NOTROBIN
0 incidentes
0 paises
0 sectores
apt UNKNOWN Ultimo: -
NOTROBIN refers to a unique malware payload deployed by an unnamed threat actor, which emerged around January 2020, following its discovery by Mandiant while investigating exploitation of the Citrix ADC/NetScaler vulnerability (CVE-2019-19781). This actor, characterized by initial reports as a nation-state-backed entity, operates with the primary motivation of gaining and maintaining exclusive backdoor access to compromised Citrix devices, potentially for espionage or to prepare for future campaigns. What sets this activity apart is NOTROBIN's unusual behavior of cleaning other malware from infected systems, such as cryptocurrency miners, and blocking subsequent exploitation attempts by other threat actors, effectively 'inoculating' the device against further compromise while retaining a secret key for its own persistent access. This strategy suggests a sophisticated and patient adversary focused on long-term access collection rather than immediate destructive or financially motivated
Sectores objetivo (SOCRadar)
TelecommunicationsComputer Systems Design and Related Services