← All hunts critical TLP:CLEAR

NetScaler exploitation and RMM-driven ransomware

An attacker has exploited vulnerabilities in a public-facing gateway or remote access tool to execute a backdoor, followed by establishing persistence via unauthorized RMM software and initiating ransomware file encryption.

Based on research by Cisco Talos 2026-10-02 12 steps · 5 queries T1190 T1203 T1486

Brief

Why this hunt

Talos recently reported on a ransomware campaign that exploits public-facing gateways to gain a foothold in target networks. The report, "Give yourself room to be human" (https://blog.talosintelligence.com/give-yourself-room-to-be-human/), details how attackers use vulnerabilities in Citrix NetScaler and TeamViewer to execute a custom backdoor named Antino. Because the attackers move quickly from exploitation to the use of dual-use remote management (RMM) tools, static detections often fail to catch the transition before encryption begins.

How the hunt flows

The hunt begins with scoping. An analyst identifies hosts running versions of Citrix NetScaler or TeamViewer that contain high-severity vulnerabilities. This creates a focused set of hosts for the subsequent behavioral queries.

Next, the hunt looks for evidence of the breach. One query monitors HTTP activity for high-frequency request patterns to gateways, which often indicates the "loud" exploitation attempts described in the source report. Simultaneously, another query checks process activity for specific SHA256 hashes of the Antino backdoor and other malware identified by Talos.

The final phase focuses on persistence and impact. The hunt searches for the execution of common RMM tools like ScreenConnect, AnyDesk, or RustDesk. It uses a stacking technique to find tools that are rare across the fleet, as these are more likely to be attacker-controlled. Finally, a query monitors file activity for bursts of modifications. An analyst looks for processes changing hundreds or thousands of files in a narrow window, a signal of active encryption.

Blind spots

This hunt has two primary limitations. First, if the environment lacks TLS decryption at the gateway, the hunter cannot see the specific exploit payloads within encrypted HTTP traffic. In these cases, we must rely on meta-signals like request volume. Second, the hunt depends on agent-based telemetry. If the attacker moves to OT segments or network devices where no agent is present, the hunt will not see the resulting encryption or movement in those zones.

Steps

  1. Scope vulnerable gateway and access software

    Query · scoping

    Identify hosts running software with known high-severity vulnerabilities mentioned in the report (NetScaler, TeamViewer).

    reads hb_vulnerability_findingsql
    SELECT device_uid, cve_uid, affected_package_name, affected_package_version, cvss_score FROM hb_vulnerability_finding WHERE (LOWER(affected_package_name) LIKE '%netscaler%' OR LOWER(affected_package_name) LIKE '%teamviewer%') AND severity_id >= 4

    What a hit looks like. Hosts running vulnerable versions of Citrix NetScaler or TeamViewer. Zero results means no known vulnerable versions are reporting, but unmanaged assets may remain.

  2. Suspicious HTTP patterns to gateways

    Query · enrichment

    Find anomalous HTTP requests to gateway servers that might indicate exploitation attempts, such as high-frequency requests or rare user agents.

    reads hb_http_activitysql
    SELECT device_hostname, src_endpoint_ip, url_path, user_agent, COUNT(*) as request_count FROM hb_http_activity WHERE ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY device_hostname, src_endpoint_ip, url_path, user_agent HAVING request_count > 100 ORDER BY request_count DESC

    What a hit looks like. High-frequency requests to specific paths which might correspond to the AI-driven 'loud' attack mentioned in the article.

  3. Antino backdoor process activity

    Query · detection candidate

    Directly search for the execution of malware reported by Talos using SHA256 hashes.

    reads hb_process_activitysql
    SELECT device_hostname, process_name, process_cmd_line, process_hash_sha256, user_name, time FROM hb_process_activity WHERE instr(',' || '{{backdoor_hashes}}' || ',', ',' || LOWER(process_hash_sha256) || ',') > 0 AND time >= datetime('now', '-{{lookback_days}} days')

    What a hit looks like. Any execution of the reported hashes indicates a confirmed compromise. Silence indicates this specific payload version is not present.

