{
  "intelligence": {
    "actors": [],
    "counts": {
      "actors": 0,
      "associated_entity_contexts": 0,
      "deduplicated_iocs": 2,
      "direct_entities": 6,
      "direct_relationships": 2,
      "invalid_iocs": 0,
      "iocs": 2,
      "mentioned": 2,
      "mitre_associated": 0,
      "mitre_direct": 0,
      "targets": 0,
      "techniques": 0,
      "unsupported_indicators": 0,
      "vulnerabilities": 2
    },
    "coverage": {
      "associated_repertoire_is_incident_evidence": false,
      "attribution_policy": "explicit-public-relationships-only",
      "descriptions_publicly_exported": false,
      "excluded_context_objects": 0,
      "excluded_graph_objects": 85,
      "graph_complete": true,
      "graph_objects": 6,
      "graph_relationships": 2,
      "mitre_context_complete": true,
      "source_url": "https://www.greynoise.io/blog/swarming-against-citrix-0-day-exploitation",
      "status_as_of": "2026-10-08T07:51:40+00:00",
      "table_preview_limit": 20
    },
    "direct_entities": [
      {
        "__typename": "Indicator",
        "aliases": [],
        "attributes": {
          "pattern_type": "stix",
          "pattern_version": "2.1",
          "x_opencti_detection": false,
          "x_opencti_main_observable_type": "IPv4-Addr",
          "x_opencti_score": 50
        },
        "authorized_members": [],
        "confidence": 50,
        "created_by": null,
        "dates": {
          "created": "2026-10-01T08:06:31.305Z",
          "created_at": "2026-10-01T08:18:33.409Z",
          "modified": "2026-10-01T08:18:34.064Z",
          "updated_at": "2026-10-01T08:18:34.064Z"
        },
        "description_available": false,
        "entity_type": "Indicator",
        "id": "0326881c-fc3e-4d59-a34d-eb710bea46ac",
        "is_inferred": false,
        "labels": [
          "citrix netscaler",
          "citrixbleed",
          "command injection",
          "cve-2025-5777",
          "cve-2026-88771",
          "pre-disclosure attack",
          "rce",
          "webshell",
          "zero-day exploitation"
        ],
        "lang": "en",
        "name": null,
        "objectMarking": [
          {
            "definition": "TLP:CLEAR",
            "definition_type": "TLP"
          }
        ],
        "objectOrganization": [],
        "references": [],
        "restrict_access": false,
        "revoked": false,
        "scope": "report",
        "source_url": "https://www.greynoise.io/blog/swarming-against-citrix-0-day-exploitation",
        "standard_id": "indicator--845a5cc2-992c-5811-82ab-5ced2d8dd14f",
        "type": "Indicator"
      },
      {
        "__typename": "Indicator",
        "aliases": [],
        "attributes": {
          "indicator_types": [
            "sha256"
          ],
          "pattern_type": "stix",
          "pattern_version": "2.1",
          "x_opencti_detection": false,
          "x_opencti_main_observable_type": "StixFile",
          "x_opencti_score": 50
        },
        "authorized_members": [],
        "confidence": 50,
        "created_by": null,
        "dates": {
          "created": "2026-10-01T08:06:31.309Z",
          "created_at": "2026-10-01T08:18:33.574Z",
          "modified": "2026-10-03T04:23:34.026Z",
          "updated_at": "2026-10-03T04:23:34.026Z"
        },
        "description_available": false,
        "entity_type": "Indicator",
        "id": "03bc7fec-bed9-45b5-8871-9dfc726427a7",
        "is_inferred": false,
        "labels": [
          "citrix netscaler",
          "citrixbleed",
          "command injection",
          "cve-2025-5777",
          "cve-2026-88771",
          "pre-disclosure attack",
          "rce",
          "webshell",
          "zero-day exploitation"
        ],
        "lang": "en",
        "name": null,
        "objectMarking": [
          {
            "definition": "TLP:CLEAR",
            "definition_type": "TLP"
          }
        ],
        "objectOrganization": [],
        "references": [],
        "restrict_access": false,
        "revoked": false,
        "scope": "report",
        "source_url": "https://www.greynoise.io/blog/swarming-against-citrix-0-day-exploitation",
