Summary
NotRobin is a backdoor that targets Citrix/NetScaler appliances.
Affected platforms
The following platforms are known to be affected:
- Citrix/NetScaler ADC - Versions 13.0, 12.1, 12.0, 11.1, and 10.5 (all supported builds)
- Citrix/NetScaler Gateway - Versions 13.0, 12.1, 12.0, 11.1, and 10.5 (all supported builds)
- Citrix SD-WAN WANOP - Software and appliance models 4000, 4100, 5000, and 5100 (all supported builds)
Threat details
NotRobin is spread over the internet via exploitation of a Remote Code Execution (RCE) vulnerability in these devices. The threat actor remains anonymous as they distribute NotRobin using Tor.
When executed, NotRobin removes other malware that has compromised the affected device. It then gains persistence on the device by creating a cron job and blocks any further exploitation attempts except by the threat actor. The compromised device will also listen on UDP port 18634 but drop any received data without inspection. At the time of publication there is no evidence of any additional malware being deployed to devices compromised by NotRobin.
Remediation steps
Indicators of compromise
Last edited: 10 January 2022 4:41 pm