{"id":32958,"date":"2020-01-24T14:10:00","date_gmt":"2020-01-24T14:10:00","guid":{"rendered":"http:\/\/78970267-fdc6-480a-80ae-2426d5d54c63"},"modified":"2020-01-24T14:10:00","modified_gmt":"2020-01-24T14:10:00","slug":"hackers-target-unpatched-citrix-servers-to-deploy-ransomware","status":"publish","type":"post","link":"https:\/\/www.threatshub.org\/blog\/hackers-target-unpatched-citrix-servers-to-deploy-ransomware\/","title":{"rendered":"Hackers target unpatched Citrix servers to deploy ransomware"},"content":{"rendered":"<p><span class=\"img aspect-set\"><img decoding=\"async\" src=\"https:\/\/zdnet1.cbsistatic.com\/hub\/i\/2020\/01\/09\/ea3bd747-fd4e-412b-b9d1-6bf8a50c6aaf\/company-shuts-down-because-of-ransomware-5e16586b81f53e00015e6599-1-jan-09-2020-14-00-23-poster.jpg\" class alt=\"company-shuts-down-because-of-ransomware-5e16586b81f53e00015e6599-1-jan-09-2020-14-00-23-poster.jpg\"><\/span><\/p>\n<p>Companies still running unpatched Citrix servers are in danger of having their networks infected with ransomware.<\/p>\n<p>Multiple sources in the infosec community are reporting about hacker groups using the <a href=\"https:\/\/support.citrix.com\/article\/CTX267027\" target=\"_blank\" rel=\"noopener noreferrer nofollow\" data-component=\"externalLink\">CVE-2019-19781 vulnerability<\/a> in Citrix appliances to breach corporate networks and then install ransomware.<\/p>\n<h3>Confirmed REvil infections<\/h3>\n<p>Ransomware infections traced back to hacked Citrix servers have been confirmed by security researchers at <a href=\"https:\/\/twitter.com\/QW5kcmV3\/status\/1220408977940516867\" target=\"_blank\" rel=\"noopener noreferrer\" data-component=\"externalLink\">FireEye<\/a> and <a href=\"https:\/\/twitter.com\/underthebreach\/status\/1220687658701246464\" target=\"_blank\" rel=\"noopener noreferrer\" data-component=\"externalLink\">Under the Breach<\/a>.<\/p>\n<p><span class=\"img aspect-set\"><img decoding=\"async\" src=\"https:\/\/www.zdnet.com\/article\/hackers-target-unpatched-citrix-servers-to-deploy-ransomware\/\" class=\"lazy\" alt=\"citrix-tweet-1.png\" data-original=\" https:\/\/zdnet3.cbsistatic.com\/hub\/i\/2020\/01\/24\/1aab66de-f7b8-4943-b91f-d3124e9b288e\/citrix-tweet-1.png\"><\/span><noscript><\/p>\n<p><span class=\"img aspect-set\"><img decoding=\"async\" src=\"https:\/\/zdnet3.cbsistatic.com\/hub\/i\/2020\/01\/24\/1aab66de-f7b8-4943-b91f-d3124e9b288e\/citrix-tweet-1.png\" class alt=\"citrix-tweet-1.png\"><\/span><\/p>\n<p><\/noscript><\/p>\n<p>The REvil (Sodinokibi) ransomware gang has been identified as one of the groups attacking Citrix servers to gain a foothold on corporate networks and later install their custom ransomware strain.<\/p>\n<p>&#8220;I examined the files the REvil gang posted online from Gedia.com after the company refused to pay the ransom demand,&#8221; security researchers from Under the Breach said today.<\/p>\n<p>&#8220;The interesting thing I discovered is that they obviously hacked Gedia via the Citrix exploit.&#8221;<\/p>\n<p><span class=\"img aspect-set\"><img decoding=\"async\" src=\"https:\/\/www.zdnet.com\/article\/hackers-target-unpatched-citrix-servers-to-deploy-ransomware\/\" class=\"lazy\" alt=\"citrix-files.png\" height=\"auto\" width=\"1200\" data-original=\" https:\/\/zdnet3.cbsistatic.com\/hub\/i\/r\/2020\/01\/24\/44a34c46-d665-4810-8709-5d652ca433fd\/resize\/1200xauto\/9f89c335b368c6a91a81a7dc76350a2f\/citrix-files.png\"><\/span><noscript><\/p>\n<p><span class=\"img aspect-set\"><img decoding=\"async\" src=\"https:\/\/zdnet3.cbsistatic.com\/hub\/i\/r\/2020\/01\/24\/44a34c46-d665-4810-8709-5d652ca433fd\/resize\/1200xauto\/9f89c335b368c6a91a81a7dc76350a2f\/citrix-files.png\" class alt=\"citrix-files.png\" height=\"auto\" width=\"1200\"><\/span><\/p>\n<p><\/noscript> <span class=\"credit\">Image: Under the Breach<\/span><\/p>\n<p>Unconfirmed rumors also claim the Maze ransomware gang is also targeting Citrix servers, similar to the REvil gang.<\/p>\n<section class=\"sharethrough-top\" data-component=\"medusaContentRecommendation\" data-medusa-content-recommendation-options=\"{&quot;promo&quot;:&quot;promo_zd_recommendation_sharethrough_top_in_article_desktop&quot;,&quot;spot&quot;:&quot;dfp-in-article&quot;}\">\n<\/section>\n<p>However, attacking corporate servers fits perfectly with the modus operandi of the REvil gang. Previously, this same gang has also been <a href=\"https:\/\/doublepulsar.com\/big-game-ransomware-being-delivered-to-organisations-via-pulse-secure-vpn-bd01b791aad9\" target=\"_blank\" rel=\"noopener noreferrer nofollow\" data-component=\"externalLink\">exploiting vulnerabilities in Pulse Secure VPNs<\/a> to breach corporate networks and install their ransomware.<\/p>\n<h3>Citrix patches are now broadly available<\/h3>\n<p>All these attacks are taking place after hackers scan the internet for Citrix appliances that have not been secured against the CVE-2019-19781 vulnerability.