        "standard_id": "indicator--81b0c19c-779b-5820-a9e4-6406553a3149",
        "type": "Indicator"
      },
      {
        "__typename": "Vulnerability",
        "aliases": [],
        "attributes": {},
        "authorized_members": [],
        "confidence": 80,
        "created_by": null,
        "dates": {
          "created": "2025-06-17T13:15:21.523Z",
          "created_at": "2026-01-18T17:44:13.954Z",
          "modified": "2026-10-07T19:02:08.120Z",
          "updated_at": "2026-10-07T19:02:08.120Z"
        },
        "description_available": true,
        "entity_type": "Vulnerability",
        "id": "614bebb8-3dbf-4531-8ef3-975a65e98e28",
        "is_inferred": false,
        "labels": [],
        "lang": "en",
        "name": "CVE-2025-5777",
        "objectMarking": [
          {
            "definition": "TLP:CLEAR",
            "definition_type": "TLP"
          }
        ],
        "objectOrganization": [],
        "references": [
          {
            "external_id": null,
            "id": "8c7971c1-e850-4aba-bb3d-b9e1a0147425",
            "source_name": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
            "url": "https://doublepulsar.com/citrixbleed-2-exploitation-started-mid-june-how-to-spot-it-f3106392aa71"
          },
          {
            "external_id": null,
            "id": "48d977c8-def5-4afb-a8b0-e085fc86f4f4",
            "source_name": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
            "url": "https://reliaquest.com/blog/threat-spotlight-citrix-bleed-2-vulnerability-in-netscaler-adc-gateway-devices/"
          },
          {
            "external_id": "CVE-2025-5777",
            "id": "11117ef3-b4bf-4c29-a12a-581d9974d6c3",
            "source_name": "NIST NVD",
            "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5777"
          },
          {
            "external_id": null,
            "id": "5e0a793d-5ddc-483c-b988-130e8656063d",
            "source_name": "af854a3a-2127-422b-91ae-364da2661108",
            "url": "https://citrixbleed.com"
          },
          {
            "external_id": null,
            "id": "e0cfebf4-f69d-4746-9a44-bd7dbdf0588e",
            "source_name": "af854a3a-2127-422b-91ae-364da2661108",
            "url": "https://horizon3.ai/attack-research/attack-blogs/cve-2025-5777-citrixbleed-2-write-up-maybe/"
          },
          {
            "external_id": null,
            "id": "35f15875-d719-4681-a468-cce01ee38834",
            "source_name": "af854a3a-2127-422b-91ae-364da2661108",
            "url": "https://labs.watchtowr.com/how-much-more-must-we-bleed-citrix-netscaler-memory-disclosure-citrixbleed-2-cve-2025-5777/"
          },
          {
            "external_id": null,
            "id": "30ea2cbb-6f0d-4a74-862c-f95151934aaa",
            "source_name": "af854a3a-2127-422b-91ae-364da2661108",
            "url": "https://www.bleepingcomputer.com/news/security/cisa-tags-citrix-bleed-2-as-exploited-gives-agencies-a-day-to-patch/"
          },
          {
            "external_id": null,
            "id": "e8fe4dce-b994-438a-b5b0-b3965f96f841",
            "source_name": "af854a3a-2127-422b-91ae-364da2661108",
            "url": "https://www.netscaler.com/blog/news/netscaler-critical-security-updates-for-cve-2025-6543-and-cve-2025-5777/"
          },
          {
            "external_id": null,
            "id": "c77fec16-2999-4128-9a13-fdb0e63df3f5",
            "source_name": "af854a3a-2127-422b-91ae-364da2661108",
            "url": "https://www.theregister.com/2025/07/10/cisa_citrixbleed_kev/"
          }
        ],
        "restrict_access": false,
        "revoked": false,
        "scope": "report",
        "source_url": "https://www.greynoise.io/blog/swarming-against-citrix-0-day-exploitation",
        "standard_id": "vulnerability--f78cf0bd-1ec5-5385-95fe-355b03c2d87c",
        "type": "Vulnerability"
      },
      {
        "__typename": "StixFile",
        "aliases": [],
        "attributes": {},
        "authorized_members": [],
        "confidence": null,
        "created_by": null,
        "dates": {
          "created_at": "2026-10-01T08:18:32.648Z",
          "updated_at": "2026-10-03T04:23:32.493Z"
        },
        "description_available": false,
