Intel Exchange

Browse public community intelligence reports, source analysis, and threat research.

Cover image for Critical Unpatched Citrix NetScaler RCE Zero-Days Exploited

Critical Unpatched Citrix NetScaler RCE Zero-Days Exploited

Unauthenticated remote code execution vulnerabilities in Citrix NetScaler ADC and Gateway are being actively exploited in the wild to deploy webshells and steal credentials.

Vikas Lokhande@vlokhande9 days ago

9 intel reports

Oldphantomoftheopera and Phantom Softwares operate Phantom Stealer, a Malware-as-a-Service infostealer targeting Windows systems through multi-stage in-memory execution and obfuscated PowerShell to harvest credentials and cryptocurrency data.

An unsigned GlobalProtect-themed MSI deploys a backdoor that utilizes Cloudflare Workers for configuration and Google Sheets for C2 communication, specifically targeting victims in Myanmar.

The Chaos ransomware group is using a new Rust-based RAT called msaRAT that establishes covert C2 channels by hijacking headless Chrome and Edge browsers via the Chrome DevTools Protocol.

Threat actors compromised an Artlist subdomain using stolen credentials to deploy a ClickFix campaign that uses blockchain-based EtherHiding for evasion and delivers a multi-stage RAT.