---
analysis: A simple rule for a hash will miss the attacker if they rotate payloads;
  a rule for RMM tools will produce too many false positives. This hunt pivots from
  a vulnerability scope to rare behavioral baselines (RMM prevalence) and cross-correlates
  them with file impact metrics to find the full intrusion chain.
blind_spots:
- id: limited-ot-visibility
  owner: Network Engineering
  question: whether ransomware has successfully encrypted files on the OT segment
  remediation: Integrate OT network flow logs or specialized OT monitoring agents.
  requires: Direct telemetry from OT network devices
  risk: A negative result on the IT endpoints does not guarantee the OT network is
    safe if it lacks agent coverage.
  stage: ransomware-impact
- id: http-encryption
  owner: Security Architecture
  question: what specific payloads or exploits were sent to the NetScaler
  remediation: Enable SSL/TLS inspection for inbound traffic to public-facing gateways.
  requires: TLS decryption/inspection at the gateway
  risk: Attackers can hide exploit payloads inside encrypted traffic, leaving the
    hunter to rely only on meta-signals like request frequency or volume.
  stage: initial-access-exploit
coverage:
- stage: initial-access-exploit
  status: covered
  steps:
  - scoping-vulnerable-gateways
  - suspicious-http-patterns
- stage: backdoor-execution
  status: covered
  steps:
  - backdoor-process-hashes
- stage: remote-access-abuse
  status: covered
  steps:
  - unauthorized-rmm-usage
- stage: ransomware-impact
  status: covered
  steps:
  - ransomware-impact-signs
guardrails:
  claims: no_unsupported
  evidence: citation_required
  missing_data: not_benign
  telemetry: untrusted
hunt:
  applicability: campaign-specific
  handoff: keep-as-periodic-hunt
  justification: The exploitation of zero-day vulnerabilities in remote access gateways
    like Citrix NetScaler is a critical risk that leads directly to high-impact ransomware.
    A hunt is necessary to find post-exploit evidence that standing rules might miss
    due to the 'dual-use' nature of RMM tools.
  methodology: model-assisted
  trigger: intel-report
hypothesis: An attacker has exploited vulnerabilities in a public-facing gateway or
  remote access tool to execute a backdoor, followed by establishing persistence via
  unauthorized RMM software and initiating ransomware file encryption.
labels:
- hunt
- attack.t1190
- attack.t1203
- attack.t1486
- command and control
- execution
- impact
- initial access
name: NetScaler exploitation and RMM-driven ransomware
parameters:
  backdoor_hashes:
    default:
    - 9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507
    - 96fa6a7714670823c83099ea01d24d6d3ae8fef027f01a4ddac14f123b1c9974
    - 90b1456cdbe6bc2779ea0b4736ed9a998a71ae37390331b6ba87e389a49d3d59
    - 540080fea97d88ed902c5e4f9a026b4fcd32ab263706c520e00728f1a29578b8
    - 9896a6fcb9bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7f
    description: SHA256 hashes of the Antino backdoor and other malware from the report.
    from:
      kind: article
      observed: '2026-10-01'
      ref: https://blog.talosintelligence.com/give-yourself-room-to-be-human/
    type: list[hash]
  lookback_days:
    default: '14'
    description: Days of history to examine.
    type: number
  rmm_software:
    default:
    - teamviewer
    - anydesk
    - screenconnect
    - rustdesk
    - logmein
    - atera
    - splashtop
    description: Names of common RMM tools to monitor for unauthorized usage.
    type: list[string]
  scope_hosts:
    default: []
    description: Optional list of hostnames to focus the behavioral queries.
    type: list[host]
provenance:
  authors:
  - name: Huntbase hunt generation
    org: huntbase.io
  generated:
    by: huntbase-hunt-generation
    from: https://blog.talosintelligence.com/give-yourself-room-to-be-human/
    gates:
    - dry-run
    - lint
    - critic
    model: hb_google/gemini-3-flash-preview
rationale: Start with public-facing segments containing Citrix NetScaler or TeamViewer
  installations. Prioritize hosts with high-severity vulnerabilities first.
references:
- name: "Talos \u2014 Give yourself room to be human"
  url: https://blog.talosintelligence.com/give-yourself-room-to-be-human/
related:
- hunt: unauthorized-rmm-persistence
  reason: This hunt focuses on the specific ransomware chain; a broader RMM hunt would
    cover more diverse persistence scenarios.
  relation: out-of-scope-alternative
scenario:
  stages:
  - name: Exploitation of Public-Facing Applications
    observables:
    - Citrix NetScaler ADC
    - Citrix NetScaler Gateway
    - NetScaler zero-day vulnerabilities
    - Automated AI agent exploitation
    - Exposed file-sharing servers
    slug: initial-access-exploit
    tactic: initial-access
    techniques:
    - T1190
  - name: Malware and Backdoor Execution
    observables:
    - Antino backdoor
    - W32.Injector
    - sample.exe
    - tmp00055df5.dll
    - f_006048.exe
    - SECOH-QAD.exe
    - 9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507
    - 96fa6a7714670823c83099ea01d24d6d3ae8fef027f01a4ddac14f123b1c9974
    - 90b1456cdbe6bc2779ea0b4736ed9a998a71ae37390331b6ba87e389a49d3d59
    - 540080fea97d88ed902c5e4f9a026b4fcd32ab263706c520e00728f1a29578b8
    - 9896a6fcb9bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7f
    - w32.9f1f11a708-100.sbx.tg
    - w32.injector
    - w32.540080fea9-95.sbx.tg
    - w32.9896a6fcb9-95.sbx.tg
    slug: backdoor-execution
    tactic: execution
    techniques:
    - T1203
  - name: Remote Monitoring and Management Abuse
    observables:
    - TeamViewer high-severity flaws
    - Unauthorized RMM tool use
    - Dual-use RMM abuse
    slug: remote-access-abuse
    tactic: command-and-control
  - name: Data Encrypted for Impact
    observables:
    - Ransomware-linked malware
    - OT network data encryption
    slug: ransomware-impact
    tactic: impact
    techniques:
    - T1486
  summary: Threat actors exploit critical vulnerabilities in public-facing infrastructure
    like Citrix NetScaler or through automated AI agents to gain initial access, subsequently
    deploying backdoors like Antino and abusing remote management tools like TeamViewer.
    This activity ultimately leads to data breaches on file-sharing servers and the
    deployment of ransomware in critical infrastructure OT networks for data encryption.
severity: critical
targets:
  analyst:
    name: Tier-2 analyst
    role: analyst
  endpoint:
    category: endpoint
    name: Endpoint telemetry (hb_ surfaces)
    telemetry:
    - endpoint
  hunter:
    agent: true
    name: Hunt agent
  web:
    category: siem
    name: Web server / proxy logs
    telemetry:
    - network
tlp: clear
type: investigation
---