  4. Assess Initial Compromise

    Agent triage

    Evaluate if the scoping hits and early execution signs point to a successful breach.

  5. Unauthorized RMM usage

    Query · baseline

    Find RMM tools executed on hosts identified as likely breached, stack-counting to find rare instances.

    reads hb_process_activitysql
    SELECT device_hostname, LOWER(process_name) as p_name, COUNT(DISTINCT device_hostname) as host_count, MIN(time) as first_seen FROM hb_process_activity WHERE (instr(',' || '{{rmm_software}}' || ',', ',' || LOWER(process_name) || ',') > 0 OR instr(',' || '{{rmm_software}}' || ',', ',' || LOWER(process_original_file_name) || ',') > 0) AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY p_name HAVING host_count < 5

    What a hit looks like. RMM tool execution that is rare across the fleet, potentially indicating attacker persistence.

  6. Ransomware impact signs

    Query · enrichment

    Identify mass file modification activity on a single host within a narrow time window, typical of ransomware encryption.

    reads hb_file_activitysql
    SELECT device_hostname, process_name, COUNT(*) as file_mod_count, MIN(time) as start_time, MAX(time) as end_time FROM hb_file_activity WHERE activity_id IN (1, 3, 5) AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY device_hostname, process_name HAVING file_mod_count > 500 ORDER BY file_mod_count DESC

    What a hit looks like. A specific process modifying hundreds or thousands of files in a short burst.

  7. Assess Full Chain Impact

    Agent triage

    Synthesize the early compromise signs with the follow-on RMM and encryption activity to confirm the ransomware operation.

  8. Route on verdict

    Decision

    Initiate response if the full-chain assessment confirms malicious activity.

  9. Contain affected hosts

    Response action

    Prevent further lateral movement and data destruction by isolating confirmed compromised endpoints.

  10. Manual analyst triage

    Analyst task

    Final review of the evidence by a human analyst to confirm the agent's findings and identify tuning opportunities.

  11. Close out hunt report

    Analyst task

    Document findings and gaps.

Coverage

Scenario coverage

StageCoveredHow, or why not
Exploitation of Public-Facing Applications
T1190
Yes scoping-vulnerable-gateways, suspicious-http-patterns
Malware and Backdoor Execution
T1203
Yes backdoor-process-hashes
Remote Monitoring and Management Abuse Yes unauthorized-rmm-usage
Data Encrypted for Impact
T1486
Yes ransomware-impact-signs

Blind spots

  • Needs Direct telemetry from OT network devices. A negative result on the IT endpoints does not guarantee the OT network is safe if it lacks agent coverage. It would answer whether ransomware has successfully encrypted files on the OT segment. Remediation: Integrate OT network flow logs or specialized OT monitoring agents.
  • Needs TLS decryption/inspection at the gateway. Attackers can hide exploit payloads inside encrypted traffic, leaving the hunter to rely only on meta-signals like request frequency or volume. It would answer what specific payloads or exploits were sent to the NetScaler. Remediation: Enable SSL/TLS inspection for inbound traffic to public-facing gateways.

Parameters & data

Parameters

ParameterTypeDefaultWhat it is
backdoor_hasheslist[hash]9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507, 96fa6a7714670823c83099ea01d24d6d3ae8fef027f01a4ddac14f123b1c9974, 90b1456cdbe6bc2779ea0b4736ed9a998a71ae37390331b6ba87e389a49d3d59, 540080fea97d88ed902c5e4f9a026b4fcd32ab263706c520e00728f1a29578b8, 9896a6fcb9bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7fSHA256 hashes of the Antino backdoor and other malware from the report.
lookback_daysnumber14Days of history to examine.
rmm_softwarelist[string]teamviewer, anydesk, screenconnect, rustdesk, logmein, atera, splashtopNames of common RMM tools to monitor for unauthorized usage.
scope_hostslist[host]—Optional list of hostnames to focus the behavioral queries.

