logo

The Hidden Costs of Bad OPSEC: A Case Study on ‘Xanthorox’

ID: efaab405-7cfb-50ba-9219-da1ecb9ab7f6

STIX ID: report--efaab405-7cfb-50ba-9219-da1ecb9ab7f6

Feed Name: Zynap Blog

Threat Score
60/100

Date Published: 2026-02-05

Date Updated: 2026-05-01

Author: Zynap Team

...
...

Executive summary: An OSINT investigation uncovered a criminal AI-tooling campaign run by an actor using the aliases Xanthorox / vengeance141; the report details exposed infrastructure (Open WebUI panel hosted on a residential IP and an exposed TP-Link router), linked Telegram/Discord/YouTube handles, domains and bot identifiers, cryptocurrency addresses and a traceable transaction, prior defacement activity, ties to WormGPT and partner disputes, and publicly available doxxed personal information — illustrating that poor OPSEC and reuse of handles enabled linkage and attribution.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.