        "entity_type": "StixFile",
        "id": "942995af-f4f7-4064-a03c-d05be3983eab",
        "is_inferred": false,
        "labels": [
          "citrix netscaler",
          "citrixbleed",
          "command injection",
          "cve-2025-5777",
          "cve-2026-88771",
          "pre-disclosure attack",
          "rce",
          "webshell",
          "zero-day exploitation"
        ],
        "lang": null,
        "name": null,
        "objectMarking": [
          {
            "definition": "TLP:CLEAR",
            "definition_type": "TLP"
          }
        ],
        "objectOrganization": [],
        "references": [],
        "restrict_access": false,
        "revoked": false,
        "scope": "report",
        "source_url": "https://www.greynoise.io/blog/swarming-against-citrix-0-day-exploitation",
        "standard_id": "file--ee96d752-c4b8-57a3-b0d5-1f10029cbda5",
        "type": "StixFile"
      },
      {
        "__typename": "IPv4Addr",
        "aliases": [],
        "attributes": {},
        "authorized_members": [],
        "confidence": null,
        "created_by": null,
        "dates": {
          "created_at": "2026-10-01T08:18:32.096Z",
          "updated_at": "2026-10-01T08:18:32.396Z"
        },
        "description_available": false,
        "entity_type": "IPv4-Addr",
        "id": "b4e84aee-8271-4859-b04e-3dfaf624af65",
        "is_inferred": false,
        "labels": [
          "citrix netscaler",
          "citrixbleed",
          "command injection",
          "cve-2025-5777",
          "cve-2026-88771",
          "pre-disclosure attack",
          "rce",
          "webshell",
          "zero-day exploitation"
        ],
        "lang": null,
        "name": null,
        "objectMarking": [
          {
            "definition": "TLP:CLEAR",
            "definition_type": "TLP"
          }
        ],
        "objectOrganization": [],
        "references": [],
        "restrict_access": false,
        "revoked": false,
        "scope": "report",
        "source_url": "https://www.greynoise.io/blog/swarming-against-citrix-0-day-exploitation",
        "standard_id": "ipv4-addr--de3dbd7a-1ab9-5b57-aa0d-62dfe8bfdf38",
        "type": "IPv4Addr"
      },
      {
        "__typename": "Vulnerability",
        "aliases": [],
        "attributes": {},
        "authorized_members": [],
        "confidence": 80,
        "created_by": null,
        "dates": {
          "created": "2026-09-27T00:00:00.000Z",
          "created_at": "2026-09-27T20:47:14.970Z",
          "modified": "2026-10-01T08:06:31.181Z",
          "updated_at": "2026-10-01T08:06:31.181Z"
        },
        "description_available": true,
        "entity_type": "Vulnerability",
        "id": "c0f8d113-129e-4f2c-a0c5-80d76dfc4179",
        "is_inferred": false,
        "labels": [],
        "lang": "en",
        "name": "CVE-2026-88771",
        "objectMarking": [
          {
            "definition": "TLP:CLEAR",
            "definition_type": "TLP"
          }
        ],
        "objectOrganization": [],
        "references": [
          {
            "external_id": "CVE-2026-88771",
            "id": "06c9dd90-7190-465a-b4e4-1dfde14bd056",
            "source_name": "NIST NVD",
            "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-88771"
          }
        ],
        "restrict_access": false,
        "revoked": false,
        "scope": "report",
        "source_url": "https://www.greynoise.io/blog/swarming-against-citrix-0-day-exploitation",
        "standard_id": "vulnerability--ffd248e0-8f5c-5fa9-8a08-bf788da49f49",
        "type": "Vulnerability"
      }
    ],
    "direct_relationships": [
      {
        "__typename": "StixCoreRelationship",
        "authorized_members": [],
        "confidence": 50,
        "created_by": null,
        "dates": {
          "created": "2026-10-01T08:06:31.307Z",
          "created_at": "2026-10-01T08:18:46.291Z",
          "modified": "2026-10-01T08:18:46.499Z",
          "start_time": "1970-01-01T00:00:00.000Z",
          "stop_time": "5138-11-16T09:46:40.000Z",
          "updated_at": "2026-10-01T08:18:46.499Z"
        },
        "description_available": false,
        "entity_type": "based-on",