Telemetry

SourceCategoryTelemetry
Endpoint telemetry (hb_ surfaces)endpointendpoint
Web server / proxy logssiemnetwork

Source

Download hunt.md Definition (JSON) An open hunt.md file; it runs anywhere that reads the format.
---
analysis: A simple rule for a hash will miss the attacker if they rotate payloads;
  a rule for RMM tools will produce too many false positives. This hunt pivots from
  a vulnerability scope to rare behavioral baselines (RMM prevalence) and cross-correlates
  them with file impact metrics to find the full intrusion chain.
blind_spots:
- id: limited-ot-visibility
  owner: Network Engineering
  question: whether ransomware has successfully encrypted files on the OT segment
  remediation: Integrate OT network flow logs or specialized OT monitoring agents.
  requires: Direct telemetry from OT network devices
  risk: A negative result on the IT endpoints does not guarantee the OT network is
    safe if it lacks agent coverage.
  stage: ransomware-impact
- id: http-encryption
  owner: Security Architecture
  question: what specific payloads or exploits were sent to the NetScaler
  remediation: Enable SSL/TLS inspection for inbound traffic to public-facing gateways.
  requires: TLS decryption/inspection at the gateway
  risk: Attackers can hide exploit payloads inside encrypted traffic, leaving the
    hunter to rely only on meta-signals like request frequency or volume.
  stage: initial-access-exploit
coverage:
- stage: initial-access-exploit
  status: covered
  steps:
  - scoping-vulnerable-gateways
  - suspicious-http-patterns
- stage: backdoor-execution
  status: covered
  steps:
  - backdoor-process-hashes
- stage: remote-access-abuse
  status: covered
  steps:
  - unauthorized-rmm-usage
- stage: ransomware-impact
  status: covered
  steps:
  - ransomware-impact-signs
guardrails:
  claims: no_unsupported
  evidence: citation_required
  missing_data: not_benign
  telemetry: untrusted
hunt:
  applicability: campaign-specific
  handoff: keep-as-periodic-hunt
  justification: The exploitation of zero-day vulnerabilities in remote access gateways
    like Citrix NetScaler is a critical risk that leads directly to high-impact ransomware.
    A hunt is necessary to find post-exploit evidence that standing rules might miss
    due to the 'dual-use' nature of RMM tools.
  methodology: model-assisted
  trigger: intel-report
hypothesis: An attacker has exploited vulnerabilities in a public-facing gateway or
  remote access tool to execute a backdoor, followed by establishing persistence via
  unauthorized RMM software and initiating ransomware file encryption.
labels:
- hunt
- attack.t1190
- attack.t1203
- attack.t1486
- command and control
- execution
- impact
- initial access
name: NetScaler exploitation and RMM-driven ransomware
parameters:
  backdoor_hashes:
    default:
    - 9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507
    - 96fa6a7714670823c83099ea01d24d6d3ae8fef027f01a4ddac14f123b1c9974
    - 90b1456cdbe6bc2779ea0b4736ed9a998a71ae37390331b6ba87e389a49d3d59
    - 540080fea97d88ed902c5e4f9a026b4fcd32ab263706c520e00728f1a29578b8
    - 9896a6fcb9bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7f
    description: SHA256 hashes of the Antino backdoor and other malware from the report.
    from:
      kind: article
      observed: '2026-10-01'
      ref: https://blog.talosintelligence.com/give-yourself-room-to-be-human/
    type: list[hash]
  lookback_days:
    default: '14'
    description: Days of history to examine.
    type: number
  rmm_software:
    default:
    - teamviewer
    - anydesk
    - screenconnect
    - rustdesk
    - logmein
    - atera
    - splashtop
    description: Names of common RMM tools to monitor for unauthorized usage.
