Hackers Exploit Critical Citrix NetScaler Flaw to Deploy Web Shells and Steal Configuration Data

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com


Hackers are exploiting CVE-2026-88771, a critical Citrix NetScaler vulnerability, to run commands, install web shells, and collect appliance configuration data.

The activity goes beyond simple testing, with malicious scripts designed to maintain access and send stolen files to attacker infrastructure. The flaw affects NetScaler ADC and NetScaler Gateway and allows command execution before authentication.

Citrix rates it 9.5 under CVSS 4.0 and says vulnerable default deployments are exposed without any extra feature enabled. Its confirmed NetScaler zero-day exploitation prompted emergency updates on September 27, 2026.

Researchers from LevelBlue’s Threat Hunt Operations & Research team identified malicious authentication events across multiple customer environments.

Their September 30 technical report describes Python and Perl payloads supporting reverse shells, privileged accounts, web shells, and attempted configuration theft. The findings do not establish that every attempt succeeded.

Hackers Exploit Critical Citrix NetScaler Flaw

Attackers placed shell commands inside usernames, often alongside pitboss, NSPPE, and unexpectedly died. Some used whoami to test execution, while others used curl or wget to fetch more code.

Commands also copied the main configuration into a web directory or archived the configuration folder for later retrieval. One variation used command substitution and ${IFS}, which represents whitespace without literal spaces.

Sample of main.py (Source - LevelBlue)
Sample of main.py (Source – LevelBlue)

This gives defenders another useful search pattern: suspicious authentication fields containing crash-related text together with commands for downloading, reading, or archiving files.

The Python payload overwrites an appliance component with reverse-shell code. That code connects outward over TCP port 443, redirects input and output to the connection, and starts an interactive shell. The original script also terminates matching processes associated with the targeted component.

Web Shells and Configuration Theft

The Perl payload creates a local superuser account, archives the configuration directory, and attempts to upload the archive. It then removes the archive and deletes itself. Missing files therefore do not prove that the payload failed or that no data left the appliance.

It also changes shell permissions to 6555 and installs a PHP web shell. Changes to the HTTP server configuration enable PHP and expose the shell through addresses resembling normal CSS resources.

This echoes Google’s NetScaler web-shell findings involving disguised files, although LevelBlue does not identify its payload as the same malware.

The installed shell supports remote commands, uploads, and downloads. Together with the added administrator account, these changes give attackers several ways to keep control of the appliance after initial exploitation.

Security teams should examine authentication records, unexpected configuration access, new web-directory files, privileged account changes, and outbound traffic following suspicious login events.

Sample of update_c08937.pl (Source - LevelBlue)
Sample of update_c08937.pl (Source – LevelBlue)

LevelBlue warns that failed authentication does not mean command injection failed; investigators must check what happened afterward.

Known hashes and IP addresses help locate this activity, but attackers can change them. More lasting warning signs include shell commands in authentication data, altered appliance components, and configuration archives placed where the web server can serve them.

Carefully review network records together with file and account changes to determine whether an attempt led to a working shell or a transfer of configuration data. Administrators should follow Citrix’s official security bulletin and install an appropriate supported update.

The earlier urgent NetScaler patch guidance also stresses investigating possible compromise, rather than treating an update as proof that an appliance is clean.

The bulletin lists fixes for this flaw in 14.1-73.37 and 13.1-64.23, with corresponding FIPS and NDcPP builds. These are the minimum fixes in that advisory, not a claim that they are the latest releases. Teams should check current vendor guidance before choosing an update, especially where other NetScaler vulnerabilities also apply.

Indicators of compromise (IoCs):-

Type Indicator Observed role
IPv4 70.172.58[.]168 Exploitation source
IPv4 45.141.21[.]130 Reverse-shell C2
IPv4 162.243.36[.]88 Exploitation source
IPv4 173.40.135[.]209 Exploitation source
IPv4 47.230.224[.]154 Exploitation source
IPv4 23.27.143[.]20 Exploit source; payload host
IPv4 62.133.62[.]80 Payload host
IPv4 64.94.85[.]67 Exploit, payload, exfiltration infrastructure
IPv4 92.118.204[.]229 Command-execution testing
IPv4 87.224.84[.]82 Configuration-staging attempt
IPv4 31.56.197[.]72 Payload host
URL hxxp://62.133.62[.]80:80/xd7h/x Payload download
URL hxxp://23.27.143[.]20:9000/main.py Python reverse-shell payload
URL hxxp://64.94.85[.]67:443/update_c08937.pl Perl payload
URL hxxp://64.94.85[.]67:443/update_result_3567cs.tgz Configuration exfiltration endpoint
URL hxxp://31.56.197[.]72:9090/lula Payload download
SHA-256 e9fe43968c6c0955300e3bc4d7fb0b05a18570b4733aaf4f5c6f7f09be5a242c main.py
SHA-256 974b69782fdf5d67b97cfd508465939e44ee10798dbcc1e82b92d78776bad938 update_c08937.pl
File /var/netscaler/logon/LogonPoint/.local_journal PHP web shell
File /tmp/update_result_3567cs.tgz Staged configuration archive
File /var/netscaler/logon/insight-new.js Staged configuration
File /var/netscaler/logon/LogonPoint/xua.html Staged configuration archive
Account sec_monitor Created superuser account
Component /var/python/bin/customsnmpd Reverse-shell overwrite target
Configuration /flash/nsconfig/ns.conf Modified account configuration
Directory /flash/nsconfig Archived configuration data
Configuration /etc/httpd.conf PHP and alias changes
Permissions /bin/sh: 6555 Altered shell permissions
Alias LogonUISimple.html.style.min.css Disguised web-shell resource

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Stops threats before impact with 21 min faster MTTR. Integrate ANYRUN’s Sandbox in your SOC

The post Hackers Exploit Critical Citrix NetScaler Flaw to Deploy Web Shells and Steal Configuration Data appeared first on Cyber Security News.