Threat hunts for Citrix
4 hunts covering Citrix, each with a hypothesis, the queries that test it and what the hunt cannot see.
4 hunts
-
criticalResearch by Cisco Talos
NetScaler exploitation and RMM-driven ransomware
An attacker has exploited vulnerabilities in a public-facing gateway or remote access tool to execute a backdoor, followed by establishing persistence via unauthorized RMM software and initiating ransomware file encryption.
5 query2 analytic1 checkpoint1 action2 taskcommand and control · execution · impact -
highResearch by CISA
Citrix NetScaler Zero-Day Exposure
An attacker is exploiting zero-day remote code execution vulnerabilities in Citrix NetScaler appliances, characterized by anomalous HTTP requests to management interfaces followed by the execution of unauthorized shell commands.
3 query1 analytic1 checkpoint2 taskCVE-2026-88771 · CVE-2026-88772 -
highResearch by Rapid7
Citrix NetScaler Authentication Bypass and Exposure
An unauthenticated attacker has exploited CVE-2026-19490 on an internet-facing NetScaler appliance to bypass authentication and gain unauthorized remote access.
3 query1 analytic1 checkpoint2 taskCVE-2026-19490 -
high Part 1 of 2Research by Mandiant
Interactive Remote Access and Support Tool Abuse
An intruder uses vishing to direct users to a self-destructing note service and installs unauthorized RMM tools to pivot into corporate VDI infrastructure.
3 query2 analytic2 checkpoint1 action2 taskcollection · execution · exfiltration