NetScaler exploitation and RMM-driven ransomware
An attacker has exploited vulnerabilities in a public-facing gateway or remote access tool to execute a backdoor, followed by establishing persistence via unauthorized RMM software and initiating ransomware file encryption.
Based on research by Cisco Talos 2026-10-02 12 steps · 5 queries T1190 T1203 T1486
Brief
Why this hunt
Talos recently reported on a ransomware campaign that exploits public-facing gateways to gain a foothold in target networks. The report, "Give yourself room to be human" (https://blog.talosintelligence.com/give-yourself-room-to-be-human/), details how attackers use vulnerabilities in Citrix NetScaler and TeamViewer to execute a custom backdoor named Antino. Because the attackers move quickly from exploitation to the use of dual-use remote management (RMM) tools, static detections often fail to catch the transition before encryption begins.
How the hunt flows
The hunt begins with scoping. An analyst identifies hosts running versions of Citrix NetScaler or TeamViewer that contain high-severity vulnerabilities. This creates a focused set of hosts for the subsequent behavioral queries.
Next, the hunt looks for evidence of the breach. One query monitors HTTP activity for high-frequency request patterns to gateways, which often indicates the "loud" exploitation attempts described in the source report. Simultaneously, another query checks process activity for specific SHA256 hashes of the Antino backdoor and other malware identified by Talos.
The final phase focuses on persistence and impact. The hunt searches for the execution of common RMM tools like ScreenConnect, AnyDesk, or RustDesk. It uses a stacking technique to find tools that are rare across the fleet, as these are more likely to be attacker-controlled. Finally, a query monitors file activity for bursts of modifications. An analyst looks for processes changing hundreds or thousands of files in a narrow window, a signal of active encryption.
Blind spots
This hunt has two primary limitations. First, if the environment lacks TLS decryption at the gateway, the hunter cannot see the specific exploit payloads within encrypted HTTP traffic. In these cases, we must rely on meta-signals like request volume. Second, the hunt depends on agent-based telemetry. If the attacker moves to OT segments or network devices where no agent is present, the hunt will not see the resulting encryption or movement in those zones.
Steps
-
Scope vulnerable gateway and access software
Query · scopingIdentify hosts running software with known high-severity vulnerabilities mentioned in the report (NetScaler, TeamViewer).
reads hb_vulnerability_findingsqlSELECT device_uid, cve_uid, affected_package_name, affected_package_version, cvss_score FROM hb_vulnerability_finding WHERE (LOWER(affected_package_name) LIKE '%netscaler%' OR LOWER(affected_package_name) LIKE '%teamviewer%') AND severity_id >= 4What a hit looks like. Hosts running vulnerable versions of Citrix NetScaler or TeamViewer. Zero results means no known vulnerable versions are reporting, but unmanaged assets may remain.
-
Suspicious HTTP patterns to gateways
Query · enrichmentFind anomalous HTTP requests to gateway servers that might indicate exploitation attempts, such as high-frequency requests or rare user agents.
reads hb_http_activitysqlSELECT device_hostname, src_endpoint_ip, url_path, user_agent, COUNT(*) as request_count FROM hb_http_activity WHERE ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY device_hostname, src_endpoint_ip, url_path, user_agent HAVING request_count > 100 ORDER BY request_count DESCWhat a hit looks like. High-frequency requests to specific paths which might correspond to the AI-driven 'loud' attack mentioned in the article.
-
Antino backdoor process activity
Query · detection candidateDirectly search for the execution of malware reported by Talos using SHA256 hashes.
reads hb_process_activitysqlSELECT device_hostname, process_name, process_cmd_line, process_hash_sha256, user_name, time FROM hb_process_activity WHERE instr(',' || '{{backdoor_hashes}}' || ',', ',' || LOWER(process_hash_sha256) || ',') > 0 AND time >= datetime('now', '-{{lookback_days}} days')What a hit looks like. Any execution of the reported hashes indicates a confirmed compromise. Silence indicates this specific payload version is not present.
-
Assess Initial Compromise
Agent triageEvaluate if the scoping hits and early execution signs point to a successful breach.
-
Unauthorized RMM usage
Query · baselineFind RMM tools executed on hosts identified as likely breached, stack-counting to find rare instances.
reads hb_process_activitysqlSELECT device_hostname, LOWER(process_name) as p_name, COUNT(DISTINCT device_hostname) as host_count, MIN(time) as first_seen FROM hb_process_activity WHERE (instr(',' || '{{rmm_software}}' || ',', ',' || LOWER(process_name) || ',') > 0 OR instr(',' || '{{rmm_software}}' || ',', ',' || LOWER(process_original_file_name) || ',') > 0) AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY p_name HAVING host_count < 5What a hit looks like. RMM tool execution that is rare across the fleet, potentially indicating attacker persistence.
