Critical Unpatched Citrix NetScaler RCE Zero-Days Exploited
Unauthenticated remote code execution vulnerabilities in Citrix NetScaler ADC and Gateway are being actively exploited in the wild to deploy webshells and steal credentials.
Browse public community intelligence reports, source analysis, and threat research.
6 intel reports
Gamaredon, a Russian FSB-operated group, uses a multi-stage modular framework (GammaPhish, GammaLoad, GammaWorm, GammaSteel) to maintain persistent access and exfiltrate sensitive documents from Ukrainian government and critical infrastructure.
The Mirage2FA Phishing-as-a-Service toolkit by LinX Coders utilizes Adversary-in-the-Middle (AiTM) techniques to bypass MFA and steal Microsoft 365 session cookies, primarily targeting US-based technology and manufacturing sectors.
The SourTrade malvertising campaign uses victim browsers to locally assemble unique Windows executables from legitimate components and malicious bytecode to evade hash-based detection.
The Russia-aligned Gamaredon group significantly updated its arsenal in 2025, deploying six new PowerShell tools and leveraging legitimate cloud services and tunnels to target Ukrainian military and government institutions.
The Colombian Smugglers group and other actors utilize techniques like Device Code Phishing and SVG smuggling to deliver malware including rmrlx, vjw0rm, and UnixStealer.
Russia's FSB-operated Gamaredon group leverages a modular VBScript and PowerShell arsenal targeting Ukraine through advanced persistence and multi-stage loading techniques.