NetScaler Attack Payloads Aim for Superuser Persistence and CSS-Masked Web Shells

Attackers exploit CVE-2026-88771 on NetScaler to deploy reverse shells, create sec_monitor superuser, steal configs and hide PHP web shells as CSS.

NetScaler Attack Payloads Aim for Superuser Persistence and CSS-Masked Web Shells
Vulnerabilities

Illustrative image generated with AI

Listen to this articleAudio edition · 9 min

Attackers exploiting Citrix NetScaler appliances have moved beyond simple command-execution tests, using second-stage payloads designed to establish reverse shells, create privileged accounts, stage configuration data and deploy web shells.

LevelBlue’s Threat Hunt Operations & Research team observed the activity across multiple customer environments. The malicious authentication events targeted CVE-2026-88771, a pre-authentication command-injection vulnerability affecting NetScaler ADC and NetScaler Gateway.

The researchers documented attempts to collect and stage appliance configurations, but the reporting does not confirm that every payload action succeeded. One analyzed Perl script is capable of creating a sec_monitor superuser, preparing configuration files for exfiltration and exposing a PHP shell through URLs resembling legitimate CSS resources.

A separate NetScaler flaw, CVE-2026-88772, is also being exploited. Both vulnerabilities entered the US Cybersecurity and Infrastructure Security Agency’s Known Exploited Vulnerabilities catalog on September 27, 2026. The remediation deadline for federal agencies was September 30, 2026.

Malicious authentication data triggers command execution

LevelBlue identified malicious NetScaler authentication events containing attacker-controlled usernames crafted to exploit CVE-2026-88771. Variations of the strings pitboss and NSPPE appeared repeatedly in the observed authentication data.

Some attempts issued basic commands such as whoami, apparently to determine whether command execution was working. Other events used curl or wget to retrieve additional payloads from external infrastructure or attempted to collect NetScaler configuration data.

Taken together, the activity extended beyond vulnerability validation. LevelBlue observed attempts involving payload retrieval and execution, reverse-shell establishment, configuration collection and staging, privileged-account creation, and web-shell deployment.

The reporting does not attribute the activity to a specific threat actor.

Python payload targets a process and opens a reverse shell

One second-stage payload was a Python script named main.py, retrieved from:

23.27.143[.]20:9000/main.py

The script is designed to establish a reverse shell to 45.141.21[.]130 over TCP port 443. Although that port is commonly associated with HTTPS, the available analysis does not identify the shell traffic itself as HTTPS.

The payload also searches for processes associated with:

/var/python/bin/customsnmpd

It then attempts to terminate matching processes with kill -9. The analysis documents this behavior without establishing why the process was selected.

For defenders, relevant traces include outbound connections to the reported destination, retrieval of main.py, and unexpected termination of the customsnmpd-related process. These artifacts should be considered alongside authentication and command-execution records rather than treated as standalone proof of compromise.

Perl script can create sec_monitor and stage configurations

The more extensive payload, update_c08937.pl, was retrieved from:

64.94.85[.]67:443/update_c08937.pl

According to LevelBlue’s analysis, the Perl script is capable of modifying /flash/nsconfig/ns.conf to add a local account named sec_monitor and assign it the superuser role. Finding that account or the corresponding configuration changes would indicate that this stage may have executed successfully.

The script is also written to archive /flash/nsconfig into:

/tmp/update_result_3567cs.tgz

It then attempts to upload the archive, which would contain NetScaler configuration data, to 64.94.85[.]67 over port 