Citrix Bleed Vulnerability: Background and Recommendations
ID: e196f474-1c3c-5e52-9ba6-bf2387133c1b
STIX ID: report--e196f474-1c3c-5e52-9ba6-bf2387133c1b
Feed Name: ReliaQuest Blog
ReliaQuest reports active, in-the-wild exploitation of Citrix Bleed (CVE-2023-4966) by multiple threat groups — including a LockBit affiliate that gained access, exfiltrated files using rclone, and left ransom-readme files without encrypting endpoints — and provides observed TTPs (Kerberoasting, NTDS.dit dumping, ZeroLogon attempts), detection indicators (Citrix TCPCONNSTAT client/source IP mismatches and a sigma rule), and urgent remediation guidance (install patched NetScaler builds and kill active sessions).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
