socradar.io 16 Sept 2026, 11:25 UTC

AI-Driven BlackHatSect0r Crew Exposed Millions of Hosts and Secrets

AI-Driven BlackHatSect0r Crew Exposed Millions of Hosts and Secrets
CyberSIXT Evidence Panel Source marked as original reporting
Threat Actor
BlackHatSect0r & DXQRTXX

SOCRADAR says an internet-exposed operation server linked to the French-speaking crew BlackHatSect0r && DXQRTXX contained 4.9GB across 9,299 files, including a Go-based command-and-control platform, a 16,834-entry credential vault and tooling for scanning, extortion, phishing and harassment. The research was based on static analysis, passive observation of the live panel and open-source material; no binaries were executed and no actor systems were accessed using credentials.

The infrastructure included two AlexHost SRL virtual servers in Moldova, with the active address at 217.156.122[.]129 and a retired node at 37.221.66[.]43. Its DXSCAN platform reportedly queued 2,759,860 domains, reached 726,989 hosts and generated 1,374,300 IP addresses, while searching exposed configuration files for secrets and sending findings to Telegram.

The report says the crew’s AI agent used a Nous Research Hermes framework with a DeepSeek model. The operator removed refusal-related instructions from its memory and identity files, disabled safety controls with `HERMES_DISABLE_SAFETY=1`, and configured automated worker processes to scan and harvest data continuously.

SOCRadar found no genuine zero-days: confirmed compromises were attributed to public cloud buckets, exposed `.env` files, default or guessable signing secrets, and key material shipped in client-side code. Reported victims or targets included the French Equestrian Federation, the French National Mountain Observation System, four New York public bodies, a cryptocurrency exchange and a French telecom subscriber database containing 449,970 records.

The researchers also documented a bank-impersonation vishing campaign that sent 672 messages to 668 recipients in 85 minutes. Defenders are advised to investigate the listed indicators, review the 251 hashed SSH `known_hosts` entries, secure object storage, remove exposed configuration files, rotate compromised secrets and monitor for the crew’s distinctive processes, strings and Telegram traffic.

View full article

Article by CyberSIXT