Intel Exchange

Browse public community intelligence reports, source analysis, and threat research.

Cover image for Critical Unpatched Citrix NetScaler RCE Zero-Days Exploited

Critical Unpatched Citrix NetScaler RCE Zero-Days Exploited

Unauthenticated remote code execution vulnerabilities in Citrix NetScaler ADC and Gateway are being actively exploited in the wild to deploy webshells and steal credentials.

Vikas Lokhande@vlokhande7 days ago

14 intel reports

Adversaries are deploying modular Linux implants including BPFDoor, Rekoobe, and the new AVERAT RAT against telecom edge appliances, utilizing SMTP-disguised C2 and BPF packet filtering to evade detection.

Russian state-sponsored actor BlueDelta utilized macro-enabled Word documents to deploy HOOKEDGE, a batch-script backdoor abusing legitimate webhook services for C2 and exfiltration targeting European government entities.

Russian state-supported actors including LAUNDRY BEAR and TA458 are exploiting zero-day vulnerabilities in Zimbra, SOGo, and other webmail clients to exfiltrate sensitive email data from Western government and commercial targets.

The EvilTokens and ARToken Phishing-as-a-Service (PhaaS) platforms use Microsoft Device Code flows and browser-side decryption to bypass MFA and achieve persistent Microsoft 365 account takeovers.