IntelBroker

IntelBroker
The profile picture commonly used by IntelBroker
NationalitySerbian
Known forHacking several government agencies and corporations

IntelBroker is a Serbian black hat hacker active since October 2022, who has committed several high-profile cyber attacks. Their targets have included Europol, Pandabuy, and Apple, with over 80 sales and leaks of compromised data having been traced to them. They claim to be currently residing in Russia for security reasons.

Description

IntelBroker first began activities in October 2022, hacking minor organizations, but only gained notoriety in 2023 after an attack on the food delivery service "Weee!".[1][2] After their initial string of attacks, they were speculated to be a highly skilled team, possibly an Iranian Persistent Threat Group, however an interview with The Cyber Express revealed that they were a single person. In another exclusive interview with the German Podcast Inside Darknet[3] , IntelBroker shared several personal details, including that they are Serbian and currently reside in Russia for safety reasons.[4] During the same interview, they expressed a desire to one day manage a cybercrime forum similar to BreachForums. This aspiration became reality in August 2024, when IntelBroker took ownership of BreachForums. IntelBroker often contributes to the racist hacking group CyberNiggers,[2] and in August 2024 became the owner of the cybercrime forum BreachForums.[5] As of June 2024, they had posted over 80 separate leaks and sales of compromised information on BreachForums, with IntelBroker claiming that they had sold the information of over 400 organizations.[4]

Modus operandi

IntelBroker has used a wide range of tactics to enter secured systems, such as exploiting leaked credentials and exploiting organizations public facing applications. Once inside, they remain for an extended period of time, escalating privileges and acquiring data. Finally, they ransom, sell, or leak the data, often on BreachForums.[6][4]

Endurance ransomware

IntelBroker created a unique ransomware strain written in C# known as Endurance, and published its source code publicly on their GitHub page. While labeled as ransomware, the software overwrites and then deletes all targeted files.[6] Endurance was confirmed by the Department of Defense Cyber Crime Center to have been used by IntelBroker to hack several U.S. government agencies.[7] They speculated that Endurance was related to the Shamoon wiping software sometimes used by Iranian Hackers, which IntelBroker has denied.[4]

Notable attacks

Acuity

In April 2024, IntelBroker announced that they and the black hat hacker Sanggiero had hacked Acuity, a technology contractor for the U.S. government, and subsequently obtained confidential information belonging to the Five Eyes intelligence organization and the United States military. A vast majority of the information had been stored in a GitHub repository by Acuity, which IntelBroker was able to access.[8][9] The information included confidential communications and documents between Five Eyes members, and the contact information for several U.S. government and military officials.[10] Sanggiero claimed that the breach had taken place on March 7, a month before the information was leaked.[11] After an investigation, Acuity determined that the leaked data was old and non-sensitive.[12]

Pandabuy

On March 31, 2024, IntelBroker assisted Sangierro in a hack of the Chinese e-commerce website Pandabuy, with user data sold the database on BreachForum for a small "symbolic" bitcoin payment.[13][14] The information had been initially ransomed to Pandabuy for an unknown amount of money, but after it was paid the leak was still released.[15][16] IntelBroker and Sangierro claimed that the leak contained the names, contact details, orders, and addresses of over 3 million Pandabuy customers, while an analysis by "Have I Been Pwned?" creator Troy Hunt found that only approximately 1.3 million user entries were real, while the rest contained fake email addresses.[14][17] Pandabuy attempted to censor posts on its Discord and Reddit pages to cover up the leak, before offering a "10% freight subsidy" to users as compensation. Both actions were received negatively by Pandabuy customers.[18][19]

On June 3, 2024, Sanggiero posted on BreachForums that they were going to sell all information from the databreach, containing over 17 million user entries, for $40,000. They had again ransomed the information to Pandabuy, who refused to pay as the two had violated the original ransom and sold the information.[15][16]

Europol

On May 10, 2024, IntelBroker announced on BreachForums that they had gained access to 9,128 confidential records from the European Union's law enforcement agency Europol, including employee information, source code, and guideline documents. Most of the records came from the Europol Platform for Experts, a discussion platform for law enforcement, and the electronic evidence program SIRIUS. Europol confirmed that the leak was real, but claimed that it only contained information from Europol Platform for Experts and SIRIUS, and did not contain any operational information.[20][21] IntelBroker announced that they would be accepting offers for the data in Monero,[22] which was sold on May 11.[23]

Apple

In June 2024, IntelBroker claimed on X that they had acquired source code for several internal Apple tools, before releasing the code on BreachForums. These tools were related to internal Apple processes, such as authenticating users and sharing information within Apple's network.[24] Later analysis revealed that leaked code was not source code, but instead plugins for internal tools. However, the code still was a security risk, and could potentially be used by malicious parties.[25][26]

AMD

On June 17, 2024, IntelBroker claimed on BreachForums that they had breached semi-conductor giant AMD, and was selling the compromised data. Samples provided by them included data on future products, employee information, customer information, source code, and financial records.[27] AMD quickly contacted law enforcement agencies to investigate the breach.[28] Soon after AMD claimed that the breach was limited in scope, would not impact the business, and implied that it did not include employee or customer information, conflicting with the initial report by The Cyber Express.[29] Bloomberg correlated the attack with a 2.4% fall in AMD stock soon after the breach was announced.[30]