-
Ransomware impact signs
Query · enrichmentIdentify mass file modification activity on a single host within a narrow time window, typical of ransomware encryption.
reads hb_file_activitysqlSELECT device_hostname, process_name, COUNT(*) as file_mod_count, MIN(time) as start_time, MAX(time) as end_time FROM hb_file_activity WHERE activity_id IN (1, 3, 5) AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY device_hostname, process_name HAVING file_mod_count > 500 ORDER BY file_mod_count DESCWhat a hit looks like. A specific process modifying hundreds or thousands of files in a short burst.
-
Assess Full Chain Impact
Agent triageSynthesize the early compromise signs with the follow-on RMM and encryption activity to confirm the ransomware operation.
-
Route on verdict
DecisionInitiate response if the full-chain assessment confirms malicious activity.
-
Contain affected hosts
Response actionPrevent further lateral movement and data destruction by isolating confirmed compromised endpoints.
-
Manual analyst triage
Analyst taskFinal review of the evidence by a human analyst to confirm the agent's findings and identify tuning opportunities.
-
Close out hunt report
Analyst taskDocument findings and gaps.
Coverage
Scenario coverage
| Stage | Covered | How, or why not |
|---|---|---|
| Exploitation of Public-Facing Applications T1190 |
Yes | scoping-vulnerable-gateways, suspicious-http-patterns |
| Malware and Backdoor Execution T1203 |
Yes | backdoor-process-hashes |
| Remote Monitoring and Management Abuse | Yes | unauthorized-rmm-usage |
| Data Encrypted for Impact T1486 |
Yes | ransomware-impact-signs |
Blind spots
- Needs Direct telemetry from OT network devices. A negative result on the IT endpoints does not guarantee the OT network is safe if it lacks agent coverage. It would answer whether ransomware has successfully encrypted files on the OT segment. Remediation: Integrate OT network flow logs or specialized OT monitoring agents.
- Needs TLS decryption/inspection at the gateway. Attackers can hide exploit payloads inside encrypted traffic, leaving the hunter to rely only on meta-signals like request frequency or volume. It would answer what specific payloads or exploits were sent to the NetScaler. Remediation: Enable SSL/TLS inspection for inbound traffic to public-facing gateways.
Parameters & data
Parameters
| Parameter | Type | Default | What it is |
|---|---|---|---|
backdoor_hashes | list[hash] | 9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507, 96fa6a7714670823c83099ea01d24d6d3ae8fef027f01a4ddac14f123b1c9974, 90b1456cdbe6bc2779ea0b4736ed9a998a71ae37390331b6ba87e389a49d3d59, 540080fea97d88ed902c5e4f9a026b4fcd32ab263706c520e00728f1a29578b8, 9896a6fcb9bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7f | SHA256 hashes of the Antino backdoor and other malware from the report. |
lookback_days | number | 14 | Days of history to examine. |
rmm_software | list[string] | teamviewer, anydesk, screenconnect, rustdesk, logmein, atera, splashtop | Names of common RMM tools to monitor for unauthorized usage. |
scope_hosts | list[host] | — | Optional list of hostnames to focus the behavioral queries. |
Telemetry
| Source | Category | Telemetry |
|---|---|---|
| Endpoint telemetry (hb_ surfaces) | endpoint | endpoint |
| Web server / proxy logs | siem | network |
Source
---
analysis: A simple rule for a hash will miss the attacker if they rotate payloads;
a rule for RMM tools will produce too many false positives. This hunt pivots from
a vulnerability scope to rare behavioral baselines (RMM prevalence) and cross-correlates
them with file impact metrics to find the full intrusion chain.
blind_spots:
- id: limited-ot-visibility
owner: Network Engineering
question: whether ransomware has successfully encrypted files on the OT segment
remediation: Integrate OT network flow logs or specialized OT monitoring agents.
requires: Direct telemetry from OT network devices
risk: A negative result on the IT endpoints does not guarantee the OT network is
safe if it lacks agent coverage.
stage: ransomware-impact
- id: http-encryption
owner: Security Architecture
question: what specific payloads or exploits were sent to the NetScaler
remediation: Enable SSL/TLS inspection for inbound traffic to public-facing gateways.