        "fromId": "0326881c-fc3e-4d59-a34d-eb710bea46ac",
        "from_id": "0326881c-fc3e-4d59-a34d-eb710bea46ac",
        "from_name": null,
        "from_type": "Indicator",
        "id": "a4455215-da27-431f-a691-adf05e3e39f0",
        "is_inferred": false,
        "objectMarking": [
          {
            "definition": "TLP:CLEAR",
            "definition_type": "TLP"
          }
        ],
        "objectOrganization": [],
        "references": [],
        "relationship_type": "based-on",
        "restrict_access": false,
        "revoked": false,
        "scope": "report",
        "source_url": "https://www.greynoise.io/blog/swarming-against-citrix-0-day-exploitation",
        "standard_id": "relationship--554fa0a7-e29c-5ef4-83d1-391107c14f7a",
        "toId": "b4e84aee-8271-4859-b04e-3dfaf624af65",
        "to_id": "b4e84aee-8271-4859-b04e-3dfaf624af65",
        "to_name": null,
        "to_type": "IPv4Addr"
      },
      {
        "__typename": "StixCoreRelationship",
        "authorized_members": [],
        "confidence": 50,
        "created_by": null,
        "dates": {
          "created": "2026-10-01T08:06:31.311Z",
          "created_at": "2026-10-01T08:18:46.457Z",
          "modified": "2026-10-03T08:11:58.099Z",
          "start_time": "1970-01-01T00:00:00.000Z",
          "stop_time": "5138-11-16T09:46:40.000Z",
          "updated_at": "2026-10-03T08:11:58.099Z"
        },
        "description_available": false,
        "entity_type": "based-on",
        "fromId": "03bc7fec-bed9-45b5-8871-9dfc726427a7",
        "from_id": "03bc7fec-bed9-45b5-8871-9dfc726427a7",
        "from_name": null,
        "from_type": "Indicator",
        "id": "ee5b5a49-862c-4d3c-84d5-aa7ddee6e54a",
        "is_inferred": false,
        "objectMarking": [
          {
            "definition": "TLP:CLEAR",
            "definition_type": "TLP"
          }
        ],
        "objectOrganization": [],
        "references": [],
        "relationship_type": "based-on",
        "restrict_access": false,
        "revoked": false,
        "scope": "report",
        "source_url": "https://www.greynoise.io/blog/swarming-against-citrix-0-day-exploitation",
        "standard_id": "relationship--c3048518-47de-55df-a272-ed25e8e0d006",
        "toId": "942995af-f4f7-4064-a03c-d05be3983eab",
        "to_id": "942995af-f4f7-4064-a03c-d05be3983eab",
        "to_name": null,
        "to_type": "StixFile"
      }
    ],
    "iocs": [
      {
        "classification": "indicator",
        "confidence": 50,
        "context": "Objet Indicator explicitement associé au rapport source.",
        "defanged": "149[.]104[.]78[.]141",
        "description_available": false,
        "object_id": "0326881c-fc3e-4d59-a34d-eb710bea46ac",
        "object_ids": [
          "0326881c-fc3e-4d59-a34d-eb710bea46ac",
          "b4e84aee-8271-4859-b04e-3dfaf624af65"
        ],
        "source_objects": [
          {
            "classification": "indicator",
            "confidence": 50,
            "context": "Objet Indicator explicitement associé au rapport source.",
            "object_id": "0326881c-fc3e-4d59-a34d-eb710bea46ac",
            "valid_from": "2026-10-01T04:37:09.000Z",
            "valid_until": "2026-10-21T10:11:48.434Z",
            "validity_status": "active",
            "value": "149.104.78.141"
          },
          {
            "classification": "observable",
            "confidence": null,
            "context": "Objet IPv4Addr explicitement associé au rapport source.",
            "object_id": "b4e84aee-8271-4859-b04e-3dfaf624af65",
            "valid_from": null,
            "valid_until": null,
            "validity_status": "undated",
            "value": "149.104.78.141"
          }
        ],
        "source_url": "https://www.greynoise.io/blog/swarming-against-citrix-0-day-exploitation",
        "type": "ipv4",
        "valid_from": "2026-10-01T04:37:09.000Z",
        "valid_until": "2026-10-21T10:11:48.434Z",
        "validity_status": "active",
        "value": "149.104.78.141"
      },
      {
        "classification": "indicator",
        "confidence": 50,
        "context": "Objet Indicator explicitement associé au rapport source.",
