Mass-Exploitation Campaign Targets Citrix NetScalers With Backdoors
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2023-3519 | Unauthenticated RCE in Citrix NetScaler ADC and NetScaler Gateway CVE-2023-3519 is a critical (CVSS 9.8) unauthenticated remote code execution flaw caused by improper code-injection handling (CWE-94) in Citrix NetScaler ADC and NetScaler Gateway. A remote attacker with no credentials can trigger it by sending crafted requests to an appliance configured as a Gateway (VPN/ICA proxy/RDP proxy) or AAA authentication virtual server, gaining arbitrary code execution on the appliance. Exploitation typically yields a foothold behind the VPN edge — access to internal networks, credential theft, and follow-on activity such as espionage or ransomware deployment. Any organization running unpatched NetScaler ADC/Gateway appliances, especially internet-facing remote-access endpoints, is affected; NetScaler is one of the most widely deployed enterprise VPN/ADC platforms. Exploitation is confirmed in the wild: the flaw was added to CISA's KEV on 2023-07-19 with known ransomware use, EPSS estimates a 99.7% exploitation probability, and researchers have linked activity to China-nexus espionage (Silk Typhoon) and ransomware operations. Do: Immediately upgrade internet-facing NetScaler ADC/Gateway appliances to the fixed builds in Citrix's advisory (14.1-8.50+, 13.1-49.13+, 13.0-82.45+, 12.1-55.300+, including FIPS/NDcPP equivalents) — per CISA KEV, apply these mitigations or discontinue use if patching is unavailable. Confirm whether each appliance is configured as a Gateway or AAA virtual server (only those are affected), and hunt for compromise — unexpected configuration changes, unfamiliar accounts, webshells, or anomalous VPN sessions — rotating credentials on any suspected compromise. | 9.8 | 100% | KEV ransomware PoC |
| largetens of thousands of internet-exposed NetScaler Gateway/ADC appliances (order 10k-100k at disclosure), serving hundreds of thousands to millions of downstream… |
Full article309 words · extracted from infosecurity-magazine.com · click to collapse
A widespread cyber-attack targeting thousands of Citrix NetScalers has been unveiled by cybersecurity firm Fox-IT (part of NCC Group) in collaboration with the Dutch Institute of Vulnerability Disclosure (DIVD).
The campaign involved exploiting a critical vulnerability, CVE-2023-3519, which allowed malicious actors to infiltrate and compromise vulnerable NetScalers, even after patches and reboots.
Describing the threat in an advisory published on Tuesday, NCC Group said the scale of the attack became evident as over 1900 NetScalers were found to be still backdoored at the time of discovery.
The attackers employed automated methods to place web shells onto compromised systems, granting them persistent access and the ability to execute arbitrary commands. Despite efforts to apply patches and updates, only half of the compromised NetScalers had been successfully updated to fix the vulnerability.
The vulnerability itself was disclosed on July 18, following reports of limited exploitation by various security organizations. This prompted a joint effort by Fox-IT and DIVD to identify compromised systems and initiate responsible disclosure notifications.
Read more on these events: Thousands of Citrix Servers Exposed to Zero-Day Bug
In the new advisory, NCC Group revealed that the compromised NetScalers were spread across different countries, with the majority located in Europe. However, a notable portion remained untouched in countries like Canada, Russia and the United States.
In response, Fox-IT and DIVD released recommendations for NetScaler administrators to assess the security of their systems. The suggestions include performing Indicator of Compromise (IoC) checks, utilizing provided tools like Python scripts for forensic analysis and investigating possible unauthorized activities if a web shell is detected.
The incident highlights the ongoing challenge of securing edge devices such as NetScalers, as attackers exploit vulnerabilities before patches can be applied.
This development emerged just one week after the Shadowserver Foundation announced that it detected nearly 7000 exposed and unpatched instances of NetScaler ADC and Gateway.
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.infosecurity-magazine.com/news/mass-exploitation-campaign-citrix/