    type: list[string]
  scope_hosts:
    default: []
    description: Optional list of hostnames to focus the behavioral queries.
    type: list[host]
provenance:
  authors:
  - name: Huntbase hunt generation
    org: huntbase.io
  generated:
    by: huntbase-hunt-generation
    from: https://blog.talosintelligence.com/give-yourself-room-to-be-human/
    gates:
    - dry-run
    - lint
    - critic
    model: hb_google/gemini-3-flash-preview
rationale: Start with public-facing segments containing Citrix NetScaler or TeamViewer
  installations. Prioritize hosts with high-severity vulnerabilities first.
references:
- name: "Talos \u2014 Give yourself room to be human"
  url: https://blog.talosintelligence.com/give-yourself-room-to-be-human/
related:
- hunt: unauthorized-rmm-persistence
  reason: This hunt focuses on the specific ransomware chain; a broader RMM hunt would
    cover more diverse persistence scenarios.
  relation: out-of-scope-alternative
scenario:
  stages:
  - name: Exploitation of Public-Facing Applications
    observables:
    - Citrix NetScaler ADC
    - Citrix NetScaler Gateway
    - NetScaler zero-day vulnerabilities
    - Automated AI agent exploitation
    - Exposed file-sharing servers
    slug: initial-access-exploit
    tactic: initial-access
    techniques:
    - T1190
  - name: Malware and Backdoor Execution
    observables:
    - Antino backdoor
    - W32.Injector
    - sample.exe
    - tmp00055df5.dll
    - f_006048.exe
    - SECOH-QAD.exe
    - 9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507
    - 96fa6a7714670823c83099ea01d24d6d3ae8fef027f01a4ddac14f123b1c9974
    - 90b1456cdbe6bc2779ea0b4736ed9a998a71ae37390331b6ba87e389a49d3d59
    - 540080fea97d88ed902c5e4f9a026b4fcd32ab263706c520e00728f1a29578b8
    - 9896a6fcb9bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7f
    - w32.9f1f11a708-100.sbx.tg
    - w32.injector
    - w32.540080fea9-95.sbx.tg
    - w32.9896a6fcb9-95.sbx.tg
    slug: backdoor-execution
    tactic: execution
    techniques:
    - T1203
  - name: Remote Monitoring and Management Abuse
    observables:
    - TeamViewer high-severity flaws
    - Unauthorized RMM tool use
    - Dual-use RMM abuse
    slug: remote-access-abuse
    tactic: command-and-control
  - name: Data Encrypted for Impact
    observables:
    - Ransomware-linked malware
    - OT network data encryption
    slug: ransomware-impact
    tactic: impact
    techniques:
    - T1486
  summary: Threat actors exploit critical vulnerabilities in public-facing infrastructure
    like Citrix NetScaler or through automated AI agents to gain initial access, subsequently
    deploying backdoors like Antino and abusing remote management tools like TeamViewer.
    This activity ultimately leads to data breaches on file-sharing servers and the
    deployment of ransomware in critical infrastructure OT networks for data encryption.
severity: critical
targets:
  analyst:
    name: Tier-2 analyst
    role: analyst
  endpoint:
    category: endpoint
    name: Endpoint telemetry (hb_ surfaces)
    telemetry:
    - endpoint
  hunter:
    agent: true
    name: Hunt agent
  web:
    category: siem
    name: Web server / proxy logs
    telemetry:
    - network
tlp: clear
type: investigation
---


# NetScaler exploitation and RMM-driven ransomware

This hunt follows the complete attack chain reported by Talos, focusing on the exploitation of Citrix NetScaler and TeamViewer. It begins by identifying vulnerable assets, then moves to detect early-stage backdoor execution via known hashes. Finally, it looks for the aftermath: unauthorized remote management tools and the high-volume file modifications characteristic of ransomware impact.

