VYPR
breachPublished Sep 28, 2026· 1 source

Criminal Crew Exposes AI-Powered Attack Machine After Configuration Error

A cybercriminal group linked to Blackhatsect0r and DXQRTXX accidentally exposed a sophisticated AI-powered attack machine, revealing credential vaults, source code, and extensive target lists.

A criminal crew, identified as being associated with the aliases Blackhatsect0r and DXQRTXX, has inadvertently exposed a powerful automated attack system, offering a rare glimpse into the operational methods of modern cybercriminals. The exposed server contained a wealth of sensitive data, including credential vaults, source code for their tools, internal chat logs, notes on fraudulent activities, and a comprehensive list of targets. This discovery highlights an operation that skillfully blends broad, automated discovery with more focused, targeted attacks against specific entities.

The infrastructure meticulously scanned the internet for exposed services, leaked credentials, and weak application configurations. The collected data was then systematically organized for subsequent exploitation. Security researchers from ThreatMon identified the publicly accessible environment after discovering that its internal directories were left unprotected and accessible without any form of authentication. This oversight is particularly striking given the group's documented discussions about operational security within their own Telegram channel, yet they ultimately exposed files that mapped their entire operation.

The incident underscores how common configuration mistakes can significantly amplify the impact of automated attacks. Rather than relying on novel zero-day exploits, the operators leveraged readily available information such as exposed files, predictable default credentials, and secrets embedded within applications that were inadvertently disclosed. These seemingly minor oversights provided substantial opportunities for the attackers.

The recovered materials describe an operation built for persistence and sustained activity rather than one-off attacks. The crew developed a command-and-control framework written in Go, complemented by a Python-based discovery engine that continuously searched for vulnerable systems. This engine queried certificate records, analyzed DNS data, and repeatedly tested subdomains, effectively supplying a steady stream of potential targets. While automation handled the initial discovery, human operators then focused on analyzing and prioritizing the most valuable systems.

Earlier reports had linked this same crew to AI-assisted workflows, but ThreatMon's analysis specifically documents automated discovery processes, rather than definitively proving that AI directed every attempted intrusion. The exposed server also provided a detailed look at the attackers' methodology. It contained not just malware samples, but also operational materials including database, email, cloud, and developer credentials, alongside research and exploitation logs.

A Telegram export revealed coordination among several user handles, supporting the assessment that a small, specialized crew was behind the operation. The channel became active in May, initially posting alleged stolen data before shifting its focus to offensive tools. By mid-August, subscribers reportedly voted for tools over databases, suggesting an effort to broaden the distribution of their capabilities and potentially make basic access and scanning tools available to a wider range of actors.

Researchers highlighted two specific targeted efforts that exemplify the transition from discovery to attempted abuse. One involved France's ANTAI traffic-fine payment system, where the group analyzed browser-delivered application code, attempting to forge authentication tokens, test request handling, and enumerate payment records. This activity demonstrates the critical importance of securing signing material and preventing its exposure on client-side systems. The second campaign targeted a cryptocurrency exchange after operators discovered a readable environment file. They sought elevated access, reviewed account details, and prepared to initiate withdrawals.

Security teams are advised to implement robust measures, including removing configuration and version-control files from public paths, securely storing token-signing keys exclusively on servers, replacing weak or default secrets, and promptly rotating any credentials that may have been exposed. Continuous monitoring of external footprints, review of logs for reconnaissance activity, and restriction of administration interfaces are also crucial steps in mitigating such threats. The core lesson is that patient, automated discovery, combined with common configuration errors, makes known vulnerabilities easier to exploit, emphasizing the need for diligent security practices.

Synthesized by Vypr AI