Critical Unpatched Citrix NetScaler RCE Zero-Days Exploited
Unauthenticated remote code execution vulnerabilities in Citrix NetScaler ADC and Gateway are being actively exploited in the wild to deploy webshells and steal credentials.
Browse public community intelligence reports, source analysis, and threat research.
4 intel reports
Sauron Loader is a novel Russian-language Malware-as-a-Service that utilizes social engineering, DLL side-loading, and in-memory decryption to deliver multi-stage payloads.
The TAG-195 threat group is using the ChonkyChicken RAT and ChromEggscalator helper to bypass Chrome App-Bound encryption and hijack authenticated browser sessions via the ClickFix social engineering technique.
TAG-195 (Golden Chickens) has introduced a new generation of modular malware, including TinyEgg and ChonkyChicken, featuring enhanced browser credential theft and session automation via CDP.
A multi-stage HTA-based loader uses VBScript and PowerShell to deploy the Lightlife RAT, targeting crypto wallets and establishing persistence via Russian infrastructure.