Critical Unpatched Citrix NetScaler RCE Zero-Days Exploited
Unauthenticated remote code execution vulnerabilities in Citrix NetScaler ADC and Gateway are being actively exploited in the wild to deploy webshells and steal credentials.
Browse public community intelligence reports, source analysis, and threat research.
7 intel reports
The threat actor zdn2pwn utilizes XHOPELESS v1.0, a sophisticated multi-phase wiper designed to permanently brick Windows systems by corrupting UEFI firmware, destroying disk partitions, and disabling all recovery mechanisms.
Stealer/1.0 is a hybrid malware designed to exfiltrate cloud, browser, and developer credentials via Discord webhooks before executing a highly destructive wiper routine that formats the C: drive.
Direwolf is an emerging ransomware group using custom Golang-based malware and double-extortion tactics to target global organizations, particularly in the manufacturing and technology sectors.
The Silver Fox threat actor utilizes a modular four-stage loader chain starting with a fake Flash Player to deliver AtlasRAT for credential theft and WeChat manipulation.
The NoEscape wiper is a destructive 'troll' malware that locks user interfaces, hijacks executable associations, and performs raw disk writes to disable systems.
The REF6045 activity cluster uses ClickFix social engineering to deploy SCMBANKER, a PowerShell toolkit designed for banking fraud targeting Mexican financial institutions.
An active phishing campaign targets hospitality organizations in Europe and Asia using photo-themed ZIP files to deliver a Node.js-based implant called TonRAT.