{"id":49224,"date":"2022-11-09T18:53:00","date_gmt":"2022-11-09T18:53:00","guid":{"rendered":"https:\/\/www.csoonline.com\/article\/3679628\/researchers-show-techniques-for-malware-persistence-on-f5-and-citrix-load-balancers.html#tk.rss_security"},"modified":"2022-11-09T18:53:00","modified_gmt":"2022-11-09T18:53:00","slug":"researchers-show-techniques-for-malware-persistence-on-f5-and-citrix-load-balancers","status":"publish","type":"post","link":"https:\/\/www.threatshub.org\/blog\/researchers-show-techniques-for-malware-persistence-on-f5-and-citrix-load-balancers\/","title":{"rendered":"Researchers show techniques for malware persistence on F5 and Citrix load balancers"},"content":{"rendered":"<div><img decoding=\"async\" src=\"https:\/\/images.idgesg.net\/images\/article\/2020\/02\/firmware_message_on_circuit_board_by_atakan_gettyimages-1199850158_2400x1600-100832616-large.jpg?auto=webp&amp;quality=85,70\" class=\"ff-og-image-inserted\"><\/div>\n<p>Over the past several years, hackers have targeted public-facing network devices such as routers, VPN concentrators, and load balancers to gain a foothold into corporate networks. While finding remote code execution vulnerabilities in such devices is not uncommon, incidents where attackers were able to deploy malware on them that can survive restarts or firmware upgrades have been rare and generally attributed with sophisticated APT groups.<\/p>\n<p>Because they use flash memory that degrades over time if subjected to many write operations, embedded network devices typically store their firmware in read-only filesystems and load their contents into RAM at each restart. This means that all changes and files generated by the various running services during the device\u2019s normal operation are temporary because they only occur in RAM and are never saved to the file system, which is restored to its initial state when the device is restarted reboot.<\/p>\n<p>The exceptions are configuration files and scripts that are generated through the device administrative interface and are stored in a limited area of storage known as NVRAM (non-volatile RAM). From an attacker&#8217;s perspective, this limitation makes compromising networking devices in a persistent way much harder, which is why mass attacks against home routers, for example, involve automated botnets that periodically rescan and reinfect routers that have been restarted.<\/p>\n<p>However, in a targeted attack scenario against enterprise networks, attackers would prefer to remain stealthy and not attack the same device multiple times so they don\u2019t trigger any detections that might be put in place after a vulnerability becomes public. They would also prefer to have long-term access to such devices and use them as bridges into the internal networks, as well as pivot points from where they could perform lateral movement and expand their access to other non-public devices.<\/p>\n<h2>Persistence opportunities in Citrix, F5 load balancers<\/h2>\n<p>Since 2019, there have been three critical vulnerabilities in Citrix and F5 load balancers (<a href=\"https:\/\/support.citrix.com\/article\/CTX267027\/cve201919781-vulnerability-in-citrix-application-delivery-controller-citrix-gateway-and-citrix-sdwan-wanop-appliance\" rel=\"nofollow noopener\" target=\"_blank\">CVE-2019-19781<\/a>, <a href=\"https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2020-5902\" rel=\"nofollow noopener\" target=\"_blank\">CVE-2020-5902<\/a> and <a href=\"https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=2022-1388\" rel=\"nofollow noopener\" target=\"_blank\">CVE-2022-1388<\/a>) that have been publicly documented and exploited in the wild, <a href=\"https:\/\/www.cisa.gov\/uscert\/ncas\/alerts\/aa22-138a\" rel=\"nofollow noopener\" target=\"_blank\">triggering warnings<\/a> from the US Cybersecurity and Infrastructure Security Agency (CISA) and other organizations. Because of this, researchers from firmware security firm Eclypsium recently investigated the persistence opportunities attackers would have on such devices. Their findings were released in <a href=\"https:\/\/eclypsium.com\/2022\/11\/09\/pwned-balancers-f5-and-citrix-for-persistent-c2\/\" rel=\"nofollow noopener\" target=\"_blank\">a report<\/a> Wednesday.<\/p>\n<p>In May 2022, security firm Mandiant <a href=\"https:\/\/www.mandiant.com\/resources\/blog\/unc3524-eye-spy-email\" rel=\"nofollow noopener\" target=\"_blank\">reported<\/a> that a cyberespionage threat actor \u2013 identified at the time as UNC3524 but since correlated with the Russian state-run APT29 (Cozy Bear) \u2013 compromised enterprise networks and remained undetected for long periods of time due to deploying backdoor implants on network appliances including load balancers that don\u2019t support running detection tools such as endpoint detection and response (EDR) on them and run older versions of CentOS and BSD. While Mandiant didn\u2019t name the appliances or their manufacturers, the Eclypsium researchers believe they were F5 and Citrix appliances, since F5 load balancers run CentOS and Citrix (formerly branded as Netscaler) runs FreeBSD.