Critical Unpatched Citrix NetScaler RCE Zero-Days Exploited
Unauthenticated remote code execution vulnerabilities in Citrix NetScaler ADC and Gateway are being actively exploited in the wild to deploy webshells and steal credentials.
Browse public community intelligence reports, source analysis, and threat research.
8 intel reports
The CARBONATO botnet exploits unauthenticated Docker daemons to deploy an AI-driven Hermes Agent for automated post-exploitation and credential harvesting via Telegram.
The Go-based ClosedQuorum malware utilizes multiple commercial AI models to autonomously select post-compromise actions, including credential dumping and process injection, without human operator intervention.
Threat actors are abusing FTP banners as Dead Drop Resolvers (DDRs) to deliver novel RATs, E4del and PINHOLE, using legitimate services like Pinterest and SurveyMonkey for configuration retrieval.
The Aeternum botnet utilizes the public Polygon blockchain as a decentralized command-and-control infrastructure to distribute XWorm, XMRig, and data-stealing payloads.
Russian-speaking actor UAT-11795 is targeting US and European users with trojanized installers for MobaXterm, WebEx, and Zoom to deploy the novel Starland RAT and WLDR PowerShell agent.
Russian-speaking threat actor UAT-11795 is utilizing ClickFix lures and trojanized software to deploy novel Python-based Starland RAT and PowerShell-based WLDR agent for cryptocurrency theft.
Vidar Stealer utilizes memory forking and APC injections to extract and decrypt the Chromium v20_master_key, bypassing Application-Bound Encryption.
SERPENTINE#CLOUD has updated its delivery chain using ClickFix lures and Cloudflare tunnels to deploy a multi-RAT suite including Brute Ratel C4 and PureHVNC.