Breaking
Cyber CrimeDeveloping Story

NetScaler Flaw Weaponized for Deep Access

LevelBlue says attackers exploited a critical NetScaler bug to plant web shells, create superuser accounts, and exfiltrate configuration data.

··1 hour ago·5 min read
a close up of a computer with green lights
Photo by Tyler on Unsplash

Attackers exploiting a critical NetScaler flaw are not stopping at a simple proof-of-concept. According to analysis from LevelBlue's Threat Hunt Operations & Research (THOR) team, the post-exploitation activity observed across multiple customer environments goes well beyond basic validation — dropping web shells, creating superuser accounts, and attempting to steal configuration data.

The activity centers on CVE-2026-88771, a pre-authentication command injection vulnerability in Citrix NetScaler ADC and NetScaler Gateway. With a CVSS score of 9.5, the flaw allows an unauthenticated attacker to run arbitrary commands on affected appliances.

Tracking the initial breach attempts

LevelBlue said it identified malicious NetScaler authentication events containing attacker-controlled usernames designed to weaponize the vulnerability. One of the most consistent characteristics across the identified events was authentication data containing variations of the pitboss and NSPPE strings associated with exploitation of CVE-2026-88771.

Other attempts used common tools like curl or wget to fetch additional payloads from external servers or to extract NetScaler configuration data. The researchers listed several command-and-control endpoints observed in the activity:

  • 64.94.85[.]67:443/update_c08937.pl
  • 31.56.197[.]72:9090/lula
  • 31.56.197[.]72:9090/lula
  • 23.27.143[.]20:9000/main.py

The pattern suggests a deliberate effort to move from checking for command execution to retrieving and running second-stage tools, according to LevelBlue.

Second-stage payloads and their capabilities

Two notable second-stage payloads were highlighted in the analysis. The first, a Python script named main.py, establishes a reverse shell to 45.141.21[.]130 over TCP port 443. It also searches for running processes associated with "/var/python/bin/customsnmpd" and forcefully terminates them by issuing a "kill -9" command.

The second payload, a Perl script named update_c08937.pl, carries a broader set of post-exploitation duties. It modifies "/flash/nsconfig/ns.conf" to create a local account named sec_monitor and assigns it the superuser role. It then archives the "/flash/nsconfig" directory into "/tmp/update_result_3567cs.tgz" and uploads the resulting archive containing NetScaler configuration data to 64.94.85[.]67:443. After the upload, the script deletes the archive and erases itself to reduce the forensic footprint on disk.

The same Perl script changes the permissions of "/bin/sh" to 6555 and deploys a PHP web shell at "/var/netscaler/logon/LogonPoint/.local_journal" for remote command execution and file upload and download. It also modifies "/etc/httpd.conf" to enable PHP execution and map the web shell to URLs resembling legitimate NetScaler CSS resources — a detail that corroborates activity observed by GreyNoise.

Exploitation timeline and disclosure context

CVE-2026-88771, along with CVE-2026-88772, was disclosed last week after reports that the Dutch National Cyber Security Centre (NCSC-NL) reportedly sent a pre-notification to organizations in the Netherlands urging them to shut down their appliances citing active exploitation. As of the writing of the LevelBlue analysis, there were no details about who is behind the efforts.

The disclosure came a day after Mandiant Consulting and Google Threat Intelligence Group (GTIG) said dozens of organizations have been impacted by attacks exploiting CVE-2026-88772 to deliver PHP web shells, like WHIPSHOT, and a Python tunneler dubbed SLAPSHOT.

What the observed commands reveal

LevelBlue noted that the range of commands seen in the wild shows a progression beyond initial access.

"Taken together, the observed commands demonstrate activity extending beyond basic vulnerability validation," LevelBlue said. "The attempts included payload retrieval and execution as well as collection and staging of NetScaler configuration data."

— LevelBlue

In a separate comment on the mix of techniques, the team added:

"While some attempts used commands such as whoami to test command execution, others attempted to retrieve additional payloads, collect NetScaler configuration data, establish reverse shells, create privileged accounts, and deploy web shells," LevelBlue said.

— LevelBlue

Persistence and stealth mechanisms

The creation of the sec_monitor account with superuser privileges stands out as a durable foothold. By modifying the NetScaler configuration file, the script ensures the account survives reboots and blends into legitimate administrative access. The deletion of the uploaded archive and the self-erasure of the Perl script are textbook anti-forensic moves, though the configuration changes themselves remain in place.

The web shell's placement is equally calculated. By mapping it to URLs that look like normal NetScaler CSS resources, the attackers aim to make the shell harder to spot in web logs or casual traffic inspections. Enabling PHP execution via "/etc/httpd.conf" is a prerequisite that turns an otherwise static path into an interactive backdoor.

Reverse shell and process tampering

The Python payload's reverse shell to 45.141.21[.]130 over port 443 uses a common port to blend with typical HTTPS traffic. Its habit of killing processes tied to "/var/python/bin/customsnmpd" suggests an attempt to disable legitimate monitoring or SNMP-related services that might interfere with the attackers' operations or alert defenders.

These actions align with the broader pattern described by LevelBlue: a mix of lightweight reconnaissance (such as whoami) and heavier, stateful payloads that establish persistent remote access.

What defenders should watch for

NetScaler authentication logs remain a critical source of evidence. Unusual usernames containing pitboss or NSPPE strings, unexpected outbound connections to the IP addresses listed above, and modifications to configuration files like "/flash/nsconfig/ns.conf" or "/etc/httpd.conf" are all potential indicators of compromise.

File-system anomalies are also worth flagging: the presence of "/tmp/update_result_3567cs.tgz", a PHP file at "/var/netscaler/logon/LogonPoint/.local_journal", or permission changes on "/bin/sh" to 6555. Because the Perl script attempts to erase itself, forensic analysis may need to rely on memory, network logs, or NetScaler's own configuration history rather than the dropped files themselves.

Why this matters for NetScaler operators

The gap between a proof-of-concept and a full-fledged intrusion is often measured in hours, and the LevelBlue findings suggest that gap has already closed for CVE-2026-88771. For organizations running NetScaler ADC or Gateway, the immediate implication is that patching alone may not be enough if a system was already compromised. A configuration review for unexpected local accounts, a sweep for web shells on file paths that mimic CSS, and an audit of outbound traffic to the listed IPs are logical next steps.

The involvement of the Dutch NCSC-NL pre-notification and the parallel Mandiant and GTIG reports on CVE-2026-88772 point to a broader campaign against NetScaler appliances. The techniques observed — reverse shells, superuser accounts, and stealthy web shells — are not opportunistic smash-and-grab tactics. They are the building blocks of a sustained presence. That raises the stakes for any organization that treats NetScaler as a simple remote access gateway rather than a high-value target that needs continuous monitoring.

#citrix#netscaler#vulnerability#web shell#exploitation

Sources

Iliyas

Founder & Editor, Xploitwire

This article was written and reviewed against the sources listed above before publication, under editorial policies set by Iliyas. Read our Editorial Policy →

← Back to all stories