## scoping-vulnerable-gateways
<!-- Scope vulnerable gateway and access software -->
Identify hosts running software with known high-severity vulnerabilities mentioned in the report (NetScaler, TeamViewer).

```sqlite target=endpoint role=scoping
~~~yaml
expected: Hosts running vulnerable versions of Citrix NetScaler or TeamViewer. Zero
  results means no known vulnerable versions are reporting, but unmanaged assets may
  remain.
reads:
- affected_package_name
- affected_package_version
- cve_uid
- cvss_score
- device_uid
- severity_id
silence: not_evidence_of_absence
source: hb_vulnerability_finding
verified: dry-run
verified_at: '2026-10-02'
~~~
SELECT device_uid, cve_uid, affected_package_name, affected_package_version, cvss_score FROM hb_vulnerability_finding WHERE (LOWER(affected_package_name) LIKE '%netscaler%' OR LOWER(affected_package_name) LIKE '%teamviewer%') AND severity_id >= 4
```

## early-stage-p
<!-- Parallel: Access and Execution Evidence -->
parallel:
- → suspicious-http-patterns
- → backdoor-process-hashes
join: → assess-initial-compromise

## suspicious-http-patterns
<!-- Suspicious HTTP patterns to gateways -->
Find anomalous HTTP requests to gateway servers that might indicate exploitation attempts, such as high-frequency requests or rare user agents.

```sqlite target=web role=enrichment params=(lookback_days=lookback_days, scope_hosts=scope_hosts)
~~~yaml
expected: High-frequency requests to specific paths which might correspond to the
  AI-driven 'loud' attack mentioned in the article.
reads:
- device_hostname
- src_endpoint_ip
- time
- url_path
- user_agent
silence: not_evidence_of_absence
source: hb_http_activity
verified: dry-run
verified_at: '2026-10-02'
~~~
SELECT device_hostname, src_endpoint_ip, url_path, user_agent, COUNT(*) as request_count FROM hb_http_activity WHERE ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY device_hostname, src_endpoint_ip, url_path, user_agent HAVING request_count > 100 ORDER BY request_count DESC
```

## backdoor-process-hashes
<!-- Antino backdoor process activity -->
Directly search for the execution of malware reported by Talos using SHA256 hashes.

```sqlite target=endpoint role=detection-candidate params=(lookback_days=lookback_days, backdoor_hashes=backdoor_hashes)
~~~yaml
expected: Any execution of the reported hashes indicates a confirmed compromise. Silence
  indicates this specific payload version is not present.
reads:
- device_hostname
- process_cmd_line
- process_hash_sha256
- process_name
- time
- user_name
silence: evidence_of_absence
source: hb_process_activity
verified: dry-run
verified_at: '2026-10-02'
~~~
SELECT device_hostname, process_name, process_cmd_line, process_hash_sha256, user_name, time FROM hb_process_activity WHERE instr(',' || '{{backdoor_hashes}}' || ',', ',' || LOWER(process_hash_sha256) || ',') > 0 AND time >= datetime('now', '-{{lookback_days}} days')
```

## assess-initial-compromise
<!-- Assess Initial Compromise -->
```agent target=hunter
cite: required
context:
- scoping-vulnerable-gateways
- suspicious-http-patterns
- backdoor-process-hashes
max_iterations: 3
objective: Determine if any host identified in the scoping query shows signs of exploitation
  (HTTP anomalies) or execution of the Antino backdoor.
success_criteria: A verdict per host indicating breach status with citations of suspicious
  activity.
tools:
- endpoint
- web
```

## follow-on-p
<!-- Parallel: Persistence and Ransomware Impact -->
parallel:
- → unauthorized-rmm-usage
- → ransomware-impact-signs
join: → assess-full-chain

