Attackers are exploiting CVE-2026-88771, a critical pre-authentication command-injection vulnerability in Citrix NetScaler ADC and NetScaler Gateway, to deploy reverse shells, create privileged accounts, and establish persistent access.
LevelBlue’s Threat Hunt Operations & Research (THOR) team identified malicious authentication events across multiple customer environments, documenting activity extending beyond vulnerability testing into payload execution and configuration theft attempts.
LevelBlue’s September 30 investigation links attacker-controlled usernames to commands that retrieve malware, stage sensitive appliance configuration, and modify legitimate components.
Its earlier advisory assigns the vulnerability a CVSS score of 9.5 and reports that Citrix released patches on September 27.
Observed authentication data repeatedly contained pitboss, NSPPE, and “unexpectedly died” alongside injected shell commands.
Some attempts invoked whoami to validate execution; others used curl or wget to retrieve secondary payloads, including update_c08937.pl and a resource named lula.
Attackers also targeted /flash/nsconfig/ns.conf, copying its contents into /var/netscaler/logon/insight-new.js.
Separate commands archived the entire /flash/nsconfig directory into /var/netscaler/logon/LogonPoint/xua.html, placing configuration data beneath a web-accessible directory.
Several commands substituted ${IFS} for literal spaces, while another used backtick command substitution instead of semicolon-delimited injection.
These variations give investigators additional search patterns without requiring an exact match against one exploit string.
One second-stage Python payload, main.py, was hosted at 23.27.143[.]20:9000.
It overwrites /var/python/bin/customsnmpd with code that connects to 45.141.21[.]130:443, redirects standard input, output, and error to the socket, and launches an interactive /bin/sh.
The initial script also identifies and terminates processes associated with customsnmpd.
A separate Perl payload, update_c08937.pl, was retrieved from 64.94.85[.]67:443 and piped directly into Perl.
This execution pattern avoids first saving the downloaded script to a fixed filesystem location.
LevelBlue Researchers identified malicious NetScaler authentication, events containing attacker-controlled usernames designed to exploit CVE-2026-88771.
The Perl code modifies /flash/nsconfig/ns.conf to create sec_monitor with superuser privileges.
It archives the configuration directory into /tmp/update_result_3567cs.tgz and attempts to upload that archive to the same infrastructure. Afterwards, it removes the archive and deletes itself, limiting residual evidence.
The payload additionally changes /bin/sh permissions to 6555 and installs a PHP web shell at /var/netscaler/logon/LogonPoint/.local_journal.
Changes to /etc/httpd.conf enable PHP execution and expose the implant through CSS-like URLs, including LogonUISimple.html.style.min.css and randomized hexadecimal variants.
The shell supports remote command execution, uploads, and downloads.
Defenders should correlate suspicious authentication fields with outbound connections, configuration access, and appliance modifications.
Particularly valuable artifacts include sec_monitor, altered customsnmpd content, .local_journal, unexpected HTTP Alias or SetHandler directives, and changes to shell permissions.
Missing payloads or archives do not establish that exploitation failed: the Perl script explicitly removes artifacts.
Conversely, an injected authentication event alone does not demonstrate successful compromise; subsequent filesystem, process, and network evidence remains essential.
The findings distinguish attempted exploitation from verified downstream activity. THOR’s report describes commands observed in authentication telemetry and capabilities identified through payload analysis, rather than attributing every capability to every targeted appliance.
That distinction matters when assessing incident scope: configuration staging, an outbound callback, and a newly privileged account represent different investigative milestones and should be validated independently against available logs and preserved appliance evidence during triage.
LevelBlue lists fixed standard builds as 14.1-73.37 and 13.1-64.23, with FIPS fixes at 14.1-73.37 FIPS and 13.1-37.279 for FIPS/NDcPP.
Organizations should apply appropriate updates promptly, review local accounts, reset active-account authentication, and collect surrounding network telemetry.
The published indicators are investigative pivots, not an exhaustive inventory; behavioral hunting remains necessary as infrastructure and filenames change.
| Indicator | Type | Description |
| 70.172.58[.]168 | IPv4 | Source of NetScaler exploitation attempts |
| 45.141.21[.]130 | IPv4 | Reverse-shell C2 infrastructure |
| 162.243.36[.]88 | IPv4 | Source of NetScaler exploitation attempts |
| 173.40.135[.]209 | IPv4 | Source of NetScaler exploitation attempts |
| 47.230.224[.]154 | IPv4 | Source of NetScaler exploitation attempts |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Stops Cyber threats before impact with 21 min faster MTTR. Integrate ANYRUN’s Sandbox in your SOC.
A threat actor published a malicious version of the tensorlake npm package on October 8,…
A proof-of-concept (PoC) exploit has been released for CVE-2026-102489, a critical vulnerability in Zammad that…
A critical vulnerability in LMCache allows unauthenticated attackers to execute arbitrary code against reachable multi-process…
16 malicious Firefox extensions that impersonate cryptocurrency wallets to intercept recovery phrases and private keys…
Exposed directories on five servers have revealed an operational DarkSword/Coruna exploitation platform built to compromise…
wolfSSL has released wolfSSH version 1.6.0, which addresses five security vulnerabilities, including a critical flaw…