ZeroFox Intelligence Flash Report - Mass Access Brokering Event Impacting Corporate Citrix VPN Users
|by Alpha Team

ZeroFox Intelligence Flash Report - Mass Access Brokering Event Impacting Corporate Citrix VPN Users
Product Serial: F-2023-11-28a
TLP:CLEAR
In this flash report, ZeroFox researchers report on the announcement of the sale of at least 711 compromised Citrix Virtual Private Network instances with verified credentials on the Russian-speaking forum exploit[.]in.
Standing Intelligence Requirements
Deep Dark Web and Criminal Underground

For the most up-to-date list of ZeroFox’s Intelligence Requirements, please visit:
https://cloud.zerofox.com/intelligence/advisories/14956
Link to Download
View the full report here
Key Findings
- On November 26, 2023, highly regarded threat actor “Punktir” announced that they are selling at least 711 compromised Citrix Virtual Private Network instances with verified credentials on the Russian-speaking forum exploit[.]in.
- Targets included in the access sale are alleged to have a revenue of over USD 5 million and are all based in either Europe or the United States.
- Ransomware cartels—which frequently leverage exploit[.]in to purchase access from brokers—are very likely to deem the access sale affordable and to have a potentially high return on investment.
- The emergence of corporate access checkers on the deep and dark web has driven an increase in bulk access sales in 2023.
Tags: tlp:clear, threat actor, all industries, MAL Initial Access, DDW Ransomware