ZeroFox Intelligence Flash Report - IntelBroker Sells Zero-Day Vulnerability Leveraged in Recent Attacks
|by Alpha Team

ZeroFox Intelligence Flash Report - IntelBroker Sells Zero-Day Vulnerability Leveraged in Recent Attacks
Product Serial: F-2024-06-27a
TLP:CLEAR
In this Flash Report, ZeroFox researchers report on IntelBroker's alleged sale of a zero-day vulnerability, which has likely been leveraged in numerous recent data breaches.
Standing Intelligence Requirements
Deep Dark Web and Criminal Underground

For the most up-to-date list of ZeroFox’s Intelligence Requirements, please visit:
https://cloud.zerofox.com/intelligence/advisories/14956
Link to Download
View the full report here
Key Findings
- On June 13, 2024, prominent and well-regarded threat actor “IntelBroker” registered an account on the popular illicit hacking forum BreachForums—one day after removing themselves from the platform.
- Shortly after returning to the forum, IntelBroker began advertising numerous illicit network accesses and data breaches targeting high-profile organizations from a multitude of industries. The majority of these attacks alluded to the exploitation of an unspecified vulnerability targeting Atlassian software.
- On June 16, 2024, IntelBroker advertised the sale of a zero-day vulnerability that targets Atlassian Jira software via remote code execution. This was purchased by an unknown actor between June 20 and June 24, 2024, though it is unlikely that IntelBroker received the exorbitant asking price of USD 800,000.
- The details provided in the announcement of the three attacks were almost certainly intended to serve as an advertisement or proof of concept for the zero-day vulnerability.
Tags: tlp:clear, dark web, data breach, threat actor