# NetScaler exploitation and RMM-driven ransomware

This hunt follows the complete attack chain reported by Talos, focusing on the exploitation of Citrix NetScaler and TeamViewer. It begins by identifying vulnerable assets, then moves to detect early-stage backdoor execution via known hashes. Finally, it looks for the aftermath: unauthorized remote management tools and the high-volume file modifications characteristic of ransomware impact.

## scoping-vulnerable-gateways
<!-- Scope vulnerable gateway and access software -->
Identify hosts running software with known high-severity vulnerabilities mentioned in the report (NetScaler, TeamViewer).

```sqlite target=endpoint role=scoping
~~~yaml
expected: Hosts running vulnerable versions of Citrix NetScaler or TeamViewer. Zero
  results means no known vulnerable versions are reporting, but unmanaged assets may
  remain.
reads:
- affected_package_name
- affected_package_version
- cve_uid
- cvss_score
- device_uid
- severity_id
silence: not_evidence_of_absence
source: hb_vulnerability_finding
verified: dry-run
verified_at: '2026-10-02'
~~~
SELECT device_uid, cve_uid, affected_package_name, affected_package_version, cvss_score FROM hb_vulnerability_finding WHERE (LOWER(affected_package_name) LIKE '%netscaler%' OR LOWER(affected_package_name) LIKE '%teamviewer%') AND severity_id >= 4
```

## early-stage-p
<!-- Parallel: Access and Execution Evidence -->
parallel:
- → suspicious-http-patterns
- → backdoor-process-hashes
join: → assess-initial-compromise

## suspicious-http-patterns
<!-- Suspicious HTTP patterns to gateways -->
Find anomalous HTTP requests to gateway servers that might indicate exploitation attempts, such as high-frequency requests or rare user agents.

```sqlite target=web role=enrichment params=(lookback_days=lookback_days, scope_hosts=scope_hosts)
~~~yaml
expected: High-frequency requests to specific paths which might correspond to the
  AI-driven 'loud' attack mentioned in the article.
reads:
- device_hostname
- src_endpoint_ip
- time
- url_path
- user_agent
silence: not_evidence_of_absence
source: hb_http_activity
verified: dry-run
verified_at: '2026-10-02'
~~~
SELECT device_hostname, src_endpoint_ip, url_path, user_agent, COUNT(*) as request_count FROM hb_http_activity WHERE ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY device_hostname, src_endpoint_ip, url_path, user_agent HAVING request_count > 100 ORDER BY request_count DESC
```

