Critical Unpatched Citrix NetScaler RCE Zero-Days Exploited
Unauthenticated remote code execution vulnerabilities in Citrix NetScaler ADC and Gateway are being actively exploited in the wild to deploy webshells and steal credentials.
Browse public community intelligence reports, source analysis, and threat research.
14 intel reports
Adversaries are deploying modular Linux implants including BPFDoor, Rekoobe, and the new AVERAT RAT against telecom edge appliances, utilizing SMTP-disguised C2 and BPF packet filtering to evade detection.
Kimsuky (APT-C-55) utilizes multi-stage PowerShell and C# malware delivered via disguised installers to target South Korean institutions for intelligence theft.
Attackers are abusing legitimate Microsoft device-code OAuth workflows via deceptive document-verification pages to steal access tokens and bypass MFA.
Russian state-sponsored actor BlueDelta utilized macro-enabled Word documents to deploy HOOKEDGE, a batch-script backdoor abusing legitimate webhook services for C2 and exfiltration targeting European government entities.
A multi-stage PureLogs Stealer campaign impersonates Adobe Sign to deliver fileless payloads via image steganography and environment variable manipulation.
North Korean threat actors compromised two @joyfill npm packages to deliver the DEV#POPPER RAT and OmniStealer via a multi-chain blockchain C2 infrastructure.
Russian state-supported actors including LAUNDRY BEAR and TA458 are exploiting zero-day vulnerabilities in Zimbra, SOGo, and other webmail clients to exfiltrate sensitive email data from Western government and commercial targets.
Stealth Falcon utilized an LLM-accelerated WebDAV delivery lab to deploy PureRAT via working directory hijacking and DLL sideloading targeting Mexican enterprise users.
The EvilTokens and ARToken Phishing-as-a-Service (PhaaS) platforms use Microsoft Device Code flows and browser-side decryption to bypass MFA and achieve persistent Microsoft 365 account takeovers.
A China-nexus threat actor is targeting Indian taxpayers and government infrastructure using a multi-stage infection chain to deploy DcRAT via fake tax utility lures.