<\/p>\n<aside class=\"nativo-promo nativo-promo-1 smartphone\" id> <\/aside>\n<p>\u201cOne characteristic of UNC3524 stuck out: Their TTPs were unreliable, they used modified open-source software to establish their backdoor, and seemed to only possess enough understanding of the systems to achieve the most basic of goals,\u201d the Eclypsium researchers said in their report. \u201cTheir implants were so unreliable they installed web shells for the sole purpose of restarting them when they died. It was this characteristic that was the catalyst for the research, the unanswered being: Is it possible to use an off-the-shelf C2 framework on a load balancer? Can the malware be resilient enough to persist across reboots and even upgrades? Is it possible to infect the device so deeply that a clean wipe and reinstall isn\u2019t sufficient?\u201d<\/p>\n<p>Many attack groups choose to use cracked versions of commercial attack frameworks such as Cobalt Strike or Brute Ratel, but the Eclypsium researchers wanted something that\u2019s open source and easily available to less sophisticated attackers, so they chose Sliver, an open-source adversary emulation framework, for their test implant. Sliver is written in Go, so it\u2019s cross-platform and provides pivoting and tunneling functionality.<\/p>\n<aside class=\"nativo-promo nativo-promo-1 tablet desktop\" id> <\/aside>\n<p>To investigate what files F5 load balancers retain across reboots and firmware upgrades, the researchers looked into the configuration backup functionality available through the administration interface that can be used to generate an archive containing all the configs and settings that can later be deployed on a fresh install. Inside the archive, which included hundreds of files, the researchers settled on three executable scripts and configuration files that can execute scripts on certain events.<\/p>\n<p>\u201cAn unexpected discovery during this research was vendor documentation; it proved to be a wealth of information on undocumented features and functionality shoehorned into these devices over the years,\u201d the researchers said. \u201cIn credit to the vendors, had it not been for the documentation this research would have been significantly more difficult. It is important to understand how devices handle their configuration files.\u201d<\/p>\n<h2>Three ways to store and start malicious scripts<\/h2>\n<p>After scouring the documentation and config files, the team now had three different ways to store and start scripts after reboot that would even survive reinstalled because they would be included in the config backups. Storing the 12MB implant directly inside the backup archive would have not been inconspicuous, so the researchers opted to store a script that would later download the implant from the internet, kill any existing versions, and deploy it.<\/p>\n<p>\u201cOpting to download the implant makes the assumption that the device can connect to the internet,\u201d they said. \u201cIf the attacker didn\u2019t have this luxury but had a foothold on another system in the network, a smaller implant could be stored inside the config directory structure without alerting the administrators. This implant could instead connect to the \u2018jump box\u2019 system under the attacker\u2019s control.\u201d<\/p>\n<aside class=\"nativo-promo nativo-promo-2 tablet desktop smartphone\" id> <\/aside>\n<p>For further stealthiness, the researchers found that the runsv Linux service on F5 boxes was configured to run a service whose configuration pointed to a binary file called \u200b\u200brestjavad that didn\u2019t exist on the system. They used this file name for their implant so it doesn\u2019t look suspicious in a process listing. If an administrator would spot the process and would search for the name, they would likely find the F5 documentation for the legitimate \u200b\u200brestjavad service.<\/p>\n<p>Researching the Citrix system proved a bit more difficult as the documentation was not as detailed. However, inside the user manual they found a note about setting up Network Time Protocol (NTP) synchronization. The instructions involved creating a file called rc.netscaler inside the \/nsconfig directory, which does get saved during a backup, and then adding a line to it called \/bin\/sh \/etc\/ntpd_ctl full_start. However, the scripts in the \/etc\/ directory were not set as executable and there was no way to change that. During the process the researchers figured out that the system used a package called Monit to start, stop and monitor the status of system processes and Monit stored its configuration in \/nsconfig.