Cyber Security

Tag-100 Hacker Group Exploiting Citrix NetScaler & F5 BIG-IP Vulnerabilities

A new threat actor, TAG-100, has emerged and is actively targeting government and private sector organizations worldwide and initiates its attacks by exploiting vulnerabilities in internet-facing devices, such as Citrix NetScaler and F5 BIG-IP, to gain initial access to victim networks.

It leverages open-source remote access tools to automate and streamline this initial compromise stage.

Once inside a target network, TAG-100 establishes persistence within the compromised system by deploying open-source Go backdoors like Pantegana and SparkRAT.

The persistence mechanism enables TAG-100 to maintain long-term access to the compromised system and conduct further exploitation activities, such as lateral movement, data exfiltration, or credential theft.

TAG-100’s attack chain is a prime example of a strategy that combines the utilization of easily accessible open-source tools with the exploitation of vulnerabilities that have only recently been disclosed.

Join our free webinar to learn about combating slow DDoS attacks, a major threat today.

Leveraging open-source Tools

By leveraging open-source tools throughout the attack lifecycle, TAG-100 minimizes the need for custom-developed malware, reducing their development time and potentially evading detection by security software focused on identifying signatures of known malware.

The opportunistic exploitation of recently disclosed vulnerabilities demonstrates their ability to rapidly adapt their tactics to the evolving threat landscape, allowing them to target vulnerable systems before security patches are widely deployed, potentially maximizing the window of opportunity for a successful attack.

The use of open-source tools throughout various stages of the attack cycle offers them several advantages, as open-source tools are freely available and widely documented, making them easy to obtain and integrate into existing toolsets.

Additionally, the ubiquity of open-source tools can obfuscate malicious activity, as network traffic generated during these attacks may appear legitimate on the surface, which can make it more difficult for security defenders to detect and isolate malicious activity within a network.

TAG-100’s reliance on open-source tools also presents potential weaknesses.

The open nature of these tools means that security researchers and defenders are also familiar with their capabilities, making it easier to identify and disrupt attacks that leverage these tools.

The open-source community constantly develops and updates these tools, which may introduce vulnerabilities that security researchers can exploit to disrupt or disable malware that relies on them.


Broadcom
identified threats using a combination of signature-based and behavioral analysis. Trojan malware, Trojan.Gen.MBT and Trojan.Gen.NPE was detected on the system.

The system flagged suspicious network activity, including attempts to connect to malicious domains or IPs, which were identified through a combination of file-based analysis, network traffic monitoring, and web filtering.

Protect Your Business Emails From Spoofing, Phishing & BEC with AI-Powered Security | Free Demo

Cyber Advisory

CISO Advisory is a Team of Security Experts Covering Various Cybersecurity Research and Technical Write-ups.

Recent Posts

Hackers Target AI Infrastructure With RCE, Prompt Injection and API Key Theft

Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…

4 hours ago

Hackers Make Phishing Pages Change Their Code Every Time Someone Opens Them

Hackers are making some phishing pages harder to track by changing the code delivered to…

4 hours ago

Iran-Linked Hackers Reportedly Knock UK Power Plant Offline for Four Days

A cyber incident reportedly forced a British power plant to halt operations for about four…

5 hours ago

Russian Hackers Use New HOOKEDGE Malware to Spy on European Defense and Diplomatic Targets

Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…

6 hours ago

Ransomware Gang Claims AI Can Analyze 700GB of Stolen Data Every Hour

TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…

6 hours ago

Hackers Compromise Hundreds of WordPress Sites to Deploy Amatera Stealer via ClickFix

A fake student resume is being used to place a remote-access tool on researchers’ Windows…

7 hours ago