        "defanged": "6f5a2a452a7901323abd21879c6cecccb47c06aeeaccb1b467212f3b11e4b1e7",
        "description_available": false,
        "object_id": "03bc7fec-bed9-45b5-8871-9dfc726427a7",
        "object_ids": [
          "03bc7fec-bed9-45b5-8871-9dfc726427a7",
          "942995af-f4f7-4064-a03c-d05be3983eab"
        ],
        "source_objects": [
          {
            "classification": "indicator",
            "confidence": 50,
            "context": "Objet Indicator explicitement associé au rapport source.",
            "object_id": "03bc7fec-bed9-45b5-8871-9dfc726427a7",
            "valid_from": "2026-10-01T04:37:09.000Z",
            "valid_until": "2027-07-18T15:46:53.557Z",
            "validity_status": "active",
            "value": "6f5a2a452a7901323abd21879c6cecccb47c06aeeaccb1b467212f3b11e4b1e7"
          },
          {
            "classification": "observable",
            "confidence": null,
            "context": "Objet StixFile explicitement associé au rapport source.",
            "object_id": "942995af-f4f7-4064-a03c-d05be3983eab",
            "valid_from": null,
            "valid_until": null,
            "validity_status": "undated",
            "value": "6f5a2a452a7901323abd21879c6cecccb47c06aeeaccb1b467212f3b11e4b1e7"
          }
        ],
        "source_url": "https://www.greynoise.io/blog/swarming-against-citrix-0-day-exploitation",
        "type": "sha256",
        "valid_from": "2026-10-01T04:37:09.000Z",
        "valid_until": "2027-07-18T15:46:53.557Z",
        "validity_status": "active",
        "value": "6f5a2a452a7901323abd21879c6cecccb47c06aeeaccb1b467212f3b11e4b1e7"
      }
    ],
    "mentioned": [
      {
        "confidence": 80,
        "evidence_id": "614bebb8-3dbf-4531-8ef3-975a65e98e28",
        "name": "CVE-2025-5777",
        "role": "mentionné",
        "type": "Vulnerability"
      },
      {
        "confidence": 80,
        "evidence_id": "c0f8d113-129e-4f2c-a0c5-80d76dfc4179",
        "name": "CVE-2026-88771",
        "role": "mentionné",
        "type": "Vulnerability"
      }
    ],
    "mitre": {
      "associated_repertoire": [],
      "direct_techniques": []
    },
    "report_metadata": {
      "authorized_members": [],
      "confidence": 50,
      "created_by": null,
      "dates": {
        "created": "2026-10-01T04:37:07.981Z",
        "created_at": "2026-10-01T08:19:12.412Z",
        "modified": "2026-10-01T08:19:13.830Z",
        "published": "2026-10-01T04:37:07.981Z",
        "updated_at": "2026-10-01T08:19:13.830Z"
      },
      "description_available": true,
      "id": "343c9b18-4b6a-44c0-b92a-cce0b5865b9e",
      "is_inferred": false,
      "labels": [
        "citrix netscaler",
        "citrixbleed",
        "command injection",
        "cve-2025-5777",
        "cve-2026-88771",
        "pre-disclosure attack",
        "rce",
        "webshell",
        "zero-day exploitation"
      ],
      "lang": "en",
      "name": "Swarming Against Citrix 0-Day Exploitation",
      "objectMarking": [
        {
          "definition": "TLP:CLEAR",
          "definition_type": "TLP"
        }
      ],
      "objectOrganization": [],
      "published": "2026-10-01T04:37:07.981Z",
      "references": [
        {
          "external_id": null,
          "id": "3e7aa33c-2140-4d48-a191-2fc8d632c3c4",
          "source_name": "alien-vault",
          "url": "https://www.greynoise.io/blog/swarming-against-citrix-0-day-exploitation"
        },
        {
          "external_id": "6abde373c68b5d048accac49",
          "id": "7dd65eb7-cd50-4f89-8289-c185cd6f9569",
          "source_name": "alien-vault",
          "url": "https://otx.alienvault.com/pulse/6abde373c68b5d048accac49"
        }
      ],
      "report_types": [
        "threat-report"
      ],
      "restrict_access": false,
      "source_url": "https://www.greynoise.io/blog/swarming-against-citrix-0-day-exploitation"
    },
    "targets": [],
    "techniques": [],
    "vulnerabilities": [
      "CVE-2025-5777",
      "CVE-2026-88771"
    ]
  },
  "report_id": "343c9b18-4b6a-44c0-b92a-cce0b5865b9e",
  "schema_version": 1,
  "selected_date": "2026-10-01",
  "source_url": "https://www.greynoise.io/blog/swarming-against-citrix-0-day-exploitation"
}