<\/p>\n<p>\u201cWe ended up writing a wrapper for our implant to run like a service and reused the same logic from the F5 loader,\u201d the researchers said. \u201cFrom there we simply dropped this file and the modified monit file into \/nsconfig and verified the implant would start on boot and that our wrapper would be included in backup files.\u201d Another side effect of using Monit was that it made the implant even more persistent, with Monit automatically restarting the service every few seconds if it was ever manually killed.<\/p>\n<p>The researchers also tested the pivoting ability, which allows attackers to use the compromised device as a proxy to access other devices inside the network that wouldn\u2019t normally have access to the internet. The F5 system allowed binding the implant to a port on one of the IPs on the device and then use ACL to allow access to that port.<\/p>\n<aside class=\"nativo-promo nativo-promo-3 tablet desktop smartphone\" id> <\/aside>\n<p>\u201cThe bar for advanced attackers keeps getting lower and as the imposed cost of attacking hardened systems like servers or workstations gets higher, attackers are turning to more novel ways of infiltrating systems,\u201d the researchers concluded. \u201cGone are the days of proprietary, purpose-built firmware used by routers &amp; switches, instead replaced with firmware which is a fully functional operating system. This evolution introduces the commodity-server level risk on devices that have historically been out of reach for all but the most skilled attackers.\u201d<\/p>\n<div class=\"end-note\"> <!-- blx4 #2004 blox4.html --> <\/p>\n<div id class=\"blx blxParticleendnote blxM2004 blox4_html blxC51120\">\n<aside> <strong>Next read this<\/strong> <\/aside>\n<\/p><\/div>\n<\/p><\/div>\n<p> READ MORE <a href=\"https:\/\/www.csoonline.com\/article\/3679628\/researchers-show-techniques-for-malware-persistence-on-f5-and-citrix-load-balancers.html#tk.rss_security\">HERE<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Tests show that deploying malware in a persistent manner on load balancer firmware is within reach of less sophisticated attackers. READ MORE HERE&#8230;<\/p>\n","protected":false},"author":2,"featured_media":49225,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"colormag_page_layout":"default_layout","footnotes":""},"categories":[738],"tags":[5310,1061,19],"class_list":["post-49224","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-networkworld","tag-advanced-persistent-threats","tag-network-security","tag-vulnerabilities"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.8 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Researchers show techniques for malware persistence on F5 and Citrix load balancers 2026 | ThreatsHub Cybersecurity News<\/title>\n<meta name=\"description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.threatshub.org\/blog\/researchers-show-techniques-for-malware-persistence-on-f5-and-citrix-load-balancers\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Researchers show techniques for malware persistence on F5 and Citrix load balancers 2026 | ThreatsHub Cybersecurity News\" \/>\n<meta property=\"og:description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.threatshub.org\/blog\/researchers-show-techniques-for-malware-persistence-on-f5-and-citrix-load-balancers\/\" \/>\n<meta property=\"og:site_name\" content=\"ThreatsHub Cybersecurity News\" \/>\n<meta property=\"article:published_time\" content=\"2022-11-09T18:53:00+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/images.idgesg.net\/images\/article\/2020\/02\/firmware_message_on_circuit_board_by_atakan_gettyimages-1199850158_2400x1600-100832616-large.jpg?auto=webp&amp;quality=85,70\" \/>\n<meta name=\"author\" content=\"TH Author\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@threatshub\" \/>\n<meta name=\"twitter:site\" content=\"@threatshub\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"TH Author\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"7 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/researchers-show-techniques-for-malware-persistence-on-f5-and-citrix-load-balancers\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/researchers-show-techniques-for-malware-persistence-on-f5-and-citrix-load-balancers\\\/\"},\"author\":{\"name\":\"TH Author\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\"},\"headline\":\"Researchers show techniques for malware persistence on F5 and Citrix load