A significant increase in brute-force attacks is being observed on Citrix NetScaler appliances, targeting organizations worldwide.

The attacks primarily originate from a Hong Kong-based cloud provider and exploit outdated or misconfigured systems, while being related to recently disclosed vulnerabilities
See more: Cisco: Brute-force attacks target VPN services
Specifically, CVE-2024-8534 and CVE-2024-8535, which were discovered in November 2024, pose significant risks. CVE-2024-8534 is a memory vulnerability that can cause memory corruption and denial of service, while CVE-2024-8535 allows authenticated users access to unauthorized functions due to a race condition.
The hackers use a distributed brute-force strategy, frequently changing IP addresses and ASNs, making detection difficult. Ethan Fite of Cyderes confirmed the complexity of these attacks. Additionally, the German Federal Office for Information Security (BSI) has warned of increased attacks on NetScaler devices, especially on critical infrastructure and international partners.
Read also: Cisco patches vulnerability that allows Brute-Force
This table includes all IP addresses and IP ranges associated with recent brute-force attacks on Citrix NetScaler devices. To mitigate these threats, immediate measures are recommended:

- Blocking high-risk IPs, especially from providers based in Hong Kong.
- Updating NetScaler devices to the latest versions, addressing CVE-2024-8534 and CVE-2024-8535.
- Checking RDP settings or disabling it if not necessary.
- Geographic blocking for high-risk regions.
See also: Ransomware attacks exploit VMware ESXi vulnerabilities
Citrix published security updates, but versions 12.1 and 13.0 remain vulnerable. CISA warns of possible exploitation, emphasizing the need for immediate action to prevent breaches.
Source: cybersecuritynews
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
