zerofox logo
Advisories

ZeroFox Intelligence Flash Report - Mass Access Sale to Retail eCommerce System

|by Alpha Team

banner image

ZeroFox Intelligence Flash Report - Mass Access Sale to Retail eCommerce System

Product Serial: F-2024-01-17b

TLP:CLEAR

In this flash report, ZeroFox researchers report on the announcement of the sale of the source code, business operations data, and documentation of an unspecified eCommerce Content Management System (CMS) services vendor.

Standing Intelligence Requirements

Deep Dark Web and Criminal Underground DDW

For the most up-to-date list of ZeroFox’s Intelligence Requirements, please visit:

https://cloud.zerofox.com/intelligence/advisories/14956

Link to Download

View the full report here

Key Findings

  • On January 15, 2024, well-regarded threat actor “isabellavonbiz” announced the sale of the source code, business operations data, and documentation of an unspecified eCommerce Content Management System (CMS) services vendor; as of this writing, the name of the CMS has not been disclosed.
  • The entire package was instantly purchased by a highly competent and popular threat actor, with additional intelligence indicating they are buying and potentially hoarding access to as many online shops as possible; this particular package or a variant thereof is no longer for sale.
  • The access sale is likely indicative of an impending large-scale attack against the widely-used eCommerce CMS provider and is mostly likely to be part of a broader financially-motivated operation against retail targets.

Tags: tlp:clear,  dark web,  retail/cpg,  threat actor