AI-Powered Attack Tool Exposed: Threat Actors Left Control Panel Unsecured
Key Takeaways A cybercriminal group, linked to Blackhatsect0r and DXQRTXX, inadvertently exposed the control panel of their AI-powered attack infrastructure. The exposed server contained a treasure...
Key Takeaways
- A cybercriminal group, linked to Blackhatsect0r and DXQRTXX, inadvertently exposed the control panel of their AI-powered attack infrastructure.
- The exposed server contained a treasure trove of sensitive data, including over 16,000 credential records, nearly half a million target URLs (including French government subdomains), source code, chat logs, and fraud notes.
- The group utilized automated tools written in Go and Python for continuous reconnaissance, targeting common misconfigurations and publicly exposed information rather than zero-day vulnerabilities.
- This incident highlights how fundamental security oversights, such as inadequate access controls, can severely compromise even sophisticated attack operations.
A sophisticated cybercrime syndicate, reportedly associated with the groups known as Blackhatsect0r and DXQRTXX, left the command-and-control server for their automated attack system exposed, providing cybersecurity researchers with an unprecedented glimpse into their operations. The unsecured server contained a wealth of incriminating data, including a vault of stolen credentials, proprietary source code, internal chat logs, notes on fraudulent activities, and an extensive list of targets. This exposure offers a rare, real-time look at an active cybercriminal enterprise.
Table Of Content
The group’s methodology combined broad-spectrum discovery with targeted exploitation against specific entities. Their infrastructure was designed to systematically identify vulnerable services, unearth leaked credentials, and pinpoint misconfigured application settings, compiling these findings for subsequent malicious activities.
Investigators uncovered 16,415 distinct credential records and approximately 498,000 target URLs within the exposed environment. Notably, this extensive list included 449 subdomains belonging to the French government. Analysts at ThreatMon successfully identified the publicly accessible server after discovering that its internal directories were left exposed without any authentication requirements. You can read more about their findings in a ThreatMon report.
ThreatMon emphasized the irony of this operational security failure, especially since the group had reportedly discussed opsec practices within their own Telegram channels. Despite these discussions, they exposed files that meticulously mapped their entire attack apparatus. This incident underscores how routine configuration errors can significantly amplify the impact of automated cyberattacks. Rather than relying on elusive zero-day exploits, the attackers leveraged commonly exposed files, easily guessable credentials, and sensitive data inadvertently made accessible by applications. Minor oversights by their victims became significant opportunities for the attackers, and, in this case, for researchers to observe.
Hackers Built an AI-Powered Attack Machine
The retrieved data paints a picture of an operation designed for sustained malicious activity rather than isolated, opportunistic attacks. The cybercriminals developed a robust command-and-control framework utilizing the Go programming language, complemented by a Python-based discovery engine that relentlessly scanned the internet for vulnerable systems.
This automated system systematically queried certificate records, analyzed DNS data, and repeatedly tested subdomains to identify potential targets. While automation efficiently surfaced promising candidates, human operators then focused their efforts on exploiting the most valuable systems. While previous reports suggested this group employed an AI-assisted workflow, ThreatMon’s analysis primarily documents automated discovery processes, rather than definitively proving AI directly orchestrated each intrusion. The exposed environment also provided a detailed look into the attackers’ operational playbook.
The server housed a comprehensive collection of operational materials, far beyond a single malware sample. This included credentials for databases, email accounts, cloud services, and developer platforms, alongside extensive logs detailing their research and exploitation attempts.
An exported Telegram chat log further corroborated the assessment that a small, coordinated team, with distinct roles, was behind these activities. The group’s Telegram channel, which became active in May, initially focused on sharing alleged stolen data before pivoting towards offensive tools. By mid-August, subscribers voted for attack tools over databases, suggesting a strategic shift towards broader capability dissemination, potentially making basic access and scanning utilities available to a wider array of threat actors.
The fundamental takeaway from this exposure is that sophisticated attack code cannot compensate for lax access controls. The group’s failure to secure their own infrastructure is a stark reminder of this principle.
Automated Scanning Meets Weak Secrets
Researchers highlighted two specific campaigns that exemplify the group’s transition from reconnaissance to attempted exploitation. One operation targeted France’s ANTAI traffic-fine payment system. The attackers meticulously examined browser-delivered application code, attempting to forge authentication tokens, manipulate request handling, and enumerate payment records.
This activity reinforces the critical importance of keeping token-signing material off client-side systems. The second campaign focused on a cryptocurrency exchange. Here, operators discovered a publicly readable environment file, which they leveraged to seek elevated access, review account balances, and prepare for illicit withdrawals. Similar incidents, like the recent Vite server credential theft, underscore how publicly accessible development and configuration files can expose cloud keys, passwords, and ultimately lead to widespread compromise.
Significantly, neither of these attack chains relied on a confirmed zero-day vulnerability. Instead, both exploited common weaknesses: exposed configuration files, hardcoded secrets, and applications that inadvertently disclosed sensitive information to client browsers. The threat posed by such vulnerabilities intensifies when attackers can deploy continuous, automated scanning, eliminating the need for manual initiation of each scan.
Indicators of Compromise (IoCs)
| Type | Indicator | Description |
|---|---|---|
| File name | ghost_token_forger.py |
Script referenced in the ANTAI targeting activity |
| File name | coinstable_admin.py |
Script referenced in the cryptocurrency-exchange activity |
| File name | coinstable_drain.py |
Script referenced in the cryptocurrency-exchange activity |
| JWT passphrase | troiscitronbosechatjouerbelierlawingssourisfermentpoids |
JWT_BLOB value associated with the ANTAI activity |
| JWT signing secret | secret |
JWT signing secret associated with the Coinstable activity |
| IP address | 212.27.13.112 |
Coinstable backend bypassing CDN |
| IP address | 90.102.74.9 |
F5-fronted ANTAI backend |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
What You Should Do
- Regularly audit and remove configuration and version-control files from publicly accessible paths.
- Ensure token-signing keys are stored securely on servers and never exposed client-side.
- Replace all weak or default credentials immediately and implement strong, unique passwords for all services.
- Rotate any credentials that may have been exposed or are suspected of compromise.
- Review security logs frequently for patterns of repeated reconnaissance attempts.
- Restrict access to administrative interfaces and implement multi-factor authentication (MFA) wherever possible.
- Continuously monitor your external digital footprint for accidental exposures of sensitive data or misconfigurations.
- Promptly investigate any matching indicators of compromise (IoCs) and preserve relevant logs for forensic analysis.
- Verify authentication activity for any signs of stolen credentials or forged tokens being used.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.