requires: TLS decryption/inspection at the gateway
risk: Attackers can hide exploit payloads inside encrypted traffic, leaving the
hunter to rely only on meta-signals like request frequency or volume.
stage: initial-access-exploit
coverage:
- stage: initial-access-exploit
status: covered
steps:
- scoping-vulnerable-gateways
- suspicious-http-patterns
- stage: backdoor-execution
status: covered
steps:
- backdoor-process-hashes
- stage: remote-access-abuse
status: covered
steps:
- unauthorized-rmm-usage
- stage: ransomware-impact
status: covered
steps:
- ransomware-impact-signs
guardrails:
claims: no_unsupported
evidence: citation_required
missing_data: not_benign
telemetry: untrusted
hunt:
applicability: campaign-specific
handoff: keep-as-periodic-hunt
justification: The exploitation of zero-day vulnerabilities in remote access gateways
like Citrix NetScaler is a critical risk that leads directly to high-impact ransomware.
A hunt is necessary to find post-exploit evidence that standing rules might miss
due to the 'dual-use' nature of RMM tools.
methodology: model-assisted
trigger: intel-report
hypothesis: An attacker has exploited vulnerabilities in a public-facing gateway or
remote access tool to execute a backdoor, followed by establishing persistence via
unauthorized RMM software and initiating ransomware file encryption.
labels:
- hunt
- attack.t1190
- attack.t1203
- attack.t1486
- command and control
- execution
- impact
- initial access
name: NetScaler exploitation and RMM-driven ransomware
parameters:
backdoor_hashes:
default:
- 9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507
- 96fa6a7714670823c83099ea01d24d6d3ae8fef027f01a4ddac14f123b1c9974
- 90b1456cdbe6bc2779ea0b4736ed9a998a71ae37390331b6ba87e389a49d3d59
- 540080fea97d88ed902c5e4f9a026b4fcd32ab263706c520e00728f1a29578b8
- 9896a6fcb9bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7f
description: SHA256 hashes of the Antino backdoor and other malware from the report.
from:
kind: article
observed: '2026-10-01'
ref: https://blog.talosintelligence.com/give-yourself-room-to-be-human/
type: list[hash]
lookback_days:
default: '14'
description: Days of history to examine.
type: number
rmm_software:
default:
- teamviewer
- anydesk
- screenconnect
- rustdesk
- logmein
- atera
- splashtop
description: Names of common RMM tools to monitor for unauthorized usage.
type: list[string]
scope_hosts:
default: []
description: Optional list of hostnames to focus the behavioral queries.
type: list[host]
provenance:
authors:
- name: Huntbase hunt generation
org: huntbase.io
generated:
by: huntbase-hunt-generation
from: https://blog.talosintelligence.com/give-yourself-room-to-be-human/
gates:
- dry-run
- lint
- critic
model: hb_google/gemini-3-flash-preview
rationale: Start with public-facing segments containing Citrix NetScaler or TeamViewer
installations. Prioritize hosts with high-severity vulnerabilities first.
references:
- name: "Talos \u2014 Give yourself room to be human"
url: https://blog.talosintelligence.com/give-yourself-room-to-be-human/
related:
- hunt: unauthorized-rmm-persistence
reason: This hunt focuses on the specific ransomware chain; a broader RMM hunt would
cover more diverse persistence scenarios.
relation: out-of-scope-alternative
scenario:
stages:
- name: Exploitation of Public-Facing Applications
observables:
- Citrix NetScaler ADC
- Citrix NetScaler Gateway
- NetScaler zero-day vulnerabilities
- Automated AI agent exploitation
- Exposed file-sharing servers
slug: initial-access-exploit
tactic: initial-access
techniques:
- T1190
- name: Malware and Backdoor Execution
observables:
- Antino backdoor
- W32.Injector
- sample.exe
- tmp00055df5.dll
- f_006048.exe
- SECOH-QAD.exe
- 9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507
- 96fa6a7714670823c83099ea01d24d6d3ae8fef027f01a4ddac14f123b1c9974
- 90b1456cdbe6bc2779ea0b4736ed9a998a71ae37390331b6ba87e389a49d3d59
- 540080fea97d88ed902c5e4f9a026b4fcd32ab263706c520e00728f1a29578b8
- 9896a6fcb9bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7f
- w32.9f1f11a708-100.sbx.tg
- w32.injector
- w32.540080fea9-95.sbx.tg
- w32.9896a6fcb9-95.sbx.tg
slug: backdoor-execution
tactic: execution
techniques:
- T1203
- name: Remote Monitoring and Management Abuse
observables:
- TeamViewer high-severity flaws
- Unauthorized RMM tool use
- Dual-use RMM abuse
slug: remote-access-abuse
tactic: command-and-control
- name: Data Encrypted for Impact
observables:
- Ransomware-linked malware
- OT network data encryption
slug: ransomware-impact
tactic: impact
techniques:
- T1486
summary: Threat actors exploit critical vulnerabilities in public-facing infrastructure
like Citrix NetScaler or through automated AI agents to gain initial access, subsequently
deploying backdoors like Antino and abusing remote management tools like TeamViewer.
