By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
CrytonicCrytonic
  • Home
  • Entertainment
  • Lifestyle
  • Automobile
  • Business
  • Technology
  • Health
Search
  • Advertise
© 2019-23 Crytonic. All Rights Reserved.
Reading: Security Alert: Citrix NetScaler Login Pages Hacked to Pilfer User Credentials
Share
Aa
CrytonicCrytonic
Aa
  • Entertainment
  • Lifestyle
  • Automobile
  • Business
  • Technology
  • Health
Search
  • Home
  • Categories
    • Entertainment
    • Lifestyle
    • Automobile
    • Business
    • Technology
    • Health
  • Bookmarks
  • More Crytonic
    • Sitemap
Follow US
  • Advertise
© 2020-23 Crytonic. All Rights Reserved.
Crytonic > Blog > Business > Security Alert: Citrix NetScaler Login Pages Hacked to Pilfer User Credentials
BusinessTechnology

Security Alert: Citrix NetScaler Login Pages Hacked to Pilfer User Credentials

Daniel Smith
Last updated: 2023/10/10 at 11:27 AM
Daniel Smith
Share
3 Min Read
SHARE

Cyber Attackers Exploit Citrix NetScaler Flaw to Steal User Credentials

A recent large-scale hacking campaign is taking advantage of a critical flaw in Citrix NetScaler Gateways, marked as CVE-2023-3519, to pilfer user credentials. This vulnerability, discovered as a zero-day in July, impacts Citrix NetScaler ADC and NetScaler Gateway, and has become a prime target for cybercriminals.

By early August, this flaw had already allowed unauthorized access to more than 640 Citrix servers, a number that had risen to 2,000 by mid-August. Despite warnings and advisories to update Citrix devices, the attack surface remains significant, and hackers began exploiting CVE-2023-3519 to insert JavaScript for credential harvesting in September.

The attackers behind this campaign have been quietly modifying the login pages of Citrix NetScaler devices to inject malicious credential-stealing JavaScript scripts. The attack unfolds with a web request targeting vulnerable NetScaler devices, allowing the hackers to create a web shell and gain direct access to the compromised endpoint. They then extract configuration data and append custom HTML code to the login page, which references a remote JavaScript file, subsequently collecting user credentials upon login.

This threat actor has registered several domains for their campaign, and the campaign has impacted nearly 600 unique IP addresses of NetScaler devices worldwide. While the majority of victims are located in the United States and Europe, compromised systems span the globe.

This campaign has been ongoing for two months, with an early modification of the login page detected on August 11, 2023. However, IBM X-Force, which uncovered this activity, was unable to attribute it to any known threat group or cluster. In response to this campaign, organizations are urged to apply patches and change default login credentials for their devices.

This revelation comes in conjunction with the discovery of an updated version of the IZ1H9 Mirai-based DDoS campaign, emphasizing the importance of promptly addressing vulnerabilities and adopting strong security practices. Organizations should remain vigilant and proactive in safeguarding their systems against cyber threats.

You Might Also Like

Crypto Aid Israel Surpasses Expectations, Raises $185K in 10 Days, and Empowers 4 Charitable Organizations

Global Hydrogen Train Market Soars: $3.45 Billion Forecast by 2030 in Exclusive Report

Tech Breakthrough: Tether Locks Down 32 Crypto Wallets with $873K, Suspected of Aiding Terrorism in Israel and Ukraine”

Unveiling the ‘Exclusome’: A New Guardian Mini-Organ Found in Cells

AI Revolution: Meet the Genius That Crafts Robots—On Its Own!

TAGGED: Citrix NetScaler, Login Pages Hacked, Security Alert, User Credentials

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
[mc4wp_form]
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Twitter Copy Link Print
Share
Previous Article NATO’s Willingness to Gas Pipeline Probe: Finnish President Niinistö Reveals
Next Article Google, Cloudflare, and AWS Expose Record-Breaking ‘HTTP/2 Rapid Reset’ DDoS Attack
Leave a comment Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Stay Connected

- Advertisement -

Latest News

7 Low Calorie High Protein Foods to Fuel Your Health
7 Low Calorie High Protein Foods to Fuel Your Health
Health October 23, 2023
25 Things You Must Know Before Becoming a Swinger
25 Things You Must Know Before Becoming a Swinger
Lifestyle October 21, 2023
Exploring the Thrilling World of Swinging: Dive into the Swinger Lifestyle
Exploring the Thrilling World of Swinging: Dive into the Swinger Lifestyle
Lifestyle October 21, 2023
Crypto Aid Israel Surpasses Expectations, Raises $185K in 10 Days, and Empowers 4 Charitable Organizations
Technology October 20, 2023
CrytonicCrytonic
Follow US
© 2019-23 Crytonic. All Rights Reserved.
  • Disclaimer
  • Privacy Policy
  • Terms And Conditions
  • Contact Us
Welcome Back!

Sign in to your account

Lost your password?