zerofox logo
Advisories

ZeroFox Intelligence Flash Report - IntelBroker Sells Zero-Day Vulnerability Leveraged in Recent Attacks

|by Alpha Team

banner image

ZeroFox Intelligence Flash Report - IntelBroker Sells Zero-Day Vulnerability Leveraged in Recent Attacks

Product Serial: F-2024-06-27a

TLP:CLEAR

In this Flash Report, ZeroFox researchers report on IntelBroker's alleged sale of a zero-day vulnerability, which has likely been leveraged in numerous recent data breaches.

Standing Intelligence Requirements

Deep Dark Web and Criminal Underground DDW

For the most up-to-date list of ZeroFox’s Intelligence Requirements, please visit:

https://cloud.zerofox.com/intelligence/advisories/14956

Link to Download

View the full report here

Key Findings

  • On June 13, 2024, prominent and well-regarded threat actor “IntelBroker” registered an account on the popular illicit hacking forum BreachForums—one day after removing themselves from the platform.
  • Shortly after returning to the forum, IntelBroker began advertising numerous illicit network accesses and data breaches targeting high-profile organizations from a multitude of industries. The majority of these attacks alluded to the exploitation of an unspecified vulnerability targeting Atlassian software.
  • On June 16, 2024, IntelBroker advertised the sale of a zero-day vulnerability that targets Atlassian Jira software via remote code execution. This was purchased by an unknown actor between June 20 and June 24, 2024, though it is unlikely that IntelBroker received the exorbitant asking price of USD 800,000.
  • The details provided in the announcement of the three attacks were almost certainly intended to serve as an advertisement or proof of concept for the zero-day vulnerability.

Tags: tlp:clear,  dark web,  data breach, threat actor