This activity ultimately leads to data breaches on file-sharing servers and the
deployment of ransomware in critical infrastructure OT networks for data encryption.
severity: critical
targets:
analyst:
name: Tier-2 analyst
role: analyst
endpoint:
category: endpoint
name: Endpoint telemetry (hb_ surfaces)
telemetry:
- endpoint
hunter:
agent: true
name: Hunt agent
web:
category: siem
name: Web server / proxy logs
telemetry:
- network
tlp: clear
type: investigation
---
# NetScaler exploitation and RMM-driven ransomware
This hunt follows the complete attack chain reported by Talos, focusing on the exploitation of Citrix NetScaler and TeamViewer. It begins by identifying vulnerable assets, then moves to detect early-stage backdoor execution via known hashes. Finally, it looks for the aftermath: unauthorized remote management tools and the high-volume file modifications characteristic of ransomware impact.
## scoping-vulnerable-gateways
<!-- Scope vulnerable gateway and access software -->
Identify hosts running software with known high-severity vulnerabilities mentioned in the report (NetScaler, TeamViewer).
```sqlite target=endpoint role=scoping
~~~yaml
expected: Hosts running vulnerable versions of Citrix NetScaler or TeamViewer. Zero
results means no known vulnerable versions are reporting, but unmanaged assets may
remain.
reads:
- affected_package_name
- affected_package_version
- cve_uid
- cvss_score
- device_uid
- severity_id
silence: not_evidence_of_absence
source: hb_vulnerability_finding
verified: dry-run
verified_at: '2026-10-02'
~~~
SELECT device_uid, cve_uid, affected_package_name, affected_package_version, cvss_score FROM hb_vulnerability_finding WHERE (LOWER(affected_package_name) LIKE '%netscaler%' OR LOWER(affected_package_name) LIKE '%teamviewer%') AND severity_id >= 4
```
## early-stage-p
<!-- Parallel: Access and Execution Evidence -->
parallel:
- → suspicious-http-patterns
- → backdoor-process-hashes
join: → assess-initial-compromise
## suspicious-http-patterns
<!-- Suspicious HTTP patterns to gateways -->
Find anomalous HTTP requests to gateway servers that might indicate exploitation attempts, such as high-frequency requests or rare user agents.
```sqlite target=web role=enrichment params=(lookback_days=lookback_days, scope_hosts=scope_hosts)
~~~yaml
expected: High-frequency requests to specific paths which might correspond to the
AI-driven 'loud' attack mentioned in the article.
reads:
- device_hostname
- src_endpoint_ip
- time
- url_path
- user_agent
silence: not_evidence_of_absence
source: hb_http_activity
verified: dry-run
verified_at: '2026-10-02'
~~~
SELECT device_hostname, src_endpoint_ip, url_path, user_agent, COUNT(*) as request_count FROM hb_http_activity WHERE ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY device_hostname, src_endpoint_ip, url_path, user_agent HAVING request_count > 100 ORDER BY request_count DESC
```
## backdoor-process-hashes
<!-- Antino backdoor process activity -->
Directly search for the execution of malware reported by Talos using SHA256 hashes.
```sqlite target=endpoint role=detection-candidate params=(lookback_days=lookback_days, backdoor_hashes=backdoor_hashes)
~~~yaml
expected: Any execution of the reported hashes indicates a confirmed compromise. Silence
indicates this specific payload version is not present.
reads:
- device_hostname
- process_cmd_line
- process_hash_sha256
- process_name
- time
- user_name
silence: evidence_of_absence
source: hb_process_activity
verified: dry-run
verified_at: '2026-10-02'
~~~
SELECT device_hostname, process_name, process_cmd_line, process_hash_sha256, user_name, time FROM hb_process_activity WHERE instr(',' || '{{backdoor_hashes}}' || ',', ',' || LOWER(process_hash_sha256) || ',') > 0 AND time >= datetime('now', '-{{lookback_days}} days')
```
## assess-initial-compromise
<!-- Assess Initial Compromise -->
```agent target=hunter
cite: required
context:
- scoping-vulnerable-gateways
- suspicious-http-patterns
- backdoor-process-hashes
max_iterations: 3
objective: Determine if any host identified in the scoping query shows signs of exploitation
(HTTP anomalies) or execution of the Antino backdoor.
