Skip to main content

NotRobin Backdoor

NotRobin is a backdoor that targets Citrix/NetScaler appliances.

Report a cyber attack: call 0300 303 5222 or email [email protected]

Summary

NotRobin is a backdoor that targets Citrix/NetScaler appliances.


Affected platforms

The following platforms are known to be affected:

  • Citrix/NetScaler ADC - Versions 13.0, 12.1, 12.0, 11.1, and 10.5 (all supported builds)
  • Citrix/NetScaler Gateway - Versions 13.0, 12.1, 12.0, 11.1, and 10.5 (all supported builds)
  • Citrix SD-WAN WANOP - Software and appliance models 4000, 4100, 5000, and 5100 (all supported builds)

Threat details

NotRobin is spread over the internet via exploitation of a Remote Code Execution (RCE) vulnerability in these devices. The threat actor remains anonymous as they distribute NotRobin using Tor.

When executed, NotRobin removes other malware that has compromised the affected device. It then gains persistence on the device by creating a cron job and blocks any further exploitation attempts except by the threat actor. The compromised device will also listen on UDP port 18634 but drop any received data without inspection. At the time of publication there is no evidence of any additional malware being deployed to devices compromised by NotRobin.


Remediation steps

Type Step

To prevent a compromise by NotRobin, administrators can apply Citrix's updates or mitigation to vulnerable devices. Citrix expects to release firmware updates for all supported versions before the end of January 2020.

If a device has been compromised it should be re-formatted before the update or mitigation is applied.

Update and mitigation details can be found at the following link:



Indicators of compromise

Main indicators

Listening UDP port:

  • 18634

Directories/Filenames:

  • /var/nstmp/.nscache/httpd
  • /tmp/.init/httpd

Crontab entry:

  • /var/nstmp/.nscache/httpd

Domain:

  • vilarunners[.]cat

IP addresses:

  • 95.179.163[.]186
  • 80.240.31[.]218

YARA rule:

  • NotRobin YARA Rule 17/01/2020 (Courtesy of FireEye, Inc.)

Last edited: 10 January 2022 4:41 pm