NetScaler Flaw Weaponized for Deep Access
LevelBlue says attackers exploited a critical NetScaler bug to plant web shells, create superuser accounts, and exfiltrate configuration data.
Attackers exploiting a critical NetScaler flaw are not stopping at a simple proof-of-concept. According to analysis from LevelBlue's Threat Hunt Operations & Research (THOR) team, the post-exploitation activity observed across multiple customer environments goes well beyond basic validation — dropping web shells, creating superuser accounts, and attempting to steal configuration data.
The activity centers on CVE-2026-88771, a pre-authentication command injection vulnerability in Citrix NetScaler ADC and NetScaler Gateway. With a CVSS score of 9.5, the flaw allows an unauthenticated attacker to run arbitrary commands on affected appliances.
Tracking the initial breach attempts
LevelBlue said it identified malicious NetScaler authentication events containing attacker-controlled usernames designed to weaponize the vulnerability. One of the most consistent characteristics across the identified events was authentication data containing variations of the pitboss and NSPPE strings associated with exploitation of CVE-2026-88771.
Other attempts used common tools like curl or wget to fetch additional payloads from external servers or to extract NetScaler configuration data. The researchers listed several command-and-control endpoints observed in the activity:
- 64.94.85[.]67:443/update_c08937.pl
- 31.56.197[.]72:9090/lula
- 31.56.197[.]72:9090/lula
- 23.27.143[.]20:9000/main.py
The pattern suggests a deliberate effort to move from checking for command execution to retrieving and running second-stage tools, according to LevelBlue.
Second-stage payloads and their capabilities
Two notable second-stage payloads were highlighted in the analysis. The first, a Python script named main.py, establishes a reverse shell to 45.141.21[.]130 over TCP port 443. It also searches for running processes associated with "/var/python/bin/customsnmpd" and forcefully terminates them by issuing a "kill -9" command.
The second payload, a Perl script named update_c08937.pl, carries a broader set of post-exploitation duties. It modifies "/flash/nsconfig/ns.conf" to create a local account named sec_monitor and assigns it the superuser role. It then archives the "/flash/nsconfig" directory into "/tmp/update_result_3567cs.tgz" and uploads the resulting archive containing NetScaler configuration data to 64.94.85[.]67:443. After the upload, the script deletes the archive and erases itself to reduce the forensic footprint on disk.
The same Perl script changes the permissions of "/bin/sh" to 6555 and deploys a PHP web shell at "/var/netscaler/logon/LogonPoint/.local_journal" for remote command execution and file upload and download. It also modifies "/etc/httpd.conf" to enable PHP execution and map the web shell to URLs resembling legitimate NetScaler CSS resources — a detail that corroborates activity observed by GreyNoise.
Exploitation timeline and disclosure context
CVE-2026-88771, along with CVE-2026-88772, was disclosed last week after reports that the Dutch National Cyber Security Centre (NCSC-NL) reportedly sent a pre-notification to organizations in the Netherlands urging them to shut down their appliances citing active exploitation. As of the writing of the LevelBlue analysis, there were no details about who is behind the efforts.
The disclosure came a day after Mandiant Consulting and Google Threat Intelligence Group (GTIG) said dozens of organizations have been impacted by attacks exploiting CVE-2026-88772 to deliver PHP web shells, like WHIPSHOT, and a Python tunneler dubbed SLAPSHOT.
What the observed commands reveal
LevelBlue noted that the range of commands seen in the wild shows a progression beyond initial access.
"Taken together, the observed commands demonstrate activity extending beyond basic vulnerability validation," LevelBlue said. "The attempts included payload retrieval and execution as well as collection and staging of NetScaler configuration data."
— LevelBlue
In a separate comment on the mix of techniques, the team added:
"While some attempts used commands such as whoami to test command execution, others attempted to retrieve additional payloads, collect NetScaler configuration data, establish reverse shells, create privileged accounts, and deploy web shells," LevelBlue said.
— LevelBlue
Persistence and stealth mechanisms
The creation of the sec_monitor account with superuser privileges stands out as a durable foothold. By modifying the NetScaler configuration file, the script ensures the account survives reboots and blends into legitimate administrative access. The deletion of the uploaded archive and the self-erasure of the Perl script are textbook anti-forensic moves, though the configuration changes themselves remain in place.
The web shell's placement is equally calculated. By mapping it to URLs that look like normal NetScaler CSS resources, the attackers aim to make the shell harder to spot in web logs or casual traffic inspections. Enabling PHP execution via "/etc/httpd.conf" is a prerequisite that turns an otherwise static path into an interactive backdoor.
Reverse shell and process tampering
The Python payload's reverse shell to 45.141.21[.]130 over port 443 uses a common port to blend with typical HTTPS traffic. Its habit of killing processes tied to "/var/python/bin/customsnmpd" suggests an attempt to disable legitimate monitoring or SNMP-related services that might interfere with the attackers' operations or alert defenders.
These actions align with the broader pattern described by LevelBlue: a mix of lightweight reconnaissance (such as whoami) and heavier, stateful payloads that establish persistent remote access.
What defenders should watch for
NetScaler authentication logs remain a critical source of evidence. Unusual usernames containing pitboss or NSPPE strings, unexpected outbound connections to the IP addresses listed above, and modifications to configuration files like "/flash/nsconfig/ns.conf" or "/etc/httpd.conf" are all potential indicators of compromise.
File-system anomalies are also worth flagging: the presence of "/tmp/update_result_3567cs.tgz", a PHP file at "/var/netscaler/logon/LogonPoint/.local_journal", or permission changes on "/bin/sh" to 6555. Because the Perl script attempts to erase itself, forensic analysis may need to rely on memory, network logs, or NetScaler's own configuration history rather than the dropped files themselves.
Why this matters for NetScaler operators
The gap between a proof-of-concept and a full-fledged intrusion is often measured in hours, and the LevelBlue findings suggest that gap has already closed for CVE-2026-88771. For organizations running NetScaler ADC or Gateway, the immediate implication is that patching alone may not be enough if a system was already compromised. A configuration review for unexpected local accounts, a sweep for web shells on file paths that mimic CSS, and an audit of outbound traffic to the listed IPs are logical next steps.
The involvement of the Dutch NCSC-NL pre-notification and the parallel Mandiant and GTIG reports on CVE-2026-88772 point to a broader campaign against NetScaler appliances. The techniques observed — reverse shells, superuser accounts, and stealthy web shells — are not opportunistic smash-and-grab tactics. They are the building blocks of a sustained presence. That raises the stakes for any organization that treats NetScaler as a simple remote access gateway rather than a high-value target that needs continuous monitoring.
Sources
- The Hacker News Original source
Continue Reading
Star Blizzard Refines Phishing Delivery
Microsoft says the Russian state actor's RedFlick chain cuts victim interaction down to a single click while scaling phishing across 100+ targets.
Zimbra Bug Exploited for Mailbox Theft
Microsoft says attackers chained a patched Zimbra command-injection flaw into web shells, credential theft and cloud exfiltration.
Dual RMM Phishing Attack Evades Defenses
Microsoft says phishing emails hid a legitimate MSP360 installer behind meeting and PDF lures, then used it to install ScreenConnect as a redundant remote-access channel.