Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
AI-Powered Attack Tool Exposed: Threat Actors Left Control Panel Unsecured
September 28, 2026
Critical CVE-2023-38408 in libcue Exposes Linux, Windows, macOS Users to Tracking
September 28, 2026
NCSC Urges UK organizations to Patch for Citrix NetScaler ADC and Gateway 0-Day Vulnerabilities
September 28, 2026
Home/CyberSecurity News/AI-Powered Attack Tool Exposed: Threat Actors Left Control Panel Unsecured
CyberSecurity News

AI-Powered Attack Tool Exposed: Threat Actors Left Control Panel Unsecured

Key Takeaways A cybercriminal group, linked to Blackhatsect0r and DXQRTXX, inadvertently exposed the control panel of their AI-powered attack infrastructure. The exposed server contained a treasure...

Sarah simpson
Sarah simpson
September 28, 2026 5 Min Read
2 0

Key Takeaways

  • A cybercriminal group, linked to Blackhatsect0r and DXQRTXX, inadvertently exposed the control panel of their AI-powered attack infrastructure.
  • The exposed server contained a treasure trove of sensitive data, including over 16,000 credential records, nearly half a million target URLs (including French government subdomains), source code, chat logs, and fraud notes.
  • The group utilized automated tools written in Go and Python for continuous reconnaissance, targeting common misconfigurations and publicly exposed information rather than zero-day vulnerabilities.
  • This incident highlights how fundamental security oversights, such as inadequate access controls, can severely compromise even sophisticated attack operations.

A sophisticated cybercrime syndicate, reportedly associated with the groups known as Blackhatsect0r and DXQRTXX, left the command-and-control server for their automated attack system exposed, providing cybersecurity researchers with an unprecedented glimpse into their operations. The unsecured server contained a wealth of incriminating data, including a vault of stolen credentials, proprietary source code, internal chat logs, notes on fraudulent activities, and an extensive list of targets. This exposure offers a rare, real-time look at an active cybercriminal enterprise.

Table Of Content

  • Key Takeaways
  • Hackers Built an AI-Powered Attack Machine
  • Automated Scanning Meets Weak Secrets
  • Indicators of Compromise (IoCs)
  • What You Should Do

The group’s methodology combined broad-spectrum discovery with targeted exploitation against specific entities. Their infrastructure was designed to systematically identify vulnerable services, unearth leaked credentials, and pinpoint misconfigured application settings, compiling these findings for subsequent malicious activities.

Investigators uncovered 16,415 distinct credential records and approximately 498,000 target URLs within the exposed environment. Notably, this extensive list included 449 subdomains belonging to the French government. Analysts at ThreatMon successfully identified the publicly accessible server after discovering that its internal directories were left exposed without any authentication requirements. You can read more about their findings in a ThreatMon report.

ThreatMon emphasized the irony of this operational security failure, especially since the group had reportedly discussed opsec practices within their own Telegram channels. Despite these discussions, they exposed files that meticulously mapped their entire attack apparatus. This incident underscores how routine configuration errors can significantly amplify the impact of automated cyberattacks. Rather than relying on elusive zero-day exploits, the attackers leveraged commonly exposed files, easily guessable credentials, and sensitive data inadvertently made accessible by applications. Minor oversights by their victims became significant opportunities for the attackers, and, in this case, for researchers to observe.

Hackers Built an AI-Powered Attack Machine

The retrieved data paints a picture of an operation designed for sustained malicious activity rather than isolated, opportunistic attacks. The cybercriminals developed a robust command-and-control framework utilizing the Go programming language, complemented by a Python-based discovery engine that relentlessly scanned the internet for vulnerable systems.

This automated system systematically queried certificate records, analyzed DNS data, and repeatedly tested subdomains to identify potential targets. While automation efficiently surfaced promising candidates, human operators then focused their efforts on exploiting the most valuable systems. While previous reports suggested this group employed an AI-assisted workflow, ThreatMon’s analysis primarily documents automated discovery processes, rather than definitively proving AI directly orchestrated each intrusion. The exposed environment also provided a detailed look into the attackers’ operational playbook.

The server housed a comprehensive collection of operational materials, far beyond a single malware sample. This included credentials for databases, email accounts, cloud services, and developer platforms, alongside extensive logs detailing their research and exploitation attempts.

