Citrix NetScaler Post-Exploitation Payload Creates Superuser, Maps Web Shell to CSS-Like URLs
Citrix NetScaler exploited via CVE-2026-88771 for post-exploitation, web shells, and data theft.
Summary
Threat actors are actively exploiting a critical command injection vulnerability (CVE-2026-88771) in Citrix NetScaler ADC and Gateway. The exploitation allows for the deployment of web shells, creation of superuser accounts, and theft of configuration data, with attackers attempting to mask malicious activity by mapping web shells to CSS-like URLs.
Full text
Citrix NetScaler Post-Exploitation Payload Creates Superuser, Maps Web Shell to CSS-Like URLs Ravie LakshmananOct 01, 2026Vulnerability / Web Security Threat actors have been observed exploiting a critical pre-authentication command injection vulnerability in Citrix NetScaler ADC and NetScaler Gateway to drop web shells and attempt theft of configuration data. LevelBlue's Threat Hunt Operations & Research (THOR) team, which analyzed the exploitation activity across multiple customer environments, said it identified malicious NetScaler authentication events containing attacker-controlled usernames designed to weaponize CVE-2026-88771. CVE-2026-88771 (CVSS score: 9.5) is an improper input validation vulnerability that could allow an unauthenticated attacker to execute arbitrary commands. The security flaw, along with CVE-2026-88772, was disclosed last week after reports that the Dutch National Cyber Security Centre (NCSC-NL) reportedly sent a pre-notification to organizations in the Netherlands that urged organizations to shut their appliances down, citing active exploitation. As of writing, there are currently no details about who is behind these efforts. "One of the most consistent characteristics across the identified events was attacker-controlled authentication data containing variations of the pitboss and NSPPE strings associated with exploitation of CVE-2026-88771," LevelBlue said. Other attempts have been observed using curl or wget to fetch additional payloads from external servers, or extract NetScaler configuration data - 64.94.85[.]67:443/update_c08937.pl 31.56.197[.]72:9090/lula 31.56.197[.]72:9090/lula 23.27.143[.]20:9000/main.py "Taken together, the observed commands demonstrate activity extending beyond basic vulnerability validation," LevelBlue said. "The attempts included payload retrieval and execution as well as collection and staging of NetScaler configuration data." Notable among the second-stage payloads is a Python script ("main.py") that's designed to establish a reverse shell to "45.141.21[.]130" over TCP port 443. It also searches for running processes associated with "/var/python/bin/customsnmpd" and forcefully terminates them by issuing a "kill -9" command. Another second-stage payload, "update_c08937.pl," is a Perl script with several post-exploitation capabilities - Modify "/flash/nsconfig/ns.conf" to create a local account named sec_monitor and assign it the superuser role. Archive the "/flash/nsconfig" directory into "/tmp/update_result_3567cs.tgz" and upload the resulting archive containing NetScaler configuration data to "64.94.85[.]67:443." The script then deletes the archive and erases itself to reduce the forensic footprint on disk. Change the permissions of "/bin/sh" to 6555 and deploy a PHP web shell at "/var/netscaler/logon/LogonPoint/.local_journal" for remote command execution and file upload and download. Modify "/etc/httpd.conf" to enable PHP execution and map the web shell to URLs resembling legitimate NetScaler CSS resources, corroborating activity observed by GreyNoise. "While some attempts used commands such as whoami to test command execution, others attempted to retrieve additional payloads, collect NetScaler configuration data, establish reverse shells, create privileged accounts, and deploy web shells," LevelBlue said. The disclosure comes a day after Mandiant Consulting and Google Threat Intelligence Group (GTIG) said dozens of organizations have been impacted by attacks exploiting CVE-2026-88772 to deliver PHP web shells, like WHIPSHOT, and a Python tunneler dubbed SLAPSHOT. Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post. SHARE Tweet Share Share Share SHARE Citrix, Malware, network security, Vulnerability, Web Security ⚡ Top Stories This Week Roundcube Pre-Auth SQL Injection Flaw Actively Exploited in the Wild Cloudflare Fixes Flaw That Let One Container Read Another Customer's Leftover Disk Data Unpatched OnePlus Flaws Let Installed Android Apps Gain Root Without Permissions ThreatsDay: AI Search Poisoning, AI Coding Tool Leaking Repos, One-Click Code Execution and 13 More Stories Placeholder third-party[.]com Referenced Across 1,700+ Repositories Now Serves Malicious Content OpenAI Agent Bypassed Australian Medicare Portal Controls to Access Non-Public Files A Leaked GitLab Issue Email Address Lets Anyone Push Code and Run CI Jobs as You MikroTrick Chain Let Attackers Take Over MikroTik Routers Without a Password or SSH Key New cPanel Flaw Lets a Hosting Account Run Code as Root, Take Full Server Control Exploit Released for Unpatched Ubuntu Linux Flaw Enabling Host-Root Container Escape F5 Patches Critical BIG-IP APM Zero-Day Exploited for Unauthenticated RCE on OAuth Servers Critical Next.js ImageResponse Flaw Can Lead to Server Code Execution via Crafted SVG Input ShinyHunters Claims FBI Breach, Says It Stole Data on Agents and Job Applicants Check Point Warns of Management Server Zero-Day Exploited in Targeted Attacks WordPress Issues Patch for Critical Flaw That Can Enable Code Execution on Some Servers Researcher Drops BigDiskBuster Zero-Day PoC That Blocks Microsoft Defender Updates New CVSS 10.0 VeloCloud Orchestrator Flaw Actively Exploited in Certificate-Based Setups New Linux Kernel Flaw Gives ARM64 KVM Guests Read-Write Access to Host Memory SharePoint Flaw Initially Listed as Spoofing by Microsoft Enables Authenticated RCE One Hidden Meta Muse Setting Could Let Attackers Turn the AI Assistant Into a Backdoor WordPress Comment2Shell Flaw Can Turn Anonymous Comment XSS Into RCE via Admin Session Zyxel and Veeam Flaws Under Active Exploitation With Command and SYSTEM Access Beyond ISO 27001: Building a Risk Program That Can Keep Up With AI Secrets Sprawl Is an Identity Problem That AI Just Made Impossible to Ignore ⭐ Featured Resources Validation Summit ’26: See How Pen Testing, Exposure Validation and BAS Work Together Red Teams: Learn How Attack Path Chaining Changes Automated Security Testing Turn Threat Intelligence Into Verified Risk With Threat-Led Penetration Testing Deploy Browser Security Monitoring in Minutes With a Single Header
Indicators of Compromise
- cve — CVE-2026-88771
- cve — CVE-2026-88772
- ip — 64.94.85.67
- url — http://64.94.85.67:443/update_c08937.pl
- ip — 31.56.197.72
- url — http://31.56.197.72:9090/lula
- ip — 23.27.143.20
- url — http://23.27.143.20:9000/main.py
- ip — 45.141.21.130
- malware — WHIPSHOT
- malware — SLAPSHOT