A Second Look at CVE-2019-19781 (Citrix NetScaler / ADC)
ID: 9fc21d82-0f70-5373-8f44-fb293b71ed66
STIX ID: report--9fc21d82-0f70-5373-8f44-fb293b71ed66
Feed Name: Fox-IT blog
Threat Score
**Executive summary:** This report revisits CVE-2019-19781 (Citrix NetScaler/ADC), documents widespread active exploitation and deployment of webshells/backdoors (including NOTROBIN 'palware' that removes competing backdoors), provides IOCs and statistics showing thousands of vulnerable and compromised devices, and describes a newly demonstrated single-request exploit that bypasses adversary patching and common detection assumptions.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