References

  1. ^ Khaitan, Ashish (8 February 2023). "Weee! Data Breach: 11M User Records Leaked By Unknown Threat Actor". The Cyber Express. Retrieved 14 August 2024.
  2. ^ a b "Exclusive IntelBroker Interview: Inside The Mind Of A Hacker". The Cyber Express. 14 March 2024. Retrieved 14 August 2024.
  3. ^ "Inside Darknet Podcast - Episode 9 - IntelBroker". YouTube. 2024. Retrieved 14 August 2024. Also available on Spotify: https://open.spotify.com/show/5RHKRk7awU2SFPq2VCwpLi
  4. ^ a b c d "Dark Web Profile: IntelBroker". SOCRadar. 28 June 2024. Retrieved 14 August 2024.
  5. ^ Melillo, Pietro (2024-08-22). "IntelBroker Takes Control of BreachForums: A New Chapter in Cybercrime Management". RedHotCyber. Retrieved 2024-08-29.
  6. ^ a b The Intelbroker Data Leak Threat Actor (PDF) (Report). Mphasis. 2024-06-21.
  7. ^ DIB-REPORTED CYBER THREATS (PDF) (Report). Vol. CY2022. Department of Defense Cyber Crime Center. December 2022. Retrieved 2024-08-14.
  8. ^ Sergiu Gtalan (3 April 2024). "US State Department investigates alleged theft of government data". BleepingComputer. Retrieved 14 August 2024.
  9. ^ Sergiu Gatlan (5 April 2024). "Acuity confirms hackers stole non-sensitive govt data from GitHub repos". BleepingComputer. Retrieved 14 August 2024.
  10. ^ Jessica Lyons (4 April 2024). "Feds investigates alleged classified data theft". The Register. Retrieved 14 August 2024.
  11. ^ Jon, Quincy (5 April 2024). "Federal Contractor Acuity Confirms GitHub Breach: What Did Hackers Steal?". Tech Times. Retrieved 14 August 2024.
  12. ^ Kovacs, Eduard (5 April 2024). "Acuity Responds to US Government Data Theft Claims, Says Hackers Obtained Non-Sensitive Info". SecurityWeek. Retrieved 14 August 2024.
  13. ^ Sead Fadilpašić (2 April 2024). "Chinese ecommerce giant PandaBuy hit by cyberattack, data breach". TechRadar. Retrieved 14 August 2024.
  14. ^ a b Bill Toulas (1 April 2024). "Shopping platform PandaBuy data leak impacts 1.3 million users". BleepingComputer. Retrieved 14 August 2024.
  15. ^ a b Paganini, Pierluigi (7 June 2024). "Pandabuy was extorted twice by the same threat actor". Security Affairs. Retrieved 14 August 2024.
  16. ^ a b Bill Toulas (6 June 2024). "PandaBuy pays ransom to hacker only to get extorted again". BleepingComputer. Retrieved 14 August 2024.
  17. ^ Ashish Khaitan (25 April 2024). "PandaBuy Leak List: 1.3M Users' Info Exposed In Cyberattack". The Cyber Express. Retrieved 14 August 2024.
  18. ^ Hope, Alicia (8 April 2024). "Data Breach Impacts 1.3 Million Pandabuy Customers; Company Apologizes After Apparent Cover-Up - CPO Magazine". CPO Magazine. Retrieved 14 August 2024.
  19. ^ Sead Fadilpašić (2 April 2024). "Chinese ecommerce giant PandaBuy hit by cyberattack, data breach". TechRadar. Retrieved 14 August 2024.
  20. ^ Sead Fadilpasic (14 May 2024). "Hackers claim to have breached Europol web portal, but force says no significant data stolen". TechRadar. Retrieved 14 August 2024.
  21. ^ Antoaneta Roussi (13 May 2024). "Cybercriminals claim hack of EU police agency, posting data online". POLITICO. Retrieved 14 August 2024.
  22. ^ Sergiu Gatlan (11 May 2024). "Europol confirms web portal breach, says no operational data stolen". BleepingComputer. Retrieved 14 August 2024.
  23. ^ Kovacs, Eduard (13 May 2024). "Europol Investigating Breach After Hacker Offers to Sell Classified Data". SecurityWeek. Retrieved 14 August 2024.
  24. ^ Anton Shilov (21 June 2024). "Intelbroker claims they hacked Apple in the same week as AMD". Tom's Hardware. Retrieved 14 August 2024.
  25. ^ Winder, Davey (20 June 2024). "Has Apple Been Hacked? June 2024 Breach Exposes Source Code, Hacker Claims". Forbes. Retrieved 14 August 2024.
  26. ^ Andrew (19 June 2024). "Technical Analysis of Apple Internal Source Code Leak - AHCTS, LLC". AHCTS, LLC. Retrieved 14 August 2024.
  27. ^ Ashish Khaitan (26 June 2024). "Intelbroker Advertises Massive AMD Data Breach On Dark Web". The Cyber Express. Retrieved 14 August 2024.
  28. ^ Anton Shilov (19 June 2024). "AMD working with law enforcement after reports of massive data breach — hack may have uncovered future product details". Tom's Hardware. Retrieved 14 August 2024.
  29. ^ Jeff Butts (20 June 2024). "AMD provides update on data breach — says it won't 'have a material impact' on business". Tom's Hardware. Retrieved 14 August 2024.
  30. ^ Ian King (18 June 2024). "AMD Is Investigating Claims That Company Data Was Stolen in Hack". Bloomberg.com. Retrieved 14 August 2024.