<\/p>\n<p>Vulnerable devices include the Citrix Application Delivery Controller (ADC), Citrix Gateway, and two older versions of Citrix SD-WAN WANOP.<\/p>\n<p>The vulnerability was disclosed in mid-December; however, internet-wide attacks began after January 11, <a href=\"https:\/\/www.zdnet.com\/article\/proof-of-concept-code-published-for-citrix-bug-as-attacks-intensify\/\" target=\"_blank\" rel=\"noopener noreferrer\">when proof-of-concept exploit code was published online<\/a> and became broadly available to anyone.<\/p>\n<p>Initially, patches were not available for the CVE-2019-19781 vulnerability. Instead, Citrix recommended <a href=\"https:\/\/support.citrix.com\/article\/CTX267679\" target=\"_blank\" rel=\"noopener noreferrer nofollow\" data-component=\"externalLink\">a series of mitigations<\/a> that server owners could apply and secure their devices.<\/p>\n<p>Those mitigations didn&#8217;t always work, or many companies failed to apply them. With the broad availability of proof-of-concept code, attacks on Citrix servers have been rampant in recent weeks.<\/p>\n<p>The good news is that earlier today, <a href=\"https:\/\/www.citrix.com\/blogs\/2020\/01\/23\/fixes-now-available-for-citrix-adc-citrix-gateway-versions-12-1-and-13-0\/\" target=\"_blank\" rel=\"noopener noreferrer nofollow\" data-component=\"externalLink\">Citrix finished publishing patches for all vulnerable versions<\/a>, meaning companies can apply a permanent fix to their servers by updating to the most recent version of the Citrix firmware.<\/p>\n<h3>Patching is going well<\/h3>\n<p>Currently, the patching process appears to be going well. In December, the number of vulnerable systems was <a href=\"https:\/\/www.ptsecurity.com\/ww-en\/about\/news\/citrix-vulnerability-allows-criminals-to-hack-networks-of-80000-companies\/\" target=\"_blank\" rel=\"noopener noreferrer nofollow\" data-component=\"externalLink\">estimated at 80,000 servers<\/a>, a number that <a href=\"https:\/\/badpackets.net\/over-25000-citrix-netscaler-endpoints-vulnerable-to-cve-2019-19781\/\" target=\"_blank\" rel=\"noopener noreferrer nofollow\" data-component=\"externalLink\">went down to roughly 25,000<\/a> in mid-January, and has gone down to around 11,000 systems, as of yesterday.<\/p>\n<p>Earlier this week, Citrix and FireEye have also <a href=\"https:\/\/www.fireeye.com\/blog\/products-and-services\/2020\/01\/fireeye-and-citrix-tool-scans-for-iocs-related-to-vulnerability.html\" target=\"_blank\" rel=\"noopener noreferrer nofollow\" data-component=\"externalLink\">collaborated to build a tool<\/a> that Citrix server owners can run and see if they&#8217;re appliances have been hacked with the CVE-2019-19781 exploit, before applying a patch.<\/p>\n<p>If the threat of getting infected with ransomware is not enough to scare some companies in applying the Citrix patches for CVE-2019-19781, then companies should also be aware that some criminals are currently hijacking Citrix servers and selling access to their networks on hacking forums, according to an image researchers from Under the Breach shared with ZDNet last week.<\/p>\n<p><span class=\"img aspect-set\"><img decoding=\"async\" src=\"https:\/\/www.zdnet.com\/article\/hackers-target-unpatched-citrix-servers-to-deploy-ransomware\/\" class=\"lazy\" alt=\"citrix-access.png\" height=\"auto\" width=\"1200\" data-original=\" https:\/\/zdnet4.cbsistatic.com\/hub\/i\/r\/2020\/01\/24\/a98ef244-0b8f-44da-a932-f6bec2aab86b\/resize\/1200xauto\/b64f7a49393b5cd067350713e3654b73\/citrix-access.png\"><\/span><noscript><\/p>\n<p><span class=\"img aspect-set\"><img decoding=\"async\" src=\"https:\/\/zdnet4.cbsistatic.com\/hub\/i\/r\/2020\/01\/24\/a98ef244-0b8f-44da-a932-f6bec2aab86b\/resize\/1200xauto\/b64f7a49393b5cd067350713e3654b73\/citrix-access.png\" class alt=\"citrix-access.png\" height=\"auto\" width=\"1200\"><\/span><\/p>\n<p><\/noscript> <span class=\"credit\">Image: Under the Breach<\/span> READ MORE <a href=\"https:\/\/www.zdnet.com\/article\/hackers-target-unpatched-citrix-servers-to-deploy-ransomware\/#ftag=RSSbaffb68\">HERE<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>REvil ransomware gang has been spotted abusing Citrix bug to infect victims.