STAC4663 is a threat group associated with ransomware intrusions exploiting unpatched Citrix NetScaler ADC and Gateway systems. The group has been observed abusing CVE-2023-3519, a vulnerability that was exploited as a zero-day, to obtain initial access and establish persistent access on exposed appliances. In documented activity from August 2023, STAC4663 used this access to conduct domain-wide attacks inside victim environments and injected payloads into legitimate Windows processes, including core system management components, indicating post-compromise tradecraft focused on defense evasion and broad enterprise compromise. High-confidence reporting links the group to ransomware attacks, but publicly available detail in this context does not identify a broader alias set, sub-groups, or a confirmed national affiliation.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.