H-ISAC TLP White Threat: APT5: Citrix Application Delivery Controller (ADC) Threat Hunting Guidance

December 13, 2022

On December 13, 2022, the National Security Agency (NSA) released a Cybersecurity Advisory (CSA) to provide threat hunting guidance for Citrix Application Delivery Controller (ADC) deployments. APT5, also known as UNC2630 and MANGANESE, is a Chinese state-sponsored group that has demonstrated targeting capabilities against environments with Citrix ADC deployments leading to illegitimate access to targeted organizations via the bypass of normal authentication controls.

NSA recommends organizations hosting Citrix ADC environments take the steps provided as part of their investigation. The detection mechanisms should be treated as independent ways of identifying potentially malicious activity on impacted systems. Findings may vary based on the environment and the stage of the detected activity. As such, NSA recommends investigating any positive result even if other detections return no findings.

View the detailed report below. 

For help with Cybersecurity and Risk Advisory Services exclusively for AHA members, contact:

John Riggi

National Advisor for Cybersecurity and Risk, AHA

jriggi@aha.org

(O) +1 202 626 2272