<br \/>\nREAD MORE HERE&#8230;<\/p>\n","protected":false},"author":2,"featured_media":32959,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"colormag_page_layout":"default_layout","footnotes":""},"categories":[62],"tags":[],"class_list":["post-32958","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-zdnet-security"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.8 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Hackers target unpatched Citrix servers to deploy ransomware 2026 | ThreatsHub Cybersecurity News<\/title>\n<meta name=\"description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.threatshub.org\/blog\/hackers-target-unpatched-citrix-servers-to-deploy-ransomware\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Hackers target unpatched Citrix servers to deploy ransomware 2026 | ThreatsHub Cybersecurity News\" \/>\n<meta property=\"og:description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.threatshub.org\/blog\/hackers-target-unpatched-citrix-servers-to-deploy-ransomware\/\" \/>\n<meta property=\"og:site_name\" content=\"ThreatsHub Cybersecurity News\" \/>\n<meta property=\"article:published_time\" content=\"2020-01-24T14:10:00+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2020\/01\/hackers-target-unpatched-citrix-servers-to-deploy-ransomware.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"960\" \/>\n\t<meta property=\"og:image:height\" content=\"540\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"TH Author\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@threatshub\" \/>\n<meta name=\"twitter:site\" content=\"@threatshub\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"TH Author\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"3 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/hackers-target-unpatched-citrix-servers-to-deploy-ransomware\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/hackers-target-unpatched-citrix-servers-to-deploy-ransomware\\\/\"},\"author\":{\"name\":\"TH Author\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\"},\"headline\":\"Hackers target unpatched Citrix servers to deploy ransomware\",\"datePublished\":\"2020-01-24T14:10:00+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/hackers-target-unpatched-citrix-servers-to-deploy-ransomware\\\/\"},\"wordCount\":518,\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/hackers-target-unpatched-citrix-servers-to-deploy-ransomware\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/01\\\/hackers-target-unpatched-citrix-servers-to-deploy-ransomware.jpg\",\"articleSection\":[\"ZDNet | Security\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/hackers-target-unpatched-citrix-servers-to-deploy-ransomware\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/hackers-target-unpatched-citrix-servers-to-deploy-ransomware\\\/\",\"name\":\"Hackers target unpatched Citrix servers to deploy ransomware 2026 | ThreatsHub Cybersecurity News\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/hackers-target-unpatched-citrix-servers-to-deploy-ransomware\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/hackers-target-unpatched-citrix-servers-to-deploy-ransomware\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/01\\\/hackers-target-unpatched-citrix-servers-to-deploy-ransomware.jpg\",\"datePublished\":\"2020-01-24T14:10:00+00:00\",\"description\":\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/hackers-target-unpatched-citrix-servers-to-deploy-ransomware\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/hackers-target-unpatched-citrix-servers-to-deploy-ransomware\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/hackers-target-unpatched-citrix-servers-to-deploy-ransomware\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/01\\\/hackers-target-unpatched-citrix-servers-to-deploy-ransomware.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/01\\\/hackers-target-unpatched-citrix-servers-to-deploy-ransomware.jpg\",\"width\":960,\"height\":540},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/hackers-target-unpatched-citrix-servers-to-deploy-ransomware\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Hackers target unpatched Citrix servers to deploy ransomware\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"name\":\"ThreatsHub Cybersecurity News\",\"description\":\"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"alternateName\":\"Threatshub.org\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\",\"name\":\"ThreatsHub.org\",\"alternateName\":\"Threatshub.org\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"width\":432,\"height\":435,\"caption\":\"ThreatsHub.org\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/threatshub\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\",\"name\":\"TH Author\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"caption\":\"TH Author\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Hackers target unpatched Citrix servers to deploy ransomware 2026 | ThreatsHub Cybersecurity News","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.threatshub.org\/blog\/hackers-target-unpatched-citrix-servers-to-deploy-ransomware\/","og_locale":"en_US","og_type":"article","og_title":"Hackers target unpatched Citrix servers to deploy ransomware 2026 | ThreatsHub Cybersecurity