New Ransomware Campaign Targets Citrix NetScaler Flaw
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2023-3519 | Unauthenticated RCE in Citrix NetScaler ADC and NetScaler Gateway CVE-2023-3519 is a critical (CVSS 9.8) unauthenticated remote code execution flaw caused by improper code-injection handling (CWE-94) in Citrix NetScaler ADC and NetScaler Gateway. A remote attacker with no credentials can trigger it by sending crafted requests to an appliance configured as a Gateway (VPN/ICA proxy/RDP proxy) or AAA authentication virtual server, gaining arbitrary code execution on the appliance. Exploitation typically yields a foothold behind the VPN edge — access to internal networks, credential theft, and follow-on activity such as espionage or ransomware deployment. Any organization running unpatched NetScaler ADC/Gateway appliances, especially internet-facing remote-access endpoints, is affected; NetScaler is one of the most widely deployed enterprise VPN/ADC platforms. Exploitation is confirmed in the wild: the flaw was added to CISA's KEV on 2023-07-19 with known ransomware use, EPSS estimates a 99.7% exploitation probability, and researchers have linked activity to China-nexus espionage (Silk Typhoon) and ransomware operations. Do: Immediately upgrade internet-facing NetScaler ADC/Gateway appliances to the fixed builds in Citrix's advisory (14.1-8.50+, 13.1-49.13+, 13.0-82.45+, 12.1-55.300+, including FIPS/NDcPP equivalents) — per CISA KEV, apply these mitigations or discontinue use if patching is unavailable. Confirm whether each appliance is configured as a Gateway or AAA virtual server (only those are affected), and hunt for compromise — unexpected configuration changes, unfamiliar accounts, webshells, or anomalous VPN sessions — rotating credentials on any suspected compromise. | 9.8 | 100% | KEV ransomware PoC |
| largetens of thousands of internet-exposed NetScaler Gateway/ADC appliances (order 10k-100k at disclosure), serving hundreds of thousands to millions of downstream… |
Full article361 words · extracted from infosecurity-magazine.com · click to collapse
Cybersecurity experts at Sophos X-Ops have uncovered a wave of attacks targeting unpatched Citrix NetScaler systems exposed to the internet.
Describing the malicious campaign on X last Friday, the security researchers said it leveraged a critical remote code execution vulnerability (CVE-2023-3519), allowing threat actors to infiltrate systems and conduct domain-wide cyber campaigns.
The similarity between these attacks and previous incidents utilizing the same tactics, techniques and procedures (TTPs) has raised concerns about a potentially organized and experienced threat group.
The assault, which Sophos X-Ops has been tracking, began with the compromise of vulnerable systems in mid-August. Once inside the targeted network, the attackers exploited the aforementioned NetScaler vulnerability as a code-injection tool, enabling them to initiate a comprehensive domain-wide assault.
In the later stages, the attacks demonstrated a higher level of complexity, marked by several malicious actions. These included injecting harmful software into essential Windows processes to gain more control over compromised systems, using specific online platforms for staging malware and employing intricate scripts that were difficult to detect and decipher.
Moreover, Sophos X-Ops observed the deployment of randomly named PHP webshells on victim machines, a tactic consistent with other industry reports. The collaboration between different security entities in revealing the nature of these attacks has provided a broader understanding of the threat landscape.
In fact, the attacks closely align with findings reported by Fox-IT in August, which unveiled that approximately 2000 Citrix NetScaler systems worldwide had been compromised due to CVE-2023-3519.
In response, Citrix issued a patch for the CVE-2023-3519 vulnerability on July 18. However, the implications of these attacks go beyond simple patch application. To ensure comprehensive protection, organizations are urged not only to apply the patch but also to meticulously inspect their network for signs of compromise.
With the injected payload still under analysis, Sophos X-Ops suspects the involvement of a well-known ransomware threat actor, attributing this wave of attacks to the Threat Activity Cluster STAC4663.
Organizations are encouraged to examine historical data for traces of the identified Indicators of Compromise (IoCs) and follow Sophos X-Ops’ guidance to safeguard their infrastructure from the ongoing threat.
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.infosecurity-magazine.com/news/ransomware-targets-citrix/