Critical Unpatched Citrix NetScaler RCE Zero-Days Exploited
Unauthenticated remote code execution vulnerabilities in Citrix NetScaler ADC and Gateway are being actively exploited in the wild to deploy webshells and steal credentials.
Browse public community intelligence reports, source analysis, and threat research.
9 intel reports
Lazarus Group is distributing Graphalgo malware via malicious Terraform providers and Go modules to target infrastructure developers and cryptocurrency assets.
Oldphantomoftheopera and Phantom Softwares operate Phantom Stealer, a Malware-as-a-Service infostealer targeting Windows systems through multi-stage in-memory execution and obfuscated PowerShell to harvest credentials and cryptocurrency data.
An unsigned GlobalProtect-themed MSI deploys a backdoor that utilizes Cloudflare Workers for configuration and Google Sheets for C2 communication, specifically targeting victims in Myanmar.
A ransomware-related threat actor is deploying MLTBackdoor, a sophisticated malware using ClickFix lures and BOF loading capabilities for post-exploitation.
Twill Typhoon leverages a supply chain compromise of the QuickFox VPN proxy to deliver the FDMTP implant through multi-stage loaders and execution guardrails.
The Chaos ransomware group is using a new Rust-based RAT called msaRAT that establishes covert C2 channels by hijacking headless Chrome and Edge browsers via the Chrome DevTools Protocol.
Threat actors compromised an Artlist subdomain using stolen credentials to deploy a ClickFix campaign that uses blockchain-based EtherHiding for evasion and delivers a multi-stage RAT.
The StegoAd campaign utilized 119 malicious browser extensions to perform ad fraud and steal Google and WordPress credentials from 2.6 million users.
Lazarus, Turla, and other advanced actors utilize kernel-level ETW tampering, including DKOM and hardware breakpoints, to blind EDR and anti-cheat telemetry on Windows 11.