Sep 30, 2026 DISPATCH // HARDWARE, CODE & PLATFORMS

Cybercrime Server Leak Exposes AI Driven Attacks and Massive Data Trove

A cybercrime server tied to BlackHatSect0r and DXQRTXX was left exposed online, revealing AI-powered attack tools, phishing kits, and a vast cache of stolen data-underscoring the real-world risks of basic security lapses.
Cybercrime Server Leak Exposes AI Driven Attacks and Massive Data Trove Nerds Magazine © nerdsmagazine.com
Cybercrime Server Leak Exposes AI Driven Attacks and Massive Data Trove © nerdsmagazine.com

Investigators did not expect to find a cybercrime crew sabotaging itself. But that is exactly what happened when BlackHatSect0r and DXQRTXX left their own server wide open. The group's entire operation was suddenly visible to anyone who looked.

Researchers found more than a few files. They uncovered the full working environment of a French-speaking cybercrime crew active from at least May to August 2026. The exposed server held thousands of files and several gigabytes of data. There were custom command-and-control tools, phishing kits, credential dumps, target lists, and even exports of internal Telegram chats.

ThreatMon's September 2026 analysis confirmed that the group left not just data, but their entire operational infrastructure publicly accessible, allowing for a rare technical deep dive into their methods.

The mistake did not end there. Weeks after the first discovery, more servers tied to the same group were found exposed. The reason was simple: a basic access-control failure. The group had even told its followers to tighten security after another crew's leak. Their own advice fell flat. Their workspace was left open for anyone to watch and analyze.

The toolkit was huge. The credential vault alone held over 16,000 records. These included database logins, SMTP accounts, API keys, and AWS credentials. The target list was even bigger. About 498,000 URLs were catalogued for attack. Hundreds of these belonged to French government subdomains. According to a CyberSecurityNews investigation, 449 subdomains were tied to French government entities. The scale of automated scanning and credential theft was massive.

At the center was a custom Go-based command-and-control system called GHOST C2 v6.0. It had about 13,000 lines of code. Its modules handled scanning, credential theft, exploitation, and reverse-shell control. Alongside it ran a Python "Discovery Engine" with nearly 18,000 lines. This engine hunted for new targets by querying Certificate Transparency records, checking passive DNS, and brute-forcing subdomains with keywords like "crypto," "wallet," and "exchange."

ThreatMon publicly stated that its CTI report examines the infrastructure and methods behind the group's activity, providing indicators of compromise and actionable recommendations for defenders.

ThreatMon

This was not a crew poking around by hand. Automation ran the show. Reconnaissance became a pipeline, feeding phishing and fraud campaigns with a steady stream of new targets and weak spots.

AI was not just a buzzword. The group used a self-hosted Nous Research Hermes AI agent, linked to a DeepSeek model. All safety features were turned off on purpose. The AI helped with scanning, secret discovery, Telegram reporting, phishing prep, and automating workflows. The data showed the group mixing broad automated scans with targeted manual research, especially against financial and government targets.

One attack focused on France's ANTAI traffic-fine payment service. The crew picked apart Angular client code to find cryptographic values and token logic. Another attack hit Coinstable.io, a crypto exchange. The crew found a JWT signing secret set to "secret." That let them forge admin claims and run account enumeration scripts. These tools do not prove theft happened. The real story is the group's reliance on exposed config files, weak JWT setups, and other basic mistakes. They did not need zero-day exploits.

The group's Telegram channel had hundreds of subscribers. It became a hub for sharing alleged data leaks, spreading attack tools, and pushing political messages. By August, a poll showed the audience cared more about offensive tools than stolen databases. The focus was shifting. The crew was enabling other cybercriminals, not just leaking data for attention.

Phishing and vishing prep was clear. One dataset reportedly held nearly 450,000 French telecom subscriber records. This fueled a targeted social-engineering campaign. Attackers pretended to be Société Générale and told victims to call attacker-controlled numbers instead of clicking links.

This leak is a warning. AI-powered automation can make small security mistakes explode. Organizations need to check their public-facing assets for exposed config files, cloud storage, source code, CI/CD artifacts, backup folders, and front-end JavaScript with secrets. Credentials found in the open must be rotated, not just deleted. Security teams should replace default JWT secrets, move crypto and token logic server-side, lock down admin directories, and watch for AI-agent artifacts like .hermes folders, SOUL.md files, and the HERMES_DISABLE_SAFETY=1 variable.

When cybercriminals use AI to automate attacks but still get caught by their own mistakes, the lesson is obvious. Most breaches happen because of preventable errors, not genius. The more advanced the toolkit, the bigger the fallout from simple lapses. In the end, human error and ignored basics remain the biggest threat-criminal or not.

Topics:
Cybersecurity Privacy & Data Security #AI Agents #Cybersecurity Threats & Attacks #Phishing
Evan Solberg Technology publisher and editor-in-chief Nerds Magazine
Editor-in-Chief

Evan Solberg

Evan Solberg is the Founder, Owner, Publisher, and Editor-in-Chief of NerdsMagazine, where he covers consumer technology, software, artificial intelligence, privacy, and digital products. His editorial approach focuses on what technology actually does for readers, what it costs, where it falls short, and which claims deserve closer scrutiny.