logo

Detecting NetScaler Compromise with THOR During CVE-2025-7775 Attacks

ID: 5229553d-8ad2-5b5b-a9fe-b457e919d155

STIX ID: report--5229553d-8ad2-5b5b-a9fe-b457e919d155

Feed Name: Nextron Systems

Threat Score
88/100

Date Published: 2025-09-08

Date Updated: 2026-04-28

Author: Franziska Ploss

...
...

**Citrix NetScaler appliances are being actively exploited via critical flaws (notably CVE-2025-7775, CVSS 9.2); organizations should assume internet-facing appliances may already be compromised and must urgently assess and remediate exposure. Nextron recommends agentless forensic compromise assessments using THOR (SSHFS, YARA/IOC) to detect web shells, backdoors, modified system files, and other post-exploitation artifacts, and emphasizes that patching alone may not be sufficient.**

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.