zerofox logo
Advisories

ZeroFox Intelligence Flash Report - Mass Access Brokering Event Impacting Corporate Citrix VPN Users

|by Alpha Team

banner image

ZeroFox Intelligence Flash Report - Mass Access Brokering Event Impacting Corporate Citrix VPN Users

Product Serial: F-2023-11-28a

TLP:CLEAR

In this flash report, ZeroFox researchers report on the announcement of the sale of at least 711 compromised Citrix Virtual Private Network instances with verified credentials on the Russian-speaking forum exploit[.]in.

Standing Intelligence Requirements

Deep Dark Web and Criminal Underground DDW

For the most up-to-date list of ZeroFox’s Intelligence Requirements, please visit:

https://cloud.zerofox.com/intelligence/advisories/14956

Link to Download

View the full report here

Key Findings

  • On November 26, 2023, highly regarded threat actor “Punktir” announced that they are selling at least 711 compromised Citrix Virtual Private Network instances with verified credentials on the Russian-speaking forum exploit[.]in.
  • Targets included in the access sale are alleged to have a revenue of over USD 5 million and are all based in either Europe or the United States.
  • Ransomware cartels—which frequently leverage exploit[.]in to purchase access from brokers—are very likely to deem the access sale affordable and to have a potentially high return on investment.
  • The emergence of corporate access checkers on the deep and dark web has driven an increase in bulk access sales in 2023.

Tags: tlp:clear,  threat actor,  all industries, MAL Initial Access, DDW Ransomware