At-Bay reported evidence suggesting that the Royal ransomware group exploited CVE-2022-27510, a critical authentication bypass vulnerability affecting Citrix Application Delivery Controller (ADC) and Citrix Gateway, to gain initial access to victims. Citrix disclosed the flaw on November 8, 2022, with no exploitation reported at disclosure. Intelligence obtained by At-Bay in the first week of 2023—including security scans, insurance claims data, and other sources—pointed to suspected exploitation before a public exploit was available. The assessment did not establish exploitation as confirmed.
Royal primarily targeted U.S. companies, and its data leak site suggested a concentration of manufacturing victims, although At-Bay assessed that the group attacked opportunistically across industries. At-Bay urged organizations running affected Citrix products to patch immediately and follow Citrix’s mitigation guidance. Defenders should use the vendor security bulletin to identify affected deployments and required fixes, and investigate potentially exposed systems for signs of unauthorized access rather than treating patching alone as evidence that a deployment is uncompromised.

TTPs, infrastructure, and targeting history in one profile.
4 events from the most recent confirmed update back to the earliest known activity.
During the first week of 2023, At-Bay obtained information suggesting Royal was actively exploiting CVE-2022-27510 for initial access in ransomware attacks. Its assessment drew on security scans, insurance claims, and other intelligence, and indicated suspected exploitation before a public exploit was available.
Citrix announced CVE-2022-27510, a critical authentication bypass vulnerability affecting Citrix Application Delivery Controller and Citrix Gateway. No exploitation in the wild had been reported at disclosure.
The Royal ransomware group emerged in January 2022.
Following Citrix's disclosure, At-Bay began assessing exposure and identifying potentially vulnerable businesses.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.