DXQRTXX, also associated with the name BlackHatSect0r, is a cybercrime actor linked to an automated operation combining a customized AI agent connected to a DeepSeek model with the DXSCAN scanning and control platform. The operation conducted high-volume internet reconnaissance, web-service fingerprinting, and searches for exposed configuration data, cloud credentials, database credentials, source-control artifacts, API keys, and weak JWT signing secrets. It primarily abused exposed secrets and insecure default configurations rather than a confirmed novel vulnerability. The actor’s operation maintained a credential collection containing database, SMTP, cloud, source-control, payment-service, and other API credentials. Validated SMTP accounts were prepared for phishing delivery. Its phishing activity included bank impersonation and voice-phishing lures that directed recipients to call attacker-controlled numbers, reducing reliance on malicious links or attachments. The operation also used cloned phishing pages exposed through tunneling infrastructure, automated reporting through Telegram, and extortion-related materials. Public proof-of-concept exploit code for several known vulnerabilities was referenced by the toolset, but confirmed exploitation of a newly discovered vulnerability has not been established.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
10 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
9 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A named participant in the automated cybercrime operation jointly attributed with BlackHatSect0r. The operation used AI-assisted scanning to identify exposed credentials and configuration secrets, supported phishing and extortion activity, and maintained a credential vault containing thousands of records.
Associated with BlackHatSect0r in an automated cybercrime operation that harvested exposed secrets and credentials, validated access, supported phishing, and conducted extortion-related activity through the DXSCAN platform.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.