## unauthorized-rmm-usage
<!-- Unauthorized RMM usage -->
Find RMM tools executed on hosts identified as likely breached, stack-counting to find rare instances.

```sqlite target=endpoint role=baseline params=(lookback_days=lookback_days, rmm_software=rmm_software, scope_hosts=scope_hosts)
~~~yaml
baseline:
  compare: first_seen
  window: '{{lookback_days}}d'
expected: RMM tool execution that is rare across the fleet, potentially indicating
  attacker persistence.
prevalence:
  by: device_hostname
  key:
  - process_name
  rare_below: 5
reads:
- device_hostname
- process_name
- process_original_file_name
- time
silence: not_evidence_of_absence
source: hb_process_activity
verified: dry-run
verified_at: '2026-10-02'
~~~
SELECT device_hostname, LOWER(process_name) as p_name, COUNT(DISTINCT device_hostname) as host_count, MIN(time) as first_seen FROM hb_process_activity WHERE (instr(',' || '{{rmm_software}}' || ',', ',' || LOWER(process_name) || ',') > 0 OR instr(',' || '{{rmm_software}}' || ',', ',' || LOWER(process_original_file_name) || ',') > 0) AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY p_name HAVING host_count < 5
```

## ransomware-impact-signs
<!-- Ransomware impact signs -->
Identify mass file modification activity on a single host within a narrow time window, typical of ransomware encryption.

```sqlite target=endpoint role=enrichment params=(lookback_days=lookback_days, scope_hosts=scope_hosts)
~~~yaml
expected: A specific process modifying hundreds or thousands of files in a short burst.
reads:
- activity_id
- device_hostname
- process_name
- time
silence: not_evidence_of_absence
source: hb_file_activity
verified: dry-run
verified_at: '2026-10-02'
~~~
SELECT device_hostname, process_name, COUNT(*) as file_mod_count, MIN(time) as start_time, MAX(time) as end_time FROM hb_file_activity WHERE activity_id IN (1, 3, 5) AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY device_hostname, process_name HAVING file_mod_count > 500 ORDER BY file_mod_count DESC
```

## assess-full-chain
<!-- Assess Full Chain Impact -->
```agent target=hunter
cite: required
context:
- assess-initial-compromise
- unauthorized-rmm-usage
- ransomware-impact-signs
max_iterations: 4
objective: Combine the evidence of breach from the first agent with the observations
  of RMM tools and file encryption spikes. Determine if a ransomware incident is active.
success_criteria: A final verdict citing the progression from vulnerability to impact
  per host.
tools:
- endpoint
- web
```

## route-on-verdict
<!-- Route on verdict -->
if~: "the assessment confirms both initial compromise and follow-on ransomware-linked behavior" (confidence: high, judge=hunter)
then: → contain-threat
indeterminate: → manual-review
unavailable: → manual-review (blind_spot: limited-ot-visibility)
else: → manual-review

## contain-threat
<!-- Contain affected hosts -->
```action target=endpoint
~~~yaml
approval: required
~~~
Isolate the host, terminate the malicious process identified in the file activity step, and revoke any sessions associated with the host's users.
```
→ manual-review

## manual-review
<!-- Manual analyst triage -->
```manual target=analyst
Review the cited rows in the follow-on assessment. Confirm if the RMM usage was authorized and if the file modifications were indeed malicious encryption or benign high-volume tasks like indexing or updates.
```
→ close-out-report

## close-out-report
<!-- Close out hunt report -->
```manual target=analyst
Record the number of hosts examined, the number of confirmed compromises, and the coverage of the NetScaler/TeamViewer assets. Note any OT segments that were unreachable.
```
→ end

Run it

Take this hunt into your environment.

Open it in Huntbase to run every step against your own connections, with Scout weighing the evidence and your analysts in command. Or take the open hunt.md file anywhere that reads the format.

Machine-drafted by huntbase-hunt-generation using hb_google/gemini-3-flash-preview, gated by dry-run, lint, critic, then reviewed by a person.