Intel Exchange

Browse public community intelligence reports, source analysis, and threat research.

Cover image for Critical Unpatched Citrix NetScaler RCE Zero-Days Exploited

Critical Unpatched Citrix NetScaler RCE Zero-Days Exploited

Unauthenticated remote code execution vulnerabilities in Citrix NetScaler ADC and Gateway are being actively exploited in the wild to deploy webshells and steal credentials.

Vikas Lokhande@vlokhande8 days ago

7 intel reports

Storm-2992 operates EvilTokens, an AI-driven Phishing-as-a-Service platform targeting Microsoft 365 through device code authentication abuse to facilitate business email compromise.

Chinese-speaking threat actors are using OctLurk and SilkLurk backdoors to target government, healthcare, and educational sectors in Central Asia via modular in-memory plugins.

The EvilTokens and ARToken Phishing-as-a-Service (PhaaS) platforms use Microsoft Device Code flows and browser-side decryption to bypass MFA and achieve persistent Microsoft 365 account takeovers.

ARToken is an EvilTokens-linked Phishing-as-a-Service platform that uses Microsoft OAuth Device Code grants to capture Primary Refresh Tokens (PRTs) for persistent access and BEC operations.

The ToddyCat APT group utilizes Umbrij malware to compromise corporate Gmail accounts by leveraging a technique called Shadow Token via Remote Debug (STRD) to steal OAuth tokens.