balancers\",\"datePublished\":\"2022-11-09T18:53:00+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/researchers-show-techniques-for-malware-persistence-on-f5-and-citrix-load-balancers\\\/\"},\"wordCount\":1401,\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/researchers-show-techniques-for-malware-persistence-on-f5-and-citrix-load-balancers\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2022\\\/11\\\/researchers-show-techniques-for-malware-persistence-on-f5-and-citrix-load-balancers.jpg\",\"keywords\":[\"advanced persistent threats\",\"Network Security\",\"Vulnerabilities\"],\"articleSection\":[\"Networkworld\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/researchers-show-techniques-for-malware-persistence-on-f5-and-citrix-load-balancers\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/researchers-show-techniques-for-malware-persistence-on-f5-and-citrix-load-balancers\\\/\",\"name\":\"Researchers show techniques for malware persistence on F5 and Citrix load balancers 2026 | ThreatsHub Cybersecurity News\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/researchers-show-techniques-for-malware-persistence-on-f5-and-citrix-load-balancers\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/researchers-show-techniques-for-malware-persistence-on-f5-and-citrix-load-balancers\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2022\\\/11\\\/researchers-show-techniques-for-malware-persistence-on-f5-and-citrix-load-balancers.jpg\",\"datePublished\":\"2022-11-09T18:53:00+00:00\",\"description\":\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/researchers-show-techniques-for-malware-persistence-on-f5-and-citrix-load-balancers\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/researchers-show-techniques-for-malware-persistence-on-f5-and-citrix-load-balancers\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/researchers-show-techniques-for-malware-persistence-on-f5-and-citrix-load-balancers\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2022\\\/11\\\/researchers-show-techniques-for-malware-persistence-on-f5-and-citrix-load-balancers.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2022\\\/11\\\/researchers-show-techniques-for-malware-persistence-on-f5-and-citrix-load-balancers.jpg\",\"width\":150,\"height\":100},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/researchers-show-techniques-for-malware-persistence-on-f5-and-citrix-load-balancers\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"advanced persistent threats\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/tag\\\/advanced-persistent-threats\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"Researchers show techniques for malware persistence on F5 and Citrix load balancers\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"name\":\"ThreatsHub Cybersecurity News\",\"description\":\"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"alternateName\":\"Threatshub.org\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\",\"name\":\"ThreatsHub.org\",\"alternateName\":\"Threatshub.org\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"width\":432,\"height\":435,\"caption\":\"ThreatsHub.org\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/threatshub\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\",\"name\":\"TH Author\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"caption\":\"TH Author\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Researchers show techniques for malware persistence on F5 and Citrix load balancers 2026 | ThreatsHub Cybersecurity News","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.threatshub.org\/blog\/researchers-show-techniques-for-malware-persistence-on-f5-and-citrix-load-balancers\/","og_locale":"en_US","og_type":"article","og_title":"Researchers show techniques for malware persistence on F5 and Citrix load balancers 2026 | ThreatsHub Cybersecurity News","og_description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","og_url":"https:\/\/www.threatshub.org\/blog\/researchers-show-techniques-for-malware-persistence-on-f5-and-citrix-load-balancers\/","og_site_name":"ThreatsHub Cybersecurity News","article_published_time":"2022-11-09T18:53:00+00:00","og_image":[{"url":"https:\/\/images.idgesg.net\/images\/article\/2020\/02\/firmware_message_on_circuit_board_by_atakan_gettyimages-1199850158_2400x1600-100832616-large.jpg?auto=webp&amp;quality=85,70","type":"","width":"","height":""}],"author":"TH Author","twitter_card":"summary_large_image","twitter_creator":"@threatshub","twitter_site":"@threatshub","twitter_misc":{"Written by":"TH Author","Est. reading time":"7 