News","og_description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","og_url":"https:\/\/www.threatshub.org\/blog\/hackers-target-unpatched-citrix-servers-to-deploy-ransomware\/","og_site_name":"ThreatsHub Cybersecurity News","article_published_time":"2020-01-24T14:10:00+00:00","og_image":[{"width":960,"height":540,"url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2020\/01\/hackers-target-unpatched-citrix-servers-to-deploy-ransomware.jpg","type":"image\/jpeg"}],"author":"TH Author","twitter_card":"summary_large_image","twitter_creator":"@threatshub","twitter_site":"@threatshub","twitter_misc":{"Written by":"TH Author","Est. reading time":"3 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.threatshub.org\/blog\/hackers-target-unpatched-citrix-servers-to-deploy-ransomware\/#article","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/hackers-target-unpatched-citrix-servers-to-deploy-ransomware\/"},"author":{"name":"TH Author","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476"},"headline":"Hackers target unpatched Citrix servers to deploy ransomware","datePublished":"2020-01-24T14:10:00+00:00","mainEntityOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/hackers-target-unpatched-citrix-servers-to-deploy-ransomware\/"},"wordCount":518,"publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/hackers-target-unpatched-citrix-servers-to-deploy-ransomware\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2020\/01\/hackers-target-unpatched-citrix-servers-to-deploy-ransomware.jpg","articleSection":["ZDNet | Security"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.threatshub.org\/blog\/hackers-target-unpatched-citrix-servers-to-deploy-ransomware\/","url":"https:\/\/www.threatshub.org\/blog\/hackers-target-unpatched-citrix-servers-to-deploy-ransomware\/","name":"Hackers target unpatched Citrix servers to deploy ransomware 2026 | ThreatsHub Cybersecurity News","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/hackers-target-unpatched-citrix-servers-to-deploy-ransomware\/#primaryimage"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/hackers-target-unpatched-citrix-servers-to-deploy-ransomware\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2020\/01\/hackers-target-unpatched-citrix-servers-to-deploy-ransomware.jpg","datePublished":"2020-01-24T14:10:00+00:00","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","breadcrumb":{"@id":"https:\/\/www.threatshub.org\/blog\/hackers-target-unpatched-citrix-servers-to-deploy-ransomware\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.threatshub.org\/blog\/hackers-target-unpatched-citrix-servers-to-deploy-ransomware\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/hackers-target-unpatched-citrix-servers-to-deploy-ransomware\/#primaryimage","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2020\/01\/hackers-target-unpatched-citrix-servers-to-deploy-ransomware.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2020\/01\/hackers-target-unpatched-citrix-servers-to-deploy-ransomware.jpg","width":960,"height":540},{"@type":"BreadcrumbList","@id":"https:\/\/www.threatshub.org\/blog\/hackers-target-unpatched-citrix-servers-to-deploy-ransomware\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.threatshub.org\/blog\/"},{"@type":"ListItem","position":2,"name":"Hackers target unpatched Citrix servers to deploy ransomware"}]},{"@type":"WebSite","@id":"https:\/\/www.threatshub.org\/blog\/#website","url":"https:\/\/www.threatshub.org\/blog\/","name":"ThreatsHub Cybersecurity News","description":"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform","publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"alternateName":"Threatshub.org","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.threatshub.org\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.threatshub.org\/blog\/#organization","name":"ThreatsHub.org","alternateName":"Threatshub.org","url":"https:\/\/www.threatshub.org\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","width":432,"height":435,"caption":"ThreatsHub.org"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/threatshub"]},{"@type":"Person","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476","name":"TH Author","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","caption":"TH Author"}}]}},"_links":{"self":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/32958","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/comments?post=32958"}],"version-history":[{"count":0,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/32958\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media\/32959"}],"wp:attachment":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media?parent=32958"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/categories?post=32958"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/tags?post=32958"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}