
Citrix NetScaler Attack Creates Superuser, Camouflages Web Shell
Attackers exploiting a critical Citrix NetScaler flaw are creating a hidden superuser and disguising web shells as CSS files, while stealing configs.
Attackers are actively exploiting a critical Citrix NetScaler vulnerability to plant web shells and create hidden administrator accounts, according to new analysis from LevelBlue's Threat Hunt Operations & Research (THOR) team. The activity targets Citrix NetScaler ADC and NetScaler Gateway appliances, devices commonly used to balance website traffic and provide secure remote access. The vulnerability, tracked as CVE-2026-88771, is a pre-authentication command injection issue that allows an unauthenticated attacker to run arbitrary commands on an affected appliance before any login, earning it a CVSS severity score of 9.5.
The flaw is an improper input validation problem and was disclosed last week together with another Citrix vulnerability, CVE-2026-88772. Reports indicate that the Dutch National Cyber Security Centre (NCSC-NL) sent a pre-notification to organizations in the Netherlands urging them to shut down their appliances because of active exploitation. LevelBlue does not attribute the attacks to any specific group, and no details about who is behind the campaign are currently public.
LevelBlue's THOR team observed malicious NetScaler authentication events across multiple customer environments. A consistent feature was attacker-controlled usernames containing variations of the strings pitboss and NSPPE, which the researchers associate with exploitation of CVE-2026-88771. In some attempts, attackers used standard command-line tools such as curl or wget to download additional payloads from external servers, including 64.94.85[.]67 on port 443, 31.56.197[.]72 on port 9090, and 23.27.143[.]20 on port 9000. The downloaded files were named update_c08937.pl, lula, and main.py respectively. LevelBlue said this shows the activity goes far beyond simply checking whether a device is vulnerable; the attackers actively retrieved and executed payloads and collected NetScaler configuration data.
The second-stage payloads reveal the attackers' goals. One Python script, main.py, opens a reverse shell to the IP address 45.141.21[.]130 over TCP port 443, giving the attacker a remote command line into the appliance. It also searches for processes linked to /var/python/bin/customsnmpd and forcefully terminates them with a kill -9 command. Another payload, a Perl script called update_c08937.pl, is more destructive. It modifies the NetScaler configuration file /flash/nsconfig/ns.conf to create a local account named sec_monitor and gives that account the superuser role. The script then archives the /flash/nsconfig directory into /tmp/update_result_3567cs.tgz and uploads the archive, which contains sensitive configuration data, to 64.94.85[.]67 over port 443. After the upload, the script deletes the archive and erases itself to leave fewer forensic traces. It also changes the permissions of /bin/sh to 6555 and places a PHP web shell at /var/netscaler/logon/LogonPoint/.local_journal, allowing remote command execution and file upload and download. To hide the web shell, the script edits /etc/httpd.conf to enable PHP execution and maps the shell to URLs that look like normal NetScaler CSS resource files. GreyNoise has separately observed activity that matches this camouflage technique.
LevelBlue noted that while some attackers used simple commands such as whoami to confirm they could execute code, others moved quickly to retrieve payloads, steal configuration data, establish reverse shells, create privileged accounts, and deploy web shells. The disclosure comes one day after Mandiant Consulting and Google Threat Intelligence Group reported that dozens of organizations worldwide have been affected by attacks exploiting CVE-2026-88772 to deliver PHP web shells like WHIPSHOT and a Python tunneler called SLAPSHOT.
For any organization running NetScaler ADC or NetScaler Gateway, the immediate focus should be confirming that the latest Citrix security updates are installed and reviewing appliance logs for the indicators described above. AEU-I provides security-first IT, infrastructure and consulting services that can help teams assess and maintain such internet-facing systems. Given the active exploitation, delaying patching or leaving management interfaces exposed to the internet is a serious risk.
How to Protect Yourself
- If your website or remote work setup uses Citrix NetScaler, immediately ask your IT provider or hosting company to install the latest Citrix security update.
- While waiting for the update, make sure the NetScaler login page is not reachable from the public internet; if it must be online, restrict it to only your office or VPN addresses.
- Ask your provider to check for an unexpected administrator account called sec_monitor and for any new files in the NetScaler login folder; if found, have them rebuild the system from a clean backup.
- Ask your provider to block network connections to the internet addresses listed in the report (such as 64.94.85[.]67 and 45.141.21[.]130) at the firewall.
- Review all administrator accounts on your website and remote access tools regularly, and remove any account you do not recognize.
- Turn on logging and alerts for failed logins and unusual command activity on any internet-facing device.
Vulnerabilities & Fixes
- CVE-2026-88771 Critical pre-authentication command injection vulnerability in Citrix NetScaler ADC and NetScaler Gateway; apply the Citrix update and restrict management access. View the fix & details →
- CVE-2026-88772 A related critical Citrix NetScaler vulnerability disclosed at the same time and actively exploited to deploy web shells; organizations should apply available patches. View the fix & details →
Terms Explained
- Citrix NetScaler ADC A networking device that balances incoming website traffic and speeds up delivery; ADC stands for Application Delivery Controller.
- Citrix NetScaler Gateway A secure entry point that lets employees log into a company's internal applications from outside.
- command injection A type of attack where an attacker tricks a program into running commands of their choosing on a server.
- web shell A small hidden script left on a server that lets an attacker control it through a web browser.
- reverse shell A connection that an infected machine opens back to an attacker, giving the attacker a remote command line.
- superuser The highest-level account on a system, which has permission to change any setting or file.
- CVE Common Vulnerabilities and Exposures, a public catalog that gives each known security weakness a unique identifier.
- CVSS Common Vulnerability Scoring System, a 0 to 10 scale that rates how serious a security issue is.