Hackers are conducting an extensive campaign to exploit the recent CVE-2023-3519 vulnerability in Citrix NetScaler gateways and steal user credentials.
See also: Is the FIN8 hacking group attacking Citrix NetScaler systems?

The vulnerability is a critical unauthenticated remote code execution (RCE) flaw, discovered as a zero-day in July, affecting Citrix NetScaler ADC and NetScaler Gateway. By early August, the vulnerability had been exploited to add a backdoor to at least 640 Citrix servers, with the number reaching 2,000 by mid-August.
According to IBM's X-Force reports, despite multiple warnings to update Citrix devices, hackers began exploiting CVE-2023-3519 in September to inject JavaScript that collects login credentials.
Citrix NetScaler is one of the most trusted and powerful application delivery controllers (ADC) widely used in information technology. Citrix Systems, the company behind NetScaler, is committed to delivering technologies that connect and secure applications and data across any network or cloud.
X-Force first discovered Netscaler's credential theft campaign while investigating a case where a customer was experiencing slow authentication on device .
Based on their investigations, responders determined that hackers committed a breach using CVE-2023-3519 to inject a malicious JavaScript script that steals credentials into the index.html of a Citrix NetScaler appliance.
The attack starts with a web request that exploits vulnerable NetScaler devices to write a simple PHP web shell to “ /netscaler/ns_gui/vpn” . This web shell gives the attackers direct real-time access to the compromised terminal, which they exploit to collect configuration data from the “ ns.conf ” file. The attackers then add custom HTML code to the “index.html” file that references a remote JavaScript file, which retrieves and executes additional JS code. The last JS code snippet is designed to collect credentials, by attaching a custom function to the “ Connect ” button on the VPN authentication page . Finally, the collected information is sent to the attackers via an HTTP POST request.
See also: CISA: Warns about the critical flaw in Citrix ShareFile

The attackers registered several domains for this campaign, including jscloud[.]ink, jscloud[.]live, jscloud[.]biz, jscdn[.]biz, and cloudjs[.]live. X-Force identified nearly 600 unique IP addresses for NetScaler appliances, which had been modified on login pages to facilitate credential theft.
Most victims are located in the United States and Europe, but compromised systems are located all over the world.
Regarding the duration of the campaign, according to the X-Force report, the first modification of the login page was made on August 11, 2023, so the campaign has been ongoing for two months.
IBM analysts were unable to attribute this activity to any threat group, but they recovered a new object from the attack that may help experts detect it early.
The finding can be found in the NetScaler application crash files related to the NetScaler Packet Processing Engine (NSPPE), which are located in “/var/core/".
Application crash files are stored in “.gz” files that require decompression before analysis, while the string data content also needs to be converted to a readable format using PowerShell or other tools. administrators to follow the remediation and detection guidelines provided by CISA here.
See also: Over 640 Citrix servers compromised with web shells in ongoing attacks
Users can defend against credential theft on Citrix NetScaler in several ways, primarily by exercising precise control over the login pages they use.
Protecting your account:
- Check the URL: Always double-check the URL before entering your account information. Hackers often use slightly modified URLs to mislead users.
- Software updates: The latest versions of software often include security fixes that address known vulnerabilities. It is vital to update regularly.
How do we monitor this threat?
Information security experts are constantly monitoring such threats. Although this attack is particularly cunning – it uses the same login pages that users consider trustworthy – security professionals can often spot the signs of an insidious attack. Although this attack is new, knowing the attackers’ methods, combined with constantly updating protective measures, can ensure users’ safety.
Source: bleepingcomputer
