Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Exploits CVEs in the wild

IntelBroker

Also known asIntelBroker

IntelBroker is a cybercriminal threat actor and stolen-data broker active publicly since at least October 2022. The actor is repeatedly described as a prominent BreachForums user and later owner/administrator of BreachForums, with a reputation for posting large, genuine leaks and selling or releasing stolen data. In June 2025, U.S. authorities announced charges identifying “IntelBroker” as the online persona of 25-year-old British national Kai Logan West, also referenced as using the alias Kyle Northern. Based on the provided reporting, IntelBroker has been linked to intrusions, breach claims, or data sales affecting a wide range of targets, including U.S. government agencies and contractors, technology companies, telecommunications providers, retailers, and critical infrastructure-related entities. Reported victims or claimed victims include Acuity, Cisco, AMD, Apple, Europol, DC Health Link, PandaBuy, Weee!, Los Angeles International Airport, Hewlett Packard Enterprise, General Electric/GE Aviation, Volvo Cars, Verizon, AT&T, USCellular, Autotrader, Hilton Hotels, ICE, USCIS, the Department of Defense, the U.S. Army, and Zscaler. Some incidents remain claims by the actor, while others were at least partially confirmed by affected organizations. Tactics and tradecraft directly mentioned in the content include exploiting security misconfigurations, insecure APIs, third-party compromises, stolen credentials, and public-facing development resources; abusing multiple API flaws; exploiting Jenkins CVE-2024-23897 to obtain credentials and then access a corporate GitHub account and private repositories; stealing GitHub credentials from an Acuity Tekton CI/CD server according to a collaborator’s claim; accessing exposed DevHub/JFrog resources in the Cisco case; and obtaining or selling source code, credentials, API tokens, certificates, private keys, cloud storage access, internal documents, and large datasets containing PII. The actor commonly advertised stolen data on BreachForums, leaked samples publicly to prove authenticity, and sought payment in cryptocurrency including Monero. The content also links IntelBroker to collaboration with Sanggiero/Sangierro in the PandaBuy and Acuity-related activity. IntelBroker is additionally associated in the reporting with the group CyberN****** and with ownership/administration of BreachForums after prior law-enforcement disruption. One source notes IntelBroker denied ties to Iranian APT groups. Another source states IntelBroker has been linked to ransomware operations under the name Endurance Ransomware, but no further corroborating detail is provided in the supplied content. IntelBroker is not described in the provided content as a nation-state actor. The reporting instead characterizes the actor as financially motivated, focused on data theft, brokerage, extortion-oriented sales, and high-profile leak activity, though one article notes motives may also include disruption.

Share:
Are they targeting you?

Know when an actor pivots toward your sector

Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.

OPERATIONAL PROFILE

Targeting

Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.

Who they target

Sectors the actor has been observed targeting.

  • Government & Administration
  • Military
  • Health Care Equipment & Services
  • Software & Services
  • Capital Goods

Where they target

Geographies tied to known operations.

  • 🇺🇸 United States
MITRE ATT&CK

Tradecraft

14 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.

10 of 15 tactics18 techniques×N= number of intelligence reports citing this technique
MITRE ATT&CK
TA0043
Reconnaissance
1 technique
T1595
Active Scanning
TA0042
Resource Development
1 technique
T1583
Acquire Infrastructure
T1583.006
Web Services
TA0001
Initial Access
2 techniques
T1078×6
Valid Accounts
T1190×7
Exploit Public-Facing Application
TA0003
Persistence
1 technique
T1078×6
Valid Accounts
TA0004
Privilege Escalation
1 technique
T1078×6
Valid Accounts
TA0005
Stealth
1 technique
T1078×6
Valid Accounts
TA0006
Credential Access
3 techniques
T1212
Exploitation for Credential Access
T1552
Unsecured Credentials
T1552.001
Credentials In Files
T1649×2
Steal or Forge Authentication Certificates
TA0009
Collection
1 technique
T1213×8
Data from Information Repositories
TA0010
Exfiltration
4 techniques
T1041
Exfiltration Over C2 Channel
T1048
Exfiltration Over Alternative Protocol
T1537×4
Transfer Data to Cloud Account
T1567
Exfiltration Over Web Service
TA0040
Impact
1 technique
T1485
Data Destruction
IOCS

Observables

1 indicator attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.

IOC values are gated. View more in Mallory for domains, IPs, hashes, and other artifacts, or pipe them straight into your SIEM.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: sector and geo overlap with your footprint, the IOCs they’re burning right now, detection coverage, and what to do next.
Target overlap

Match sector + geo + tech-stack targeting against your real footprint.

Tradecraft mapping14

Every observed MITRE ATT&CK technique, grouped by tactic.

Malware arsenal

Families this actor is known to deploy, with IOCs and behavior.

Exploited CVEs1

CVEs this actor has used in known campaigns.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Observables1

Domains, IPs, and hashes tied to this actor, refreshed continuously.

IntelBroker | Mallory