An exported Telegram chat log further corroborated the assessment that a small, coordinated team, with distinct roles, was behind these activities. The group’s Telegram channel, which became active in May, initially focused on sharing alleged stolen data before pivoting towards offensive tools. By mid-August, subscribers voted for attack tools over databases, suggesting a strategic shift towards broader capability dissemination, potentially making basic access and scanning utilities available to a wider array of threat actors.

The fundamental takeaway from this exposure is that sophisticated attack code cannot compensate for lax access controls. The group’s failure to secure their own infrastructure is a stark reminder of this principle.

Automated Scanning Meets Weak Secrets

Researchers highlighted two specific campaigns that exemplify the group’s transition from reconnaissance to attempted exploitation. One operation targeted France’s ANTAI traffic-fine payment system. The attackers meticulously examined browser-delivered application code, attempting to forge authentication tokens, manipulate request handling, and enumerate payment records.

This activity reinforces the critical importance of keeping token-signing material off client-side systems. The second campaign focused on a cryptocurrency exchange. Here, operators discovered a publicly readable environment file, which they leveraged to seek elevated access, review account balances, and prepare for illicit withdrawals. Similar incidents, like the recent Vite server credential theft, underscore how publicly accessible development and configuration files can expose cloud keys, passwords, and ultimately lead to widespread compromise.

Significantly, neither of these attack chains relied on a confirmed zero-day vulnerability. Instead, both exploited common weaknesses: exposed configuration files, hardcoded secrets, and applications that inadvertently disclosed sensitive information to client browsers. The threat posed by such vulnerabilities intensifies when attackers can deploy continuous, automated scanning, eliminating the need for manual initiation of each scan.

Indicators of Compromise (IoCs)

Type Indicator Description
File name ghost_token_forger.py Script referenced in the ANTAI targeting activity
File name coinstable_admin.py Script referenced in the cryptocurrency-exchange activity
File name coinstable_drain.py Script referenced in the cryptocurrency-exchange activity
JWT passphrase troiscitronbosechatjouerbelierlawingssourisfermentpoids JWT_BLOB value associated with the ANTAI activity
JWT signing secret secret JWT signing secret associated with the Coinstable activity
IP address 212.27.13.112 Coinstable backend bypassing CDN
IP address 90.102.74.9 F5-fronted ANTAI backend

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

What You Should Do

  • Regularly audit and remove configuration and version-control files from publicly accessible paths.
  • Ensure token-signing keys are stored securely on servers and never exposed client-side.
  • Replace all weak or default credentials immediately and implement strong, unique passwords for all services.
  • Rotate any credentials that may have been exposed or are suspected of compromise.
  • Review security logs frequently for patterns of repeated reconnaissance attempts.
  • Restrict access to administrative interfaces and implement multi-factor authentication (MFA) wherever possible.
  • Continuously monitor your external digital footprint for accidental exposures of sensitive data or misconfigurations.
  • Promptly investigate any matching indicators of compromise (IoCs) and preserve relevant logs for forensic analysis.
  • Verify authentication activity for any signs of stolen credentials or forged tokens being used.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackExploitHackerMalwareSecurityThreatzero-day

Share Article

Sarah simpson

Sarah simpson

Sarah is a cybersecurity journalist specializing in threat intelligence and malware analysis. With over 8 years of experience covering APT groups, zero-day exploits, and advanced persistent threats, Sarah brings deep technical expertise to breaking cybersecurity news. Previously, she worked as a security researcher at leading threat intelligence firms, where she analyzed malware samples and tracked cybercriminal operations. Sarah holds a Master's degree in Computer Science with a focus on cybersecurity and is a regular contributor to major security conferences.

Previous Post

Critical CVE-2023-38408 in libcue Exposes Linux, Windows, macOS Users to Tracking

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
ShinyHunters Exploits Critical Oracle PeopleSoft CVE-2024-21095 to Deploy Web Shells
September 28, 2026
Attackers Intercept AI Prompts via Fake Jev AI Stores
September 28, 2026
NVIDIA Unveils Open Safety Platform for Autonomous AI Agents With 100 Partners
September 28, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
David kimber
David kimber
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us