Critical Unpatched Citrix NetScaler RCE Zero-Days Exploited
Unauthenticated remote code execution vulnerabilities in Citrix NetScaler ADC and Gateway are being actively exploited in the wild to deploy webshells and steal credentials.
Browse public community intelligence reports, source analysis, and threat research.
9 intel reports
Unattributed threat actors are leveraging legitimate MSP360 RMM and ConnectWise ScreenConnect installers via phishing to establish persistent remote access and deploy post-compromise tools.
SilverFox threat actors have upgraded their malware delivery chain from open access and whitelisting to a sophisticated cloud-based blacklist mechanism to evade detection by security researchers.
An unidentified threat actor is conducting a global phishing campaign using Vercel-hosted lures to deliver legitimate, signed RMM tools for remote system access.
Russian state-sponsored actor BlueDelta utilized macro-enabled Word documents to deploy HOOKEDGE, a batch-script backdoor abusing legitimate webhook services for C2 and exfiltration targeting European government entities.
BTMOB has evolved from a single Malware-as-a-Service operation into a fragmented ecosystem of independent resellers and source-code variants targeting Android users for financial theft.
The EvilTokens and ARToken Phishing-as-a-Service (PhaaS) platforms use Microsoft Device Code flows and browser-side decryption to bypass MFA and achieve persistent Microsoft 365 account takeovers.
ARToken is an EvilTokens-linked Phishing-as-a-Service platform that uses Microsoft OAuth Device Code grants to capture Primary Refresh Tokens (PRTs) for persistent access and BEC operations.
Turla (Secret Blizzard) targets government and military entities globally using the custom STOCKSTAY and Kazuar backdoors, often leveraging hijacked infrastructure.
An active phishing campaign targets hospitality organizations in Europe and Asia using photo-themed ZIP files to deliver a Node.js-based implant called TonRAT.