## backdoor-process-hashes
<!-- Antino backdoor process activity -->
Directly search for the execution of malware reported by Talos using SHA256 hashes.

```sqlite target=endpoint role=detection-candidate params=(lookback_days=lookback_days, backdoor_hashes=backdoor_hashes)
~~~yaml
expected: Any execution of the reported hashes indicates a confirmed compromise. Silence
  indicates this specific payload version is not present.
reads:
- device_hostname
- process_cmd_line
- process_hash_sha256
- process_name
- time
- user_name
silence: evidence_of_absence
source: hb_process_activity
verified: dry-run
verified_at: '2026-10-02'
~~~
SELECT device_hostname, process_name, process_cmd_line, process_hash_sha256, user_name, time FROM hb_process_activity WHERE instr(',' || '{{backdoor_hashes}}' || ',', ',' || LOWER(process_hash_sha256) || ',') > 0 AND time >= datetime('now', '-{{lookback_days}} days')
```

## assess-initial-compromise
<!-- Assess Initial Compromise -->
```agent target=hunter
cite: required
context:
- scoping-vulnerable-gateways
- suspicious-http-patterns
- backdoor-process-hashes
max_iterations: 3
objective: Determine if any host identified in the scoping query shows signs of exploitation
  (HTTP anomalies) or execution of the Antino backdoor.
success_criteria: A verdict per host indicating breach status with citations of suspicious
  activity.
tools:
- endpoint
- web
```

## follow-on-p
<!-- Parallel: Persistence and Ransomware Impact -->
parallel:
- → unauthorized-rmm-usage
- → ransomware-impact-signs
join: → assess-full-chain

## unauthorized-rmm-usage
<!-- Unauthorized RMM usage -->
Find RMM tools executed on hosts identified as likely breached, stack-counting to find rare instances.

```sqlite target=endpoint role=baseline params=(lookback_days=lookback_days, rmm_software=rmm_software, scope_hosts=scope_hosts)
~~~yaml
baseline:
  compare: first_seen
  window: '{{lookback_days}}d'
expected: RMM tool execution that is rare across the fleet, potentially indicating
  attacker persistence.
prevalence:
  by: device_hostname
  key:
  - process_name
  rare_below: 5
reads:
- device_hostname
- process_name
- process_original_file_name
- time
silence: not_evidence_of_absence
source: hb_process_activity
verified: dry-run
verified_at: '2026-10-02'
~~~
SELECT device_hostname, LOWER(process_name) as p_name, COUNT(DISTINCT device_hostname) as host_count, MIN(time) as first_seen FROM hb_process_activity WHERE (instr(',' || '{{rmm_software}}' || ',', ',' || LOWER(process_name) || ',') > 0 OR instr(',' || '{{rmm_software}}' || ',', ',' || LOWER(process_original_file_name) || ',') > 0) AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY p_name HAVING host_count < 5
```

## ransomware-impact-signs
<!-- Ransomware impact signs -->
Identify mass file modification activity on a single host within a narrow time window, typical of ransomware encryption.

```sqlite target=endpoint role=enrichment params=(lookback_days=lookback_days, scope_hosts=scope_hosts)
~~~yaml
expected: A specific process modifying hundreds or thousands of files in a short burst.
reads:
- activity_id
- device_hostname
- process_name
- time
silence: not_evidence_of_absence
source: hb_file_activity
verified: dry-run
verified_at: '2026-10-02'
~~~
SELECT device_hostname, process_name, COUNT(*) as file_mod_count, MIN(time) as start_time, MAX(time) as end_time FROM hb_file_activity WHERE activity_id IN (1, 3, 5) AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY device_hostname, process_name HAVING file_mod_count > 500 ORDER BY file_mod_count DESC
```

## assess-full-chain
<!-- Assess Full Chain Impact -->
```agent target=hunter
cite: required
context:
- assess-initial-compromise
- unauthorized-rmm-usage
- ransomware-impact-signs
max_iterations: 4
objective: Combine the evidence of breach from the first agent with the observations
  of RMM tools and file encryption spikes. Determine if a ransomware incident is active.
success_criteria: A final verdict citing the progression from vulnerability to impact
  per host.
tools:
- endpoint
- web
```

## route-on-verdict
<!-- Route on verdict -->
if~: "the assessment confirms both initial compromise and follow-on ransomware-linked behavior" (confidence: high, judge=hunter)
then: → contain-threat
indeterminate: → manual-review
unavailable: → manual-review (blind_spot: limited-ot-visibility)
else: → manual-review

## contain-threat
<!-- Contain affected hosts -->
```action target=endpoint
~~~yaml
approval: required
~~~
Isolate the host, terminate the malicious process identified in the file activity step, and revoke any sessions associated with the host's users.
```
→ manual-review

## manual-review
<!-- Manual analyst triage -->
```manual target=analyst
Review the cited rows in the follow-on assessment. Confirm if the RMM usage was authorized and if the file modifications were indeed malicious encryption or benign high-volume tasks like indexing or updates.
```
→ close-out-report

## close-out-report
<!-- Close out hunt report -->
```manual target=analyst
Record the number of hosts examined, the number of confirmed compromises, and the coverage of the NetScaler/TeamViewer assets. Note any OT segments that were unreachable.
```
→ end
