{"id":3299,"date":"2026-10-01T05:08:53","date_gmt":"2026-10-01T05:08:53","guid":{"rendered":"https:\/\/thedigitalfortress.us\/?p=3299"},"modified":"2026-10-01T05:08:53","modified_gmt":"2026-10-01T05:08:53","slug":"citrix-netscaler-post-exploitation-payload-creates-superuser-maps-web-shell-to-css-like-urls","status":"publish","type":"post","link":"https:\/\/thedigitalfortress.us\/?p=3299","title":{"rendered":"Citrix NetScaler Post-Exploitation Payload Creates Superuser, Maps Web Shell to CSS-Like URLs"},"content":{"rendered":"<div>\n<p><span class=\"p-author\"><i class=\"icon-font icon-user\">\ue804<\/i><span class=\"author\">Ravie Lakshmanan<\/span><i class=\"icon-font icon-calendar\">\ue802<\/i><span class=\"author\">Oct 01, 2026<\/span><\/span><span class=\"p-tags\">Vulnerability \/ Web Security<\/span><\/p>\n<\/div>\n<div id=\"articlebody\">\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjAuODp7WTARNyJa6hiyuveQ1LUgYlaYQXGDDfRAYUA7Zkwwb7vMriA7VIh5HmBJwWWR0kALhQkijvT43ke2ajjOQHk6YxQb2rAgsB0PYcbMKPdm-JezjILBH8j3kY29iATKhZLQhVIyAjwNj9XFBTeenqPCHM1AzKMKRCVlMME3jQs5yIYSoVtrbRnVSY7\/s1700-nu-rw-lo-l85-e365\/citrix-css-shell.jpg\" style=\"display: block;  text-align: center; clear: left; float: left;\"><\/a><\/div>\n<p>Threat actors have been observed exploiting a critical pre-authentication command injection vulnerability in Citrix NetScaler ADC and NetScaler Gateway to drop web shells and attempt theft of configuration data.<\/p>\n<p>LevelBlue&#8217;s Threat Hunt Operations &amp; Research (THOR) team, which analyzed the exploitation activity across multiple customer environments, said it identified malicious NetScaler authentication events containing attacker-controlled usernames designed to weaponize CVE-2026-88771.<\/p>\n<p>CVE-2026-88771 (CVSS score: 9.5) is an improper input validation vulnerability that could allow an unauthenticated attacker to execute arbitrary commands. <\/p>\n<p>The security flaw, along with CVE-2026-88772, was disclosed last week after reports that the Dutch National Cyber Security Centre (NCSC-NL) <a href=\"https:\/\/watchtowr.com\/intelligence\/citrix-netscaler-zero-day-vulnerabilities-faq\/\" target=\"_blank\">reportedly sent<\/a> a pre-notification to organizations in the Netherlands that urged organizations to shut their appliances down, citing active exploitation. As of writing, there are currently no details about who is behind these efforts.<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/trust-world-update-d\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhYq3TvePXpW0JIC7fXyv7A1W8KQqmb-AZqza2EuPyT0k8Nm5CwHYHISFLKXSKIAyR8JRtqEFQ4zx5jADiAkZKQ08nRWG1jCRV5YAbhKua7WaDdH1L6wsI-xOkoV4brlMfK44UwU-4Q1xqWg0uNN7sZkMCzci4RXYgWMNPHTtuKua7OR4oCbmxE10u0yKnR\/s728-nu-rw-lo-l85-e365\/tl-d.jpg\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>\u00abOne of the most consistent characteristics across the identified events was attacker-controlled authentication data containing variations of the pitboss and NSPPE strings associated with exploitation of CVE-2026-88771,\u00bb LevelBlue <a href=\"https:\/\/www.levelblue.com\/blogs\/spiderlabs-blog\/citrix-netscaler-cve-2026-88771-observed-exploitation-artifacts-and-hunt-indicators\" target=\"_blank\">said<\/a>.<\/p>\n<p>Other attempts have been observed using curl or wget to fetch additional payloads from external servers, or extract NetScaler configuration data &#8211;<\/p>\n<ul>\n<li>64.94.85[.]67:443\/update_c08937.pl<\/li>\n<li>31.56.197[.]72:9090\/lula<\/li>\n<li>31.56.197[.]72:9090\/lula<\/li>\n<li>23.27.143[.]20:9000\/main.py<\/li>\n<\/ul>\n<p>\u00abTaken together, the observed commands demonstrate activity extending beyond basic vulnerability validation,\u00bb LevelBlue said. \u00abThe attempts included payload retrieval and execution as well as collection and staging of NetScaler configuration data.