Critical Unpatched Citrix NetScaler RCE Zero-Days Exploited
Unauthenticated remote code execution vulnerabilities in Citrix NetScaler ADC and Gateway are being actively exploited in the wild to deploy webshells and steal credentials.
Browse public community intelligence reports, source analysis, and threat research.
3 intel reports
Kimsuky (APT-C-55) utilizes multi-stage PowerShell and C# malware delivered via disguised installers to target South Korean institutions for intelligence theft.
Transparent Tribe (APT-C-56) utilizes ISO/ZIP-based lure files and LNK execution chains to deploy CrimsonRAT and a custom Golang-based remote access trojan against Indian and South Asian targets.
China-nexus threat actors are targeting Myanmar government personnel using a VHD-delivered Golang backdoor named QUICAgent that utilizes QUIC protocol for C2 communication.