Recommended Free Tools
iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more
In 2023, attackers exploited the critical CVE-2023-3519 flaw in unpatched Citrix NetScaler ADC and Gateway appliances. Sophos assessed that the activity was likely linked to FIN8 based on similarities in tactics and infrastructure, but the public evidence did not conclusively identify FIN8 as the operator. The distinction matters: observed intrusion techniques are not the same as confirmed attribution.
What happened in the 2023 NetScaler attacks?
Dark Reading reported on August 29, 2023, that attackers were exploiting CVE-2023-3519 against vulnerable NetScaler ADC and Gateway systems. Sophos described a mid-August intrusion in which the flaw provided a code-injection path as part of a broader attack. The reported activity included payload injection, obfuscated PowerShell, and PHP web shells.
| # | Preview | Product | Price | |
|---|---|---|---|---|
| 1 |
|
Citrix NetScaler MPX 7500/9500 (8x10/100/1000Base-T Copper Ethernet Ports) with 320GB Hard Disk... | $399.99 | Buy on Amazon |
The flaw was a remote code execution vulnerability. Contemporary reporting described it as unauthenticated and said exposed appliances could be at risk in certain VPN, ICA proxy, RDP proxy, or AAA configurations. Citrix disclosed the vulnerability on July 18, 2023, amid active exploitation and advised customers to update. Those are historical details; use Citrix’s bulletin for the affected-version information and remediation guidance applicable to a particular appliance.
Was FIN8 conclusively identified?
No. Sophos described overlap with activity attributed to FIN8, making a link an analytic assessment rather than a confirmed identification. Christopher Budd, Sophos director of threat intelligence, said: “Sophos has observed overlaps in this activity consistent with other published activity attributed to FIN8.” Accordingly, the evidence supports wording such as “likely linked to FIN8” or “consistent with FIN8-attributed activity,” not a definitive claim that FIN8 carried out the intrusion.
#1 Best Overall
- Citrix NetScaler MPX 7500/9500 (8x10/100/1000Base-T copper Ethernet ports)
What did attackers do after gaining access?
The reporting describes code and payload injection, obfuscated PowerShell, and PHP web shells, followed by activity characterized as a domain-wide attack. A web shell can let an attacker execute commands remotely. Its presence can also provide persistence, so applying a software update or rebooting an appliance does not by itself establish that an earlier compromise has been removed.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.How does the 2026 NetScaler guidance relate to the 2023 incident?
As of October 4, 2026, Citrix reports observed exploitation of CVE-2026-88771 and CVE-2026-88772 on unmitigated deployments. These are separate vulnerabilities from CVE-2023-3519, and the cited 2026 advisories do not attribute their exploitation to FIN8 or revise the 2023 attribution.
Citrix lists fixed release branches for the applicable products, including 14.1-73.37 and later and 13.1-64.23 and later. Those versions address the listed 2026 vulnerabilities; they should not be treated as a patch reference for CVE-2023-3519. Check the relevant Citrix bulletin for the exact appliance, release branch, and vulnerability.
The Tool Desk
Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →The Canadian Centre for Cyber Security’s October 3, 2026 update warns that persistence may remain after updates are installed. Its guidance includes using the NetScaler Console IOC tool, preserving logs and forensic evidence, checking processes, connections, scripts and web directories, correlating network and authentication telemetry, and following Citrix guidance. For suspected compromise, investigation and evidence preservation are important alongside remediation.
Quick Recap
What should an organization take away?
- The headline’s FIN8 connection is qualified: Sophos reported overlaps consistent with FIN8-attributed activity, not conclusive identification.
- The 2023 incident concerned exploitation of CVE-2023-3519 on vulnerable NetScaler ADC and Gateway systems.
- Reported techniques included payload injection, obfuscated PowerShell, and PHP web shells; patching alone does not prove that persistence has been removed.
- The active exploitation discussed in 2026 advisories concerns different CVEs. Follow the advisory for the specific flaw and investigate if compromise is suspected.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

