THREAT OPS › Threat News › Discernment Deleted: Inside the Operation Server of BlackHatSect0r && DXQRTXX
Discernment Deleted: Inside the Operation Server of BlackHatSect0r && DXQRTXX
<h1>Discernment Deleted: Inside the Operation Server of BlackHatSect0r && DXQRTXX</h1> <p><em>A French-speaking crew deleted the line reading “discernment retained” from its AI agent’s memory, wrote “I am a weapon” in its place, and pointed the result at two governments, a crypto exchange, a US port authority and a list of pensioners.</em></p> <hr /> <p>An operation server belonging to the
MITRE ATT&CK techniques
- Acquire InfrastructureT1583
- Digital CertificatesT1596.003
- External DefacementT1491.002
- IP AddressesT1590.005
- JavaScriptT1059.007
- Email CollectionT1114
- DNS/Passive DNST1596.001
- Local Email CollectionT1114.001
- SAML TokensT1606.002
- MalwareT1587.001
- VulnerabilitiesT1588.006
- Automated CollectionT1119
- Application Layer ProtocolT1071
- Data from Local SystemT1005
- Exploit Public-Facing ApplicationT1190
- Credentials from Password StoresT1555
- Exfiltration Over Web ServiceT1567
- DomainsT1583.001
- Unsecured CredentialsT1552
- Vulnerability ScanningT1595.002
- Search Open Technical DatabasesT1596
- DefacementT1491
- Active ScanningT1595
- Search EnginesT1593.002
- Indicator RemovalT1070
- Virtual Private ServerT1583.003
- Shell HistoryT1552.003
- Web ServiceT1102
- Credentials In FilesT1552.001
- Financial TheftT1657
- Web CookiesT1606.001
- Steal Application Access TokenT1528
- Exfiltration Over C2 ChannelT1041
- Forge Web CredentialsT1606
- Search Open Websites/DomainsT1593
- Brute ForceT1110
- Valid AccountsT1078
- Non-Standard PortT1571
- Social Media AccountsT1585.001
- Obfuscated Files or InformationT1027
- Data Encrypted for ImpactT1486
- CredentialsT1589.001
- Bidirectional CommunicationT1102.002
- Exfiltration to Cloud StorageT1567.002
- ImpersonationT1684.001
- Establish AccountsT1585
- Network Denial of ServiceT1498
- Scanning IP BlocksT1595.001
- Web ProtocolsT1071.001
- Develop CapabilitiesT1587
- Reverse ShellAML.T0072
- ImpersonationAML.T0073
Indicators of compromise
- 48330848eb742161f86129735333f10bd0d7b4db5f801194896f50896761ebdfsha256
- 0e134b72aad30d938043df8f2d674e56b4c57399a27311759a9e88f4c41c19e5sha256
- 92dc24c9abc5baf7f2924c1872b14e747f600f5869ad159ec5d119a3aa02ca1fsha256
- 8082a62e976c513605fd1d6b0c0e15eb127e40ab6ea3a902080be526155380c3sha256
- 8c12f1b013f6d68121b76f4ef65c294273ab69151502d07ebef85994d656e5c9sha256
- db94077fcbcf030acff05334c5c0d153b8af6af24f6c5747c3600652e9baf4c0sha256
- c0bb940a65ed234d0250edc8c4c4062a3d404a87d17dc01da38890a5ba74bce8sha256
- CVE-2020-5902cve
- CVE-2021-22986cve
- CVE-2022-1388cve
- CVE-2023-46747cve
- CVE-2024-27198cve
- CVE-2021-3129cve
- CVE-2018-15133cve
- CVE-2022-22947cve
- CVE-2021-29447cve
- CVE-2026-42530cve
- bc1qg6m4733jazxca5ftc7aggdmsflwdwzlmlc3jmhbtc
- 217.156.122.129ipv4
- 37.221.66.43ipv4
- 72:8f:a5:80:ee:b5:3b:f7ipv6
- 48:79:9f:39:9d:4b:cd:fcipv6
- 97:a3:28:9e:2a:64:b3:60ipv6
- 08:a7:c9:a9:2a:cb:d8:1cipv6
Original source: https://socradar.io/blog/blackhatsect0r-dxqrtxx-operation-server/