logo

Approximately 2000 Citrix NetScalers backdoored in mass-exploitation campaign

ID: 94364a22-bad8-56ba-8a4b-e9f74c862359

STIX ID: report--94364a22-bad8-56ba-8a4b-e9f74c862359

Feed Name: Fox-IT blog

Threat Score
85/100

Date Published: 2023-08-15

Date Updated: 2026-04-27

...
...

Fox-IT and the Dutch Institute for Vulnerability Disclosure investigated an automated, large-scale exploitation of Citrix NetScaler (CVE-2023-3519) where adversaries deployed persistent webshells that allow arbitrary command execution even after patches or reboots; scans found roughly 2,491 webshells across 1,952 distinct NetScalers (1,828 still backdoored as of Aug 14, 2023) out of ~31,127 vulnerable devices, prompting IOC triage, forensic recommendations, and responsible disclosure to affected parties.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.