#ParsedReport #CompletenessHigh
16-09-2026
Discernment Deleted: Inside the Operation Server of BlackHatSect0r && DXQRTXX
https://socradar.io/blog/blackhatsect0r-dxqrtxx-operation-server/
Report completeness: High
Actors/Campaigns:
Blackhatsector_dxqrtxx (motivation: financially_motivated, hacktivism)
Threats:
Hermes
Ghost
Credential_harvesting_technique
Smuggling_technique
Js-smuggler
Ngrok_tool
Victims:
Public sector, Sports federation, Mountain safety service, Transportation authority, Power authority, Small business services, Cryptocurrency exchange, Telecommunications subscribers, Bank customers, Private individuals, have more...
Industry:
Financial, Retail, Education, Government, Telco
Geo:
New york, Russia, Israel, Spain, Moldova, Belgium, Germany, Russian, United states, Netherlands, United kingdom, Switzerland, France, Luxembourg, French, Italy
CVEs:
CVE-2026-42530 [Vulners]
CVSS V3.1: 8.1,
Vulners: Exploitation: Unknown
Soft:
- f5 nginx_gateway_fabric (le1.6.2, <2.6.4)
- f5 nginx_ingress_controller (le3.7.2, <5.5.1, 4.0.0, 4.0.1)
- f5 nginx_instance_manager (le2.22.0)
- f5 nginx_open_source (<1.31.2)
CVE-2022-1388 [Vulners]
CVSS V3.1: 9.8,
Vulners: Exploitation: True
Soft:
- f5 big-ip_access_policy_manager (le11.6.5, le12.1.6, <13.1.5, <14.1.4.6, <15.1.5.1)
- f5 big-ip_advanced_firewall_manager (le11.6.5, le12.1.6, <13.1.5, <14.1.4.6, <15.1.5.1)
- f5 big-ip_analytics (le11.6.5, le12.1.6, <13.1.5, <14.1.4.6, <15.1.5.1)
- f5 big-ip_application_acceleration_manager (le11.6.5, le12.1.6, <13.1.5, <14.1.4.6, <15.1.5.1)
- f5 big-ip_application_security_manager (le11.6.5, le12.1.6, <13.1.5, <14.1.4.6, <15.1.5.1)
have more...
CVE-2021-3129 [Vulners]
CVSS V3.1: 9.8,
Vulners: Exploitation: True
Soft:
- facade ignition (<2.5.2)
CVE-2018-15133 [Vulners]
CVSS V3.1: 8.1,
Vulners: Exploitation: True
Soft:
- laravel (le5.5.40, le5.6.29)
CVE-2021-22986 [Vulners]
CVSS V3.1: 9.8,
Vulners: Exploitation: True
Soft:
- f5 big-ip_access_policy_manager (<12.1.5.3, <13.1.3.6, <14.1.4, <15.1.2.1, <16.0.1.1)
- f5 big-ip_advanced_firewall_manager (<12.1.5.3, <13.1.3.6, <14.1.4, <15.1.2.1, <16.0.1.1)
- f5 big-ip_advanced_web_application_firewall (<12.1.5.3, <13.1.3.6, <14.1.4, <15.1.2.1, <16.0.1.1)
- f5 big-ip_analytics (<12.1.5.3, <13.1.3.6, <14.1.4, <15.1.2.1, <16.0.1.1)
- f5 big-ip_application_acceleration_manager (<12.1.5.3, <13.1.3.6, <14.1.4, <15.1.2.1, <16.0.1.1)
have more...
CVE-2021-29447 [Vulners]
CVSS V3.1: 7.1,
Vulners: Exploitation: Unknown
Soft:
- wordpress (<5.7.1)
CVE-2020-5902 [Vulners]
CVSS V3.1: 9.8,
Vulners: Exploitation: True
Soft:
- f5 big-ip_access_policy_manager (<11.6.5.2, <12.1.5.2, <13.1.3.4, <14.1.2.6, le15.0.1.4)
- f5 big-ip_advanced_firewall_manager (<11.6.5.2, <12.1.5.2, <13.1.3.4, <14.1.2.6, <15.0.1.4)
- f5 big-ip_advanced_web_application_firewall (<11.6.5.2, <12.1.5.2, <13.1.3.4, <14.1.2.6, <15.0.1.4)
- f5 big-ip_analytics (<11.6.5.2, <12.1.5.2, <13.1.3.4, <14.1.2.6, <15.0.1.4)
- f5 big-ip_application_acceleration_manager (<11.6.5.2, <12.1.5.2, <13.1.3.4, <14.1.2.6, <15.0.1.4)
have more...
CVE-2024-27198 [Vulners]
CVSS V3.1: 9.8,
Vulners: Exploitation: True
Soft:
- jetbrains teamcity (<2023.11.4)
CVE-2022-22947 [Vulners]
CVSS V3.1: 10.0,
Vulners: Exploitation: True
Soft:
- vmware spring_cloud_gateway (<3.0.7, 3.1.0)
CVE-2023-46747 [Vulners]
CVSS V3.1: 9.8,
Vulners: Exploitation: True
Soft:
- f5 big-ip_access_policy_manager (le13.1.5, le14.1.5, le15.1.10, le16.1.4, le17.1.1)
TTPs:
Tactics: 8
Technics: 32
IOCs:
IP: 2
File: 6
Coin: 2
Hash: 7
Soft:
Telegram, DeepSeek, Android, MySQL, PostgreSQL, OpenSSH, Redis, Drupal, Laravel, BIG-IP, have more...
Crypto:
bitcoin
Algorithms:
ed25519, aes-cbc, pbkdf2, ecdsa, sha256
Win API:
TE
Languages:
python, golang, swift, javascript, php
YARA: Found
Post #32516
25