ATT&CKReferencesNSA APT5 Citrix Threat Hunting December 2022

NSA APT5 Citrix Threat Hunting December 2022

National Security Agency. (2022, December). APT5: Citrix ADC Threat Hunting Guidance. Retrieved February 5, 2024.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples3

TechniqueUsed byProcedure example
T1053.003
Cron
GroupAPT5

APT5 has made modifications to the crontab file including in `/var/cron/tabs/`.

T1190
Exploit Public-Facing Application
GroupAPT5

APT5 has exploited vulnerabilities in externally facing software and devices including Pulse Secure VPNs and Citrix Application Delivery Controllers.

T1190
Exploit Public-Facing Application
CampaignSPACEHOP Activity

SPACEHOP Activity has enabled the exploitation of CVE-2022-27518 and CVE-2022-27518 for illegitimate access.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.