A French-speaking cybercrime gang allegedly used an AI-powered attack platform to scan nearly 727,000 internet-facing hosts and collect 16,834 credentials from exposed files and weak configurations. The server reportedly contained 4.9 GB of data across 9,299 files, including a custom command-and-control platform, stolen credential vaults, phishing tools, extortion material, and AI-agent configuration files. Researchers said the platform queued 2,759,860 domains, reached 726,989 hosts, and generated more than 1.37 million IP addresses during the operation.
It sought out exposed .env files, cloud keys, database credentials, SMTP accounts, API tokens, Git files, and application configuration data. These included 5,109 generic secrets, 3,448 database credentials, 1,535 SMTP accounts, 936 API keys, 478 AWS keys, 343 GitHub credentials, and 68 Stripe keys.
The operation was primarily based on common security lapses, including easily accessible cloud storage, exposed configuration files, weak signing secrets, and sensitive key material embedded in browser-side code. The attackers manipulated the agent’s memory and identity files to remove refusal behavior and disable safety controls via the HERMES_DISABLE_SAFETY=1 setting. This approach could bypass many email security filters because the message did not need to deliver malware or redirect victims to a phishing website, according to Socradar.



.webp?w=1600&fit=1600,900&ssl=1)






