An allegedly exposed server tied to the French-speaking BlackHatSect0r && DXQRTXX cybercrime crew hosted DXSCAN, a Go-based platform for mass IP scanning and credential harvesting, alongside phishing, extortion, and data-monetization tooling. The infrastructure also reportedly contained an AI-agent framework with safety refusals disabled and a vault holding 16,834 harvested credentials. Researchers distinguish the crew from its publicly facing affiliate, APT-90.
The group allegedly targeted or compromised French organizations and government services, New York public bodies, and a cryptocurrency exchange, and conducted a vishing operation impersonating Société Générale against older French telecom subscribers. Its observed activity relied largely on active scanning and exploitation of exposed cloud buckets, publicly accessible .env and Git files, weak or default JWT secrets, and client-exposed cryptographic material—not zero-day exploits—while using leased server infrastructure consistent with common adversary VPS-supported scanning, phishing, and credential-theft operations. Organizations should prioritize exposure management, storage access controls, secret rotation, JWT hardening, and remediation of publicly exposed development artifacts.

TTPs, infrastructure, and targeting history in one profile.
9 events from the most recent confirmed update back to the earliest known activity.
The group allegedly used a French telecom subscriber dataset containing 449,970 records for a vishing campaign impersonating Société Générale. The campaign sent 672 fraudulent debit-alert messages to 668 recipients over 85 minutes using hijacked SMTP relays and SendGrid sender identities.
A Laravel-based cryptocurrency exchange allegedly used the literal JWT signing secret "secret," allowing forged administrator tokens and exposure of 418 KYC records. Tooling attempted to disable withdrawal protections and transfer funds to actor-controlled wallets, but no funds moved because targeted accounts lacked withdrawable balances.
The group allegedly targeted ANTAI and amendes.gouv.fr using F5 BIG-IP reconnaissance, JWT-forgery attempts, request smuggling, SSRF, and brute-force tooling. Its toolset shortlisted several genuine but long-patched F5 BIG-IP vulnerabilities and incorrectly categorized the TeamCity flaw CVE-2024-27198 as an F5 vector.
An alleged extortion portal targeted the Dormitory Authority of the State of New York, New York Power Authority, Port Authority of New York and New Jersey, and New York City Small Business Services. The operation demanded 2 BTC and claimed exfiltration, encryption, and defacement of 67 S3 buckets; these were actor claims.
The crew publicly claimed to have taken files, Git history, an application .env file, and SMTP credentials from France's National Mountain Observation System (SNOSM).
BlackHatSect0r && DXQRTXX publicly claimed it compromised the French Equestrian Federation by accessing publicly available OVH S3 buckets and exposed application data.
Researchers reported that the operator used a Nous Research Hermes agent with a DeepSeek model and modified its identity and memory files to remove refusal behavior. Artifacts reportedly included SOUL.md, a .hermes directory, HERMES_DISABLE_SAFETY=1, and ghost_-prefixed processes.
The exposed infrastructure allegedly hosted the custom Go-based DXSCAN C2 v1.0 platform, which scanned targets for exposed credentials and queued 2,759,860 domains. Researchers reported 726,989 reached hosts and a vault containing 16,834 harvested credential entries, including cloud, database, SMTP, API, and source-control secrets.
Researchers attributed an allegedly exposed operation server to the French-speaking BlackHatSect0r && DXQRTXX crew, distinguishing APT-90 as a public-facing alliance and amplification partner. The recovered environment reportedly contained about 4.9 GB across 9,299 files and identified alleged active and retired C2 nodes in AlexHost SRL address space.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 9 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
3 references tracked. Mallory keeps watching after this page renders.
socradar.io
Open sourceattack.mitre.org
Open sourceattack.mitre.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.