Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors IntelBroker

Also known as: Sandworm Team, Operation Cleaver, Shell Crew, WebMasters, KungFu Kittens, PinkPanther, a separate entity, APT28, VOLTZITE, for follow-on operations

Description

IntelBroker is a threat actor known for orchestrating high-profile data breaches targeting companies like Apple, Zscaler, and Facebook Marketplace. They have a reputation for selling access to compromised systems and data on underground forums like BreachForums. IntelBroker has claimed responsibility for breaches involving government agencies such as Europol, the U.S. Department of Transportation, and the Pentagon, leaking sensitive information and classified documents. The actor has been linked to breaches at companies like Acuity, General Electric, and Home Depot, showcasing a pattern of targeting critical infrastructure and major corporations.

Goals & Targeting

Targeted Sectors

Government
Financial services
Defense
Telecommunications
Healthcare
Education
Manufacturing
Non profit
Energy
Media
Critical infrastructure
Pharmaceutical
Aviation
Hospitality
Retail
Aerospace
Information technology
Think tank
Transportation
Mining
Chemical
Gaming
Legal services
Nuclear
Entertainment
Oil gas
Maritime
Construction
Utilities

Targeted Countries / Regions

US
CN
RU
IR
GB
VN
JP
IL
AU
SA
PK
TW
AE
UA
SG
KR
IN
DE
BY
TR
MX
ES
PL
CA
BR
RO
FR
NG
KP
IT
LB
AZ
KZ

AI Analysis

· 1 week ago

Executive Summary

IntelBroker is a sophisticated threat actor known for orchestrating high-profile data breaches targeting major corporations and government agencies. Their primary activities involve compromising systems and selling access on dark web forums, posing significant risks to critical infrastructure and sensitive data.

Goals & Targeting

IntelBroker's objectives appear to be primarily financial, driven by the sale of access to compromised systems and data on the dark web. Their targeting strategy focuses on sectors with high-value assets, including technology companies, critical infrastructure, and government agencies. This strategic approach allows them to maximize the profitability of their operations while minimizing the risk of attribution.

Enhanced Description

IntelBroker has emerged as a notable player in the cybercriminal landscape, specializing in breaching high-value targets such as Apple, Zscaler, and Facebook Marketplace. The actor's operations extend to government agencies like Europol and the U.S. Department of Transportation, indicating a focus on accessing sensitive and classified information. IntelBroker operates with a distinct pattern, leveraging advanced techniques to infiltrate systems and subsequently monetizing access through underground forums such as BreachForums. Their targeting of critical infrastructure, including GeneralElectric and Home Depot, underscores a strategic approach aimed at maximizing the impact of their activities. The actor's persistence and ability to remain under the radar highlight a professional-level operational capacity.

Key Capabilities

  • High-profile data breach orchestration
  • Access brokering on dark web forums
  • Advanced persistent threat (APT) tactics
  • Lateral movement within networks
  • Data exfiltration techniques

Campaigns & Victims

IntelBroker's campaign patterns involve a focus on stealth and long-term persistence, often maintaining access to compromised systems for extended periods. Their operations have included targeting logistics, healthcare, and financial sectors, with notable campaigns against major corporations such as Apple and Home Depot. The actor is known to surface periodically, each time escalating their attack complexity and targeting scope.

IOC Patterns

  • Spear-phishing emails with malicious payloads
  • Lateral movement across networks using legitimate tools
  • C2 communication via obscure protocols or domains
  • Staging infrastructure onbulletproof hosting services

Recommended Actions

  • Implement robust perimeter security measures and multi-factor authentication for critical systems.
  • Conduct regular employee training to mitigate phishing attempts.
  • Monitor dark web forums for mentions of organizational data being sold.
  • Enhance network segmentation to limit lateral movement in case of a breach.
  • Patch systems regularly to address known vulnerabilities.

Suggested Tags

APT
DataTheft
CriticalInfrastructureTargeting
DarkWebActivity

Confidence Assessment

Confidence in the characterization of IntelBroker is high based on their well-documented activities and media coverage. However, specific technical details about their toolset and exact attack techniques remain unclear, limiting precise MITRE framework mapping.

Intel Summary

0

Techniques

40

Tools

0

Campaigns

11

IOCs

0

Observed Data

0

Tactics

Tags

Critical Infrastructure
Data Exfiltration
Government Targeting
APT
DataTheft
CriticalInfrastructureTargeting
DarkWebActivity

Details

Type
Unknown
Primary Motivation
Espionage
Country of Origin
China (CN)
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.