Blackhatsect0r & DXQRTXX Global Operations

This report is about ‘Ransomware 2026 Report August’.

Download Report

Analysis of a publicly accessible server exposed a significant portion of the infrastructure associated with threat actors operating under the identities Blackhatsect0r and DXQRTXX. The recovered environment contained custom offensive tooling, credential collections, target databases, operational communications, exploitation material, and supporting infrastructure linked to activities targeting financial services, government systems, cryptocurrency platforms, and internet-facing infrastructure across multiple countries.

The exposed server appears to have served as a central operational environment rather than a simple repository of publicly available tools. Recovered material included a custom command-and-control framework written in Go, a Python-based target discovery and reconnaissance system, and multiple purpose-built exploitation utilities. The development effort behind these components, combined with evidence of coordinated activity and multiple operational functions, indicates that the actors maintain capabilities extending beyond opportunistic use of commonly available offensive tooling.

The scale of the collected data further demonstrates the breadth of the operation. More than 16,000 credentials associated with compromised systems were stored within the environment, alongside a target dataset containing approximately 498,000 URLs prepared for reconnaissance or exploitation. The dataset included hundreds of subdomains associated with French government entities, including ministries, judicial systems, law enforcement services, and other public-sector infrastructure. Additional targeting was identified across Brazil, Kenya, Iran, India, France, and globally distributed web infrastructure.

Ransomware 2026 August

Relevant Reports

We see the full picture of the evolving cyber threat landscape thanks to unique tools for monitoring the infrastructure used by cybercriminals and data from battlefields: