Hackers used password spraying to breach Citrix, investigation confirms
Full article575 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
The unsophisticated technique gave the intruders access to two corporate drives for a “limited number of days,” Citrix's president says.
The hackers who breached corporate VPN service provider Citrix last year used an unsophisticated technique that throws commonly used, weak passwords at a system until one works, the company’s investigators has confirmed.
The “password spraying” ploy allowed the hackers to steal business files from a Citrix network drive along with a drive linked with its consulting practice, Citrix President David Henshall wrote in a blog post last week. The attackers had access to the drives for a “limited number of days,” between October 2018 and March 2019, he said.
Henshall did not say who carried out the hack or what their ultimate objective was. VPN providers could be an enticing target for any set of hackers looking for a foothold in a corporation’s network.
“The cybercriminals also may have accessed the individual virtual drives and company email accounts of a very limited number of compromised users and launched without further exploitation a limited number of internal applications,” Henshall added.
A Citrix spokesperson declined to comment when asked what those “internal applications” were and what they did.
The Florida-based company, which says it provides its services to more than 400,000 companies worldwide, is still reviewing what documents were accessed by the hackers and is in the process of notifying the “limited number of customers’” who might need to take “additional protective steps,” Henshall said.
In announcing the breach in March, Citrix said that password spraying was the likely, if unconfirmed, technique used by the attackers. But the company has now highlighted what it did to respond. It reset all passwords and shored up how it manages those credentials, is more closely monitoring data that leaves its networks, and has cut out internal access to its data for “non-essential” web services, according to Henshall.
To help with the clean-up, Citrix hired FireEye’s incident response unit, Mandiant, to remediate the breach. The FBI also investigated the breach.
With the investigation behind him, Henshall said he is focused on “fostering a security culture at Citrix that prioritizes prevention and also ensures that we detect and respond effectively to any future incidents.”
Latest Podcasts
Government
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
Feds accuse China of ‘systematic’ distillation of U.S. AI models
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
Jail time for Maine child in 764 marks turning point in federal law enforcement
Technology
Threats
Chinese espionage groups swarm to exploit triple-link chain of zero-days
Microsoft discloses two actively exploited zero-days among 974 vulnerabilities
Russian national extradited to US for alleged involvement in bank-account takeover scheme
Attackers exploit zero-days in consistently besieged SonicWall product
Policy
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/hackers-used-password-spraying-breach-citrix-investigation-confirms/