Full Report
Threat actors have been observed exploiting a critical pre-authentication command injection vulnerability in Citrix NetScaler ADC and NetScaler Gateway to drop web shells and attempt theft of configuration data. LevelBlue's Threat Hunt Operations & Research (THOR) team, which analyzed the exploitation activity across multiple customer environments, said it identified malicious NetScaler
Analysis Summary
# Incident Report: Exploitation of Citrix NetScaler CVE-2026-88771
## Executive Summary
Threat actors are actively exploiting a critical pre-authentication command injection vulnerability (CVE-2026-88771) in Citrix NetScaler ADC and Gateway appliances. The attack involves weaponizing authentication events to deploy web shells, create superuser accounts, and exfiltrate device configuration data. LevelBlue THOR has observed these activities across multiple environments, indicating a concerted effort by unidentified actors to maintain long-term persistence within target networks.
## Incident Details
- **Discovery Date:** Observed and reported by LevelBlue on October 1, 2026.
- **Incident Date:** Active exploitation began late September 2026 following Dutch NCSC alerts.
- **Affected Organization:** Multiple organizations globally (Dozens reported by Mandiant/Google).
- **Sector:** Cross-sector; any organization utilizing Citrix NetScaler ADC/Gateway.
- **Geography:** Global, with specific early notifications in the Netherlands.
## Timeline of Events
### Initial Access
- **Date/Time:** Late September 2026.
- **Vector:** Exploitation of CVE-2026-88771 (CVSS 9.5), a pre-authentication command injection flaw.
- **Details:** Attackers send malicious authentication requests containing "pitboss" and "NSPPE" strings to trigger arbitrary command execution via improper input validation.
### Lateral Movement
- **Persistence:** Attackers modified `/flash/nsconfig/ns.conf` to create a permanent local account named `sec_monitor` with superuser privileges.
- **Tooling:** Deployment of a Python script (`main.py`) to establish a reverse shell to `45.141.21[.]130`.
### Data Exfiltration/Impact
- **Staging:** The Perl script `update_c08937.pl` archives the entire `/flash/nsconfig` directory into `/tmp/update_result_3567cs.tgz`.
- **Exfiltration:** Configuration archives containing sensitive secrets and device settings were uploaded to `64.94.85[.]67:443`.
### Detection & Response
- **Detection:** LevelBlue THOR identified malicious authentication logs and unusual outbound traffic to known malicious IPs.
- **Response:** NCSC-NL urged organizations to shut down vulnerable appliances; security researchers released Indicators of Compromise (IoCs) for hunting.
## Attack Methodology
- **Initial Access:** Pre-authentication command injection (CVE-2026-88771).
- **Persistence:** Creation of superuser account (`sec_monitor`) and deployment of PHP web shells hidden in legitimate-looking directories.
- **Privilege Escalation:** Modification of `/bin/sh` permissions to `6555` (SetUID).
- **Defense Evasion:** Self-deleting scripts; mapping web shells to CSS-like URLs; killing monitoring processes (`customsnmpd`).
- **Credential Access:** Theft of NetScaler configuration files (`ns.conf`) which often contain encrypted passwords and keys.
- **Discovery:** Execution of `whoami` and process discovery.
- **Lateral Movement:** Reverse shell establishment via Python.
- **Collection:** Archiving configuration directories via Perl scripts.
- **Exfiltration:** Uploading TGZ archives to attacker-controlled infrastructure over port 443.
- **Impact:** Complete compromise of the NetScaler appliance and potential compromise of the traffic passing through it.
## Impact Assessment
- **Financial:** High potential costs related to incident response and appliance restoration.
- **Data Breach:** Exposure of full NetScaler configuration data, including SSL certificates and authentication secrets.
- **Operational:** Disruption due to the need to take appliances offline for patching or forensics.
- **Reputational:** High risk for organizations acting as service providers via Gateway appliances.
## Indicators of Compromise
- **Network Indicators:**
- 64.94.85[.]67:443
- 31.56.197[.]72:9090
- 23.27.143[.]20:9000
- 45.141.21[.]130:443
- **File Indicators:**
- `update_c08937.pl`
- `main.py`
- `/var/netscaler/logon/LogonPoint/.local_journal` (Web shell)
- `/tmp/update_result_3567cs.tgz`
- **Behavioral Indicators:**
- Unusual `pitboss` or `NSPPE` strings in authentication logs.
- Modification of `/etc/httpd.conf` to enable PHP in unexpected directories.
- Unexpected creation of the `sec_monitor` user account.
## Response Actions
- **Containment:** Disconnect affected NetScaler appliances from the internet immediately.
- **Eradication:** Wipe and reinstall appliance firmware; rotate all certificates and credentials stored on the device.
- **Recovery:** Restore from a known-good backup and apply the latest security patches from Citrix.
## Lessons Learned
- **Vulnerability Management:** Critical edge devices require immediate patching or isolation when pre-authentication RCE flaws are announced.
- **Log Monitoring:** Authentication logs should be offloaded to a central SIEM to detect injection attempts even if the appliance is compromised.
- **Configuration Integrity:** Changes to core configuration files (like `ns.conf`) should trigger high-priority alerts.
## Recommendations
- **Immediate Patching:** Apply all Citrix-released security updates for CVE-2026-88771 and CVE-2026-88772.
- **Hunt for IoCs:** Audit NetScaler filesystems for the specific web shell paths and user accounts mentioned above.
- **Restrict Access:** Limit management interface access to trusted internal IP ranges only.