBHackers· 73
Researchers found an exposed French cybercrime server holding GHOST C2, phishing kits, AI agents, and over 16,000 stolen credentials.
- · 4d agoHackers Built an AI-Powered Attack Machine and Accidentally Left the Control Panel Open
Cyber Security News· 71
ThreatMon exposed a Blackhatsect0r server holding 16,415 credentials and roughly 498,000 target URLs.