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.threatshub.org\/blog\/researchers-show-techniques-for-malware-persistence-on-f5-and-citrix-load-balancers\/#article","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/researchers-show-techniques-for-malware-persistence-on-f5-and-citrix-load-balancers\/"},"author":{"name":"TH Author","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476"},"headline":"Researchers show techniques for malware persistence on F5 and Citrix load balancers","datePublished":"2022-11-09T18:53:00+00:00","mainEntityOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/researchers-show-techniques-for-malware-persistence-on-f5-and-citrix-load-balancers\/"},"wordCount":1401,"publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/researchers-show-techniques-for-malware-persistence-on-f5-and-citrix-load-balancers\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2022\/11\/researchers-show-techniques-for-malware-persistence-on-f5-and-citrix-load-balancers.jpg","keywords":["advanced persistent threats","Network Security","Vulnerabilities"],"articleSection":["Networkworld"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.threatshub.org\/blog\/researchers-show-techniques-for-malware-persistence-on-f5-and-citrix-load-balancers\/","url":"https:\/\/www.threatshub.org\/blog\/researchers-show-techniques-for-malware-persistence-on-f5-and-citrix-load-balancers\/","name":"Researchers show techniques for malware persistence on F5 and Citrix load balancers 2026 | ThreatsHub Cybersecurity News","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/researchers-show-techniques-for-malware-persistence-on-f5-and-citrix-load-balancers\/#primaryimage"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/researchers-show-techniques-for-malware-persistence-on-f5-and-citrix-load-balancers\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2022\/11\/researchers-show-techniques-for-malware-persistence-on-f5-and-citrix-load-balancers.jpg","datePublished":"2022-11-09T18:53:00+00:00","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","breadcrumb":{"@id":"https:\/\/www.threatshub.org\/blog\/researchers-show-techniques-for-malware-persistence-on-f5-and-citrix-load-balancers\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.threatshub.org\/blog\/researchers-show-techniques-for-malware-persistence-on-f5-and-citrix-load-balancers\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/researchers-show-techniques-for-malware-persistence-on-f5-and-citrix-load-balancers\/#primaryimage","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2022\/11\/researchers-show-techniques-for-malware-persistence-on-f5-and-citrix-load-balancers.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2022\/11\/researchers-show-techniques-for-malware-persistence-on-f5-and-citrix-load-balancers.jpg","width":150,"height":100},{"@type":"BreadcrumbList","@id":"https:\/\/www.threatshub.org\/blog\/researchers-show-techniques-for-malware-persistence-on-f5-and-citrix-load-balancers\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.threatshub.org\/blog\/"},{"@type":"ListItem","position":2,"name":"advanced persistent threats","item":"https:\/\/www.threatshub.org\/blog\/tag\/advanced-persistent-threats\/"},{"@type":"ListItem","position":3,"name":"Researchers show techniques for malware persistence on F5 and Citrix load balancers"}]},{"@type":"WebSite","@id":"https:\/\/www.threatshub.org\/blog\/#website","url":"https:\/\/www.threatshub.org\/blog\/","name":"ThreatsHub Cybersecurity News","description":"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform","publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"alternateName":"Threatshub.org","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.threatshub.org\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.threatshub.org\/blog\/#organization","name":"ThreatsHub.org","alternateName":"Threatshub.org","url":"https:\/\/www.threatshub.org\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","width":432,"height":435,"caption":"ThreatsHub.org"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/threatshub"]},{"@type":"Person","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476","name":"TH Author","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","caption":"TH Author"}}]}},"_links":{"self":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/49224","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/comments?post=49224"}],"version-history":[{"count":0,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/49224\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media\/49225"}],"wp:attachment":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media?parent=49224"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/categories?post=49224"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/tags?post=49224"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}