Hackers Built an AI-Powered Attack Machine and Accidentally Left the Control Panel Open

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com


A criminal crew linked to Blackhatsect0r and DXQRTXX built an automated system designed to find weaknesses across the internet. Its exposed server revealed a credential vault, source code, chat logs, fraud notes, and a target list, offering a rare look inside an operation in progress.

The group combined mass discovery with focused work against selected targets. Its infrastructure sought exposed services, leaked credentials, and weak application settings, then organized the results for later use.

Researchers found 16,415 credential records and roughly 498,000 target URLs, including 449 French government subdomains. ThreatMon analysts identified the publicly reachable environment after its internal directories were left accessible without authentication.

ThreatMon said in a report shared with Cyber Security News (CSN) that the error was striking because the group had discussed operational security in its own Telegram channel, yet exposed files that mapped its activities.

The case shows how routine configuration mistakes can magnify automated attacks. Rather than depending on a novel zero-day, the operators looked for exposed files, predictable credentials, and secrets placed where applications could reveal them. Small oversights became opportunities.

Hackers Built an AI-Powered Attack Machine

The recovered material describes an operation built for persistence rather than one-off attempts. The crew developed a command-and-control framework in Go and a Python discovery engine that continually searched for systems.

It queried certificate records, reviewed DNS data, and tested subdomains repeatedly, supplying potential targets. Automation surfaced candidates while operators studied valuable systems.

Earlier reporting on AI linked this same crew to an AI-assisted workflow, but ThreatMon’s account documents automated discovery rather than proving AI directed each attempted intrusion. The exposed environment also revealed the attackers’ playbook.

The server held operational material, not a lone malware sample. It contained database, email, cloud, and developer credentials, plus research and exploitation logs.

Public directory listing (Source - ThreatMon)
Public directory listing (Source – ThreatMon)

A Telegram export recorded coordination among several handles, supporting the assessment that a small crew with separate roles ran the activity.

The channel became active in May and soon posted alleged stolen data before shifting toward offensive tools. By mid-August, subscribers voted for tools over databases.

That change suggests an effort to spread capabilities, potentially making basic access and scanning tools available to a wider range of actors.

The exposure laid bare the group’s operational environment. Its failure shows that sophisticated code does not offset poor access controls.

Automated Scanning Meets Weak Secrets

Researchers highlighted two targeted efforts that show the move from discovery to attempted abuse. One involved France’s ANTAI traffic-fine payment system, where the group examined browser-delivered application code and tried to create authentication tokens, test request handling, and enumerate payment records.

The activity shows why signing material must stay off client-side systems. The other campaign targeted a cryptocurrency exchange after operators found a readable environment file.

They sought elevated access, reviewed accounts and balances, and prepared withdrawals. Recent reporting on Vite server credential theft likewise shows how public development and configuration files can expose cloud keys, passwords, and routes to broader compromise.

Neither chain depended on a confirmed zero-day, according to the report. Both relied on exposed configuration files, hardcoded secrets, and applications that disclosed sensitive information to browsers.

The danger grows when attackers can search constantly instead of waiting for a person to begin each scan. Security teams should remove configuration and version-control files from public paths, retain token-signing keys only on servers, replace weak or default secrets, and rotate any credential that may have been exposed.

They should review logs for repeated reconnaissance, restrict administration interfaces, and monitor their external footprint continuously.

Guidance on hardcoded token signing keys reinforces that a predictable secret can let an intruder manufacture trusted-looking access.

Organizations should investigate matching indicators quickly, preserve relevant logs, and check authentication activity for signs that stolen credentials or forged tokens were used.

The chief lesson is not that every group will create an extensive platform. It is that patient, automated discovery makes known mistakes easier to find.

Regular exposure checks, timely remediation, and prompt review of suspicious requests can shrink the window these operations need.

Indicators of compromise (IoCs):-

Type Indicator Description
File name ghost_token_forger.py Script referenced in the ANTAI targeting activity
File name coinstable_admin.py Script referenced in the cryptocurrency-exchange activity
File name coinstable_drain.py Script referenced in the cryptocurrency-exchange activity
JWT passphrase troiscitronbosechatjouerbelierlawingssourisfermentpoids JWT_BLOB value associated with the ANTAI activity
JWT signing secret secret JWT signing secret associated with the Coinstable activity
IP address 212.27.13.112 Coinstable backend bypassing CDN
IP address 90.102.74.9 F5-fronted ANTAI backend

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC

The post Hackers Built an AI-Powered Attack Machine and Accidentally Left the Control Panel Open appeared first on Cyber Security News.