Intel Exchange

Browse public community intelligence reports, source analysis, and threat research.

Cover image for Critical Unpatched Citrix NetScaler RCE Zero-Days Exploited

Critical Unpatched Citrix NetScaler RCE Zero-Days Exploited

Unauthenticated remote code execution vulnerabilities in Citrix NetScaler ADC and Gateway are being actively exploited in the wild to deploy webshells and steal credentials.

Vikas Lokhande@vlokhande8 days ago

9 intel reports

Unattributed threat actors are leveraging legitimate MSP360 RMM and ConnectWise ScreenConnect installers via phishing to establish persistent remote access and deploy post-compromise tools.

SilverFox threat actors have upgraded their malware delivery chain from open access and whitelisting to a sophisticated cloud-based blacklist mechanism to evade detection by security researchers.

Russian state-sponsored actor BlueDelta utilized macro-enabled Word documents to deploy HOOKEDGE, a batch-script backdoor abusing legitimate webhook services for C2 and exfiltration targeting European government entities.

BTMOB has evolved from a single Malware-as-a-Service operation into a fragmented ecosystem of independent resellers and source-code variants targeting Android users for financial theft.

The EvilTokens and ARToken Phishing-as-a-Service (PhaaS) platforms use Microsoft Device Code flows and browser-side decryption to bypass MFA and achieve persistent Microsoft 365 account takeovers.

ARToken is an EvilTokens-linked Phishing-as-a-Service platform that uses Microsoft OAuth Device Code grants to capture Primary Refresh Tokens (PRTs) for persistent access and BEC operations.