Intelbroker

Threat Actor updated 7 months ago (2024-11-29T14:53:45.370Z)
Download STIX
Preview STIX
IntelBroker is a significant threat actor known for executing high-profile data breaches. The group, which could consist of a single individual or multiple persons, has been responsible for numerous cyberattacks on major corporations and government entities. IntelBroker's activities showcase a broad range of capabilities, including gaining access to confidential documents, source codes, hard-coded credentials, private keys, and more. The group's targets have included Cisco, Europol, DC Health Link, Volvo Cars, HPE, AMD, AT&T, Bank of America, Microsoft, SAP, T-Mobile, Verizon, among others. On November 17, IntelBroker, in collaboration with another threat actor known as EnergyWeaponUser, announced on BreachForums that they had stolen 44,000 customer records from Ford. This information was confirmed by the victims, who acknowledged the breach. The group often posts about their successful exploits on such forums, selling the breached data and even zero-day vulnerabilities, as seen when they offered a Jira zero-day for sale. IntelBroker's modus operandi involves targeting an organization's digital infrastructure, gaining unauthorized access, and stealing sensitive information. The group then typically publishes proof of their exploits on cybercrime forums. In the case of the Cisco breach, the company confirmed that the data IntelBroker posted online was indeed stolen from its DevHub environment. Such actions by IntelBroker underscore the substantial cybersecurity risks posed by this threat actor to both corporate and governmental entities.
Description last updated: 2024-11-25T13:42:56.186Z
What's your take? (Question 1 of 5)
Help tune the shared Cybergeist dataset, assist your peers, and earn karma. Expand the panel to get started.
Aliases We are not currently tracking any aliases
Miscellaneous Associations
Other elements of context that could aid in the identification of relevance
Source
Breachforums
SSH
Vulnerability
Exploit
Jira
Credentials
Cybercrime
Analyst Notes & Discussion
Be the first to leave your mark here! Log in to share your views and vote.
Source Document References
Information about the Intelbroker Threat Actor was read from the documents corpus below. This display is limited to 20 results, create a free account to see more
PreviewSource LinkCreatedAtTitle
Securityaffairs
a day ago
Flashpoint
a day ago
InfoSecurity-magazine
2 days ago
Securityaffairs
6 months ago
Securelist
6 months ago
DARKReading
8 months ago
Securityaffairs
7 months ago
DARKReading
7 months ago
Securityaffairs
7 months ago
Securityaffairs
8 months ago
Malwarebytes
a year ago
InfoSecurity-magazine
a year ago
Securityaffairs
a year ago
Securityaffairs
a year ago
CERT-EU
a year ago
CERT-EU
a year ago
CERT-EU
a year ago
CERT-EU
2 years ago
CERT-EU
2 years ago
CERT-EU
2 years ago