\u00bb<\/p>\n<p>Notable among the second-stage payloads is a Python script (\u00abmain.py\u00bb) that&#8217;s designed to establish a reverse shell to \u00ab45.141.21[.]130\u00bb over TCP port 443. It also searches for running processes associated with \u00ab\/var\/python\/bin\/customsnmpd\u00bb and forcefully terminates them by issuing a \u00abkill -9\u00bb command.<\/p>\n<p>Another second-stage payload, \u00abupdate_c08937.pl,\u00bb is a Perl script with several post-exploitation capabilities &#8211;<\/p>\n<ul>\n<li>Modify \u00ab\/flash\/nsconfig\/ns.conf\u00bb to create a local account named sec_monitor and assign it the superuser role.<\/li>\n<li>Archive the \u00ab\/flash\/nsconfig\u00bb directory into \u00ab\/tmp\/update_result_3567cs.tgz\u00bb and upload the resulting archive containing NetScaler configuration data to \u00ab64.94.85[.]67:443.\u00bb The script then deletes the archive and erases itself to reduce the forensic footprint on disk.<\/li>\n<li>Change the permissions of \u00ab\/bin\/sh\u00bb to 6555 and deploy a PHP web shell at \u00ab\/var\/netscaler\/logon\/LogonPoint\/.local_journal\u00bb for remote command execution and file upload and download.<\/li>\n<li>Modify \u00ab\/etc\/httpd.conf\u00bb to enable PHP execution and map the web shell to URLs resembling legitimate NetScaler CSS resources, corroborating activity <a href=\"https:\/\/thehackernews.com\/2026\/09\/cisa-says-attackers-are-exploiting-two.html#update\" target=\"_blank\">observed by GreyNoise.<\/li>\n<\/ul>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/ai-security-guide-b\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEiXA4q3EC_2cN4xiJDYmo1tVcCX5KORpjgj8jSp3DntuUZH4f0zu1Ru8jUwzShrquIuOxPb6q9TxJJXGuj7rxDRsXRSD34thOrXdZ9tDITDEj3Ocp0Z6GwhGekRTMhMnFjJ8UA5iSkfSnmnZrFzY5cmUlbCNiTNDNVrZvyef-AR_RLqwITnqZNi6PjeZkPC\/s728-nu-rw-lo-l85-e365\/AI-eBook-d.jpg\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>\u00abWhile some attempts used commands such as whoami to test command execution, others attempted to retrieve additional payloads, collect NetScaler configuration data, establish reverse shells, create privileged accounts, and deploy web shells,\u00bb LevelBlue said.<\/p>\n<p>The disclosure comes a day after Mandiant Consulting and Google Threat Intelligence Group (GTIG) said dozens of organizations have been impacted by attacks exploiting CVE-2026-88772 to deliver PHP web shells, like WHIPSHOT, and a Python tunneler dubbed SLAPSHOT.<\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>\ue804Ravie Lakshmanan\ue802Oct 01, 2026Vulnerability \/ Web Security Threat actors have been observed exploiting a critical pre-authentication command injection vulnerability in Citrix NetScaler ADC and NetScaler Gateway to drop web shells&hellip;<\/p>\n","protected":false},"author":1,"featured_media":3300,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[764,2049,3610,1849,842,2728,1841,303,3609,3041,213],"class_list":["post-3299","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-citrix","tag-creates","tag-csslike","tag-maps","tag-netscaler","tag-payload","tag-postexploitation","tag-shell","tag-superuser","tag-urls","tag-web"],"_links":{"self":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/3299","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=3299"}],"version-history":[{"count":0,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/3299\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/media\/3300"}],"wp:attachment":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=3299"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=3299"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=3299"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}