An internet-exposed cybercrime server linked to the BlackHatSect0r and DXQRTXX personas, revealing an operational environment that allegedly combined AI-assisted automation.
Custom command-and-control tooling, phishing resources, stolen credentials, target lists, and internal operator communications.
The exposure is notable not only for the scale of the material recovered, but also for its irony.
Weeks later, infrastructure attributed to the same ecosystem was itself found accessible because of a basic access-control failure.
The server reportedly exposed the operational workspace of a French-speaking cybercrime crew active between at least May and August 2026.
Researchers described the collection as far more than a single leaked database or isolated malware sample: it included actively developed source code, credential stores, Telegram chat exports, reconnaissance data, phishing material, fraud tooling, and financial targeting notes.
According to the investigation, the exposed environment contained thousands of files and several gigabytes of operational data.
A related analysis reported a custom Go-based scanning and C2 platform, credential-harvesting tooling, phishing infrastructure, extortion resources, and shell-history artifacts.
The infrastructure was reportedly reviewed using static analysis, passive observation, and public-source research rather than active engagement with attacker-controlled systems.
The recovered credential vault allegedly held more than 16,000 records, including database access, SMTP accounts, API keys, AWS credentials access..
Researchers also identified a large target corpus containing approximately 498,000 URLs, including hundreds of French government subdomains.
The crew allegedly developed a bespoke command-and-control framework called GHOST C2 v6.0, written in Go and comprising roughly 13,000 lines of code.
Its modules were designed for scanning, credential extraction, exploitation workflows, and reverse-shell handling.
Alongside it sat a Python-based “Discovery Engine” of nearly 18,000 lines.
The tool was reportedly built to identify new targets continuously by querying Certificate Transparency records, checking passive DNS data, and brute-forcing subdomains associated with keywords such as “crypto,” “wallet,” and “exchange.”
This level of automation turns routine internet reconnaissance into a persistent attack pipeline rather than a manually executed task.
Threatmon Researchers said that, an operator using the DXQRTXX identity reportedly urged followers on Telegram to improve their operational security after discussing another phishing crew’s publicly exposed server.
Separate reporting on the same crew said its operators used a self-hosted Nous Research Hermes AI agent connected to a DeepSeek model.
The operators allegedly removed safety-oriented instructions and set the HERMES_DISABLE_SAFETY=1 environment variable, enabling the agent to support scanning, secret discovery, Telegram reporting, phishing preparation, and workflow automation.
The dataset reportedly indicated that the group combined broad scanning with deeper manual research against selected financial and government targets.
One operation focused on France’s ANTAI traffic-fine payment service, where the actors allegedly examined client-side Angular code for embedded cryptographic values and token-generation logic.
Another set of tools targeted Coinstable.io, a cryptocurrency exchange.
The scripts reportedly relied on a JWT signing secret configured as the literal value “secret,” allowing forged administrative claims and attempts to enumerate accounts and prepare withdrawal requests.
These claims should be interpreted carefully: the existence of tooling or scripts does not independently prove that a successful compromise, theft, or withdrawal occurred.
The most important takeaway is that the alleged intrusion chains did not depend on novel zero-days.
Instead, they centered on exposed .env files, browser-delivered secrets, weak JWT configuration, publicly reachable storage, and other preventable deployment failures.
The crew operated a Telegram channel with hundreds of subscribers, using it to promote alleged data leaks, distribute or advertise offensive tooling, amplify political messaging, and interact with followers.
By August, a poll reportedly showed stronger audience interest in offensive tools than in stolen databases, suggesting a shift from public leak promotion toward enabling other cybercriminals.
Researchers also identified potential phishing and vishing preparation. One report described a dataset containing nearly 450,000 French telecom subscriber records.
A targeted social-engineering campaign impersonating Société Générale, aimed at encouraging victims to call an attacker-controlled number rather than click a malicious link.
The incident demonstrates how AI-enabled automation can magnify conventional security failures.
Organizations should immediately audit public-facing infrastructure for exposed configuration files, cloud storage, source-code repositories, CI/CD artifacts, backup directories, and front-end JavaScript containing secrets.
Credentials found in exposed locations must be rotated, not merely removed.
Security teams should also replace default JWT secrets, move cryptographic material and token-generation functions to server-side systems, enforce authentication on administrative directories, and monitor for suspicious AI-agent artifacts such as .hermes directories, SOUL.md files, and HERMES_DISABLE_SAFETY=1.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC

