Critical Unpatched Citrix NetScaler RCE Zero-Days Exploited
Unauthenticated remote code execution vulnerabilities in Citrix NetScaler ADC and Gateway are being actively exploited in the wild to deploy webshells and steal credentials.
Browse public community intelligence reports, source analysis, and threat research.
9 intel reports
2CLoader is a sophisticated new malware loader identified in August 2026 that uses indirect system calls and environment spoofing to deliver information stealers like Vidar and Remus.
An intrusion campaign utilizing SEO poisoning delivers PavokwiLoader and RMMCRAT, employing advanced obfuscation and environment gating to deploy Cobalt Strike beacons.
An unidentified ransomware-related threat actor is using SloppyRAT, a new multi-stage malware, to establish network footholds via ClickFix lures and blockchain-based C2 resolution.
The Vectra (formerly Nyxel) actor operates VectraRAT, a custom Go and C++ Malware-as-a-Service platform delivered via Amadey and ClickFix campaigns targeting corporate Windows environments.
HoneyMyte (Mustang Panda) has updated the CoolClient backdoor with a signed kernel-mode rootkit, msagent.sys, to hide and protect malicious artifacts on Windows systems.
Blind Eagle (APT-C-36) is utilizing a modernized JC-46 AsyncRAT build featuring WNF process injection and a Chrome App-Bound Encryption bypass to target Latin American financial interests.
StrikeShark leverages custom SharkLoader malware via DLL sideloading and public-facing application exploits to deploy Cobalt Strike Beacons across diverse global sectors.
An attacker uses a multi-stage fileless infection chain involving obfuscated VBScript and in-memory .NET loaders to deploy ScreenConnect for persistent remote access.
SERPENTINE#CLOUD has updated its delivery chain using ClickFix lures and Cloudflare tunnels to deploy a multi-RAT suite including Brute Ratel C4 and PureHVNC.