Curated news, CVE analysis, and threat reports from the world's top cybersecurity sources.
Notification This report is provided "as is" for informational purposes only. The Department of Homeland Security (DHS) does not provide any warranties of any kind regarding any information contained herein.
CISA received four files for analysis in response to the Citrix Bleed vulnerability (CVE-2023-4966) affecting NetScaler ADC and Gateway appliances. The files include a Windows batch file, executable, DLL, and Python script used to save registry hives, dump LSASS memory, and establish WinRM sessions.
CISA published a malware analysis report detailing threat actor exploitation of Citrix Bleed (CVE-2023-4966), including IOCs, TTPs, and recommended mitigations for defenders.
CISA published a malware analysis report detailing threat actor exploitation of Citrix Bleed (CVE-2023-4966), including IOCs, TTPs, and recommended mitigations for defenders.
This malware analysis report from CISA covers multiple backdoor families including SUBMARINE, SKIPJACK, SEASPRAY, WHIRLPOOL, and SALTWATER. These tools provide attackers persistent remote access and data theft capabilities. Defenders are provided with detection signatures and IOCs to identify compromise.
This malware analysis report from CISA covers multiple backdoor families including SUBMARINE, SKIPJACK, SEASPRAY, WHIRLPOOL, and SALTWATER. These tools provide attackers persistent remote access and data theft capabilities. Defenders are provided with detection signatures and IOCs to identify compromise.