success_criteria: A verdict per host indicating breach status with citations of suspicious
activity.
tools:
- endpoint
- web
```
## follow-on-p
<!-- Parallel: Persistence and Ransomware Impact -->
parallel:
- → unauthorized-rmm-usage
- → ransomware-impact-signs
join: → assess-full-chain
## unauthorized-rmm-usage
<!-- Unauthorized RMM usage -->
Find RMM tools executed on hosts identified as likely breached, stack-counting to find rare instances.
```sqlite target=endpoint role=baseline params=(lookback_days=lookback_days, rmm_software=rmm_software, scope_hosts=scope_hosts)
~~~yaml
baseline:
compare: first_seen
window: '{{lookback_days}}d'
expected: RMM tool execution that is rare across the fleet, potentially indicating
attacker persistence.
prevalence:
by: device_hostname
key:
- process_name
rare_below: 5
reads:
- device_hostname
- process_name
- process_original_file_name
- time
silence: not_evidence_of_absence
source: hb_process_activity
verified: dry-run
verified_at: '2026-10-02'
~~~
SELECT device_hostname, LOWER(process_name) as p_name, COUNT(DISTINCT device_hostname) as host_count, MIN(time) as first_seen FROM hb_process_activity WHERE (instr(',' || '{{rmm_software}}' || ',', ',' || LOWER(process_name) || ',') > 0 OR instr(',' || '{{rmm_software}}' || ',', ',' || LOWER(process_original_file_name) || ',') > 0) AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY p_name HAVING host_count < 5
```
## ransomware-impact-signs
<!-- Ransomware impact signs -->
Identify mass file modification activity on a single host within a narrow time window, typical of ransomware encryption.
```sqlite target=endpoint role=enrichment params=(lookback_days=lookback_days, scope_hosts=scope_hosts)
~~~yaml
expected: A specific process modifying hundreds or thousands of files in a short burst.
reads:
- activity_id
- device_hostname
- process_name
- time
silence: not_evidence_of_absence
source: hb_file_activity
verified: dry-run
verified_at: '2026-10-02'
~~~
SELECT device_hostname, process_name, COUNT(*) as file_mod_count, MIN(time) as start_time, MAX(time) as end_time FROM hb_file_activity WHERE activity_id IN (1, 3, 5) AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY device_hostname, process_name HAVING file_mod_count > 500 ORDER BY file_mod_count DESC
```
## assess-full-chain
<!-- Assess Full Chain Impact -->
```agent target=hunter
cite: required
context:
- assess-initial-compromise
- unauthorized-rmm-usage
- ransomware-impact-signs
max_iterations: 4
objective: Combine the evidence of breach from the first agent with the observations
of RMM tools and file encryption spikes. Determine if a ransomware incident is active.
success_criteria: A final verdict citing the progression from vulnerability to impact
per host.
tools:
- endpoint
- web
```
## route-on-verdict
<!-- Route on verdict -->
if~: "the assessment confirms both initial compromise and follow-on ransomware-linked behavior" (confidence: high, judge=hunter)
then: → contain-threat
indeterminate: → manual-review
unavailable: → manual-review (blind_spot: limited-ot-visibility)
else: → manual-review
## contain-threat
<!-- Contain affected hosts -->
```action target=endpoint
~~~yaml
approval: required
~~~
Isolate the host, terminate the malicious process identified in the file activity step, and revoke any sessions associated with the host's users.
```
→ manual-review
## manual-review
<!-- Manual analyst triage -->
```manual target=analyst
Review the cited rows in the follow-on assessment. Confirm if the RMM usage was authorized and if the file modifications were indeed malicious encryption or benign high-volume tasks like indexing or updates.
```
→ close-out-report
## close-out-report
<!-- Close out hunt report -->
```manual target=analyst
Record the number of hosts examined, the number of confirmed compromises, and the coverage of the NetScaler/TeamViewer assets. Note any OT segments that were unreachable.
```
→ end
Run it
Take this hunt into your environment.
Open it in Huntbase to run every step against your own connections, with Scout weighing the evidence and your analysts in command. Or take the open hunt.md file anywhere that reads the format.
Machine-drafted by huntbase-hunt-generation using hb_google/gemini-3-flash-preview, gated by dry-run, lint, critic, then reviewed by a person.