logo

Citrix Bleed Vulnerability: Background and Recommendations

ID: e196f474-1c3c-5e52-9ba6-bf2387133c1b

STIX ID: report--e196f474-1c3c-5e52-9ba6-bf2387133c1b

Feed Name: ReliaQuest Blog

Threat Score
85/100

Date Published: 2023-11-09

Date Updated: 2026-04-29

...
...

ReliaQuest reports active, in-the-wild exploitation of Citrix Bleed (CVE-2023-4966) by multiple threat groups — including a LockBit affiliate that gained access, exfiltrated files using rclone, and left ransom-readme files without encrypting endpoints — and provides observed TTPs (Kerberoasting, NTDS.dit dumping, ZeroLogon attempts), detection indicators (Citrix TCPCONNSTAT client/source IP mismatches and a sigma rule), and urgent remediation guidance (install patched NetScaler builds and kill active sessions).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.