CSIDB logo
Threat actor

Mr.XHat

Attribution profile

Type
Sensationalist
Location
Iran
Known incidents
1 incident
First seen
2014-01-05
Last seen
2014-01-05
Updated
2026-07-31 00:00
Aliases
1 alias

STIX characteristics

Threat actor characteristics are available to members.

Profile narrative

Mr.XHat is an Iranian hacker known by the alias Mr.XHat, whose activity has been publicly linked to a 2014 compromise of a Tajikistani domain registrar. The attacker exploited a directory traversal vulnerability on the registrar’s web server to gain unauthorized access to its administrative interface. Using this foothold, Mr.XHat modified the DNS records for several high‑profile country‑code domains, including google.com.tj, yahoo.com.tj, twitter.com.tj, and amazon.com.tj, redirecting traffic to defaced pages for approximately one day. The intruder claimed to have obtained root access to the registrar’s MySQL database, where customer credentials were stored in hashed form, and demonstrated the ability to view those hashes. To extend the breach, Mr.XHat altered the administrative email addresses associated with the compromised domain accounts, thereby intercepting password‑reset messages and gaining control of the corresponding customer control panels. The attack relied solely on web‑based techniques, with no mention of malware families or custom tooling beyond the directory traversal exploit and subsequent manipulation of account recovery functions.

The operation appears to have been driven by objectives of service disruption and unauthorized access, as evidenced by the defacement of prominent websites and the seizure of administrative control over customer domains. Public attribution to Iran is based on the actor’s self‑identification and the geographic detail supplied in the source material, although no explicit connection to a state sponsor or criminal organization has been documented. This incident remains the most notable and widely reported campaign associated with Mr.XHat, illustrating how a single vulnerability in a regional registrar can be leveraged to affect globally recognized brands through DNS hijacking and account takeover. The episode underscores the potential impact of insecure web applications on critical internet infrastructure and highlights the importance of robust input validation and monitoring for anomalous DNS changes.

Incidents

Attributed incidents are available to members.

1 incident
CSIDB