zerofox logo
Advisories

ZeroFox Intelligence Flash Report - Temporary BreachForums Disruption Claimed by Hacking Group

|by Alpha Team

banner image

ZeroFox Intelligence Flash Report - Temporary BreachForums Disruption Claimed by Hacking Group

Product Serial: F-2024-04-17a

TLP:CLEAR

In this flash report, ZeroFox researchers report on the temporary disruption of BreachForums and the claiming of responsibility by the Hacker group R00TK1T.

Standing Intelligence Requirements

Deep Dark Web and Criminal Underground DDW

For the most up-to-date list of ZeroFox’s Intelligence Requirements, please visit:

https://cloud.zerofox.com/intelligence/advisories/14956

Link to Download

View the full report here

Key Findings

  • On April 15, 2024, threat actor “R00TK1T”—in alleged coordination with the “CyberArmyofRussia”—claimed to have taken down BreachForums’ surface web domain. R00TK1T also alluded that it would imminently publish information related to the forum’s users.
  • R00TK1T’s involvement was quickly disputed by “Baphomet”, BreachForum’s moderator, who instead blamed “the five eyes network, and various other large nations.” Baphomet also announced the resumption of the forum on a new [.]st top level domain (TLD). As of the time of writing, this site is fully functional.
  • BreachForum’s short downtime and R00TK1T’s failure to publish subsequent information as had been threatened indicates there is an unlikely chance R00TK1T was involved.
  • There is a roughly even chance that the events were initiated by Law Enforcement (LE) entities as Baphomet claimed. Prior to the disruption, a well-regarded threat actor advertised a data breach composed of allegedly sensitive information, which had a high chance of spurring LE scrutiny.

Tags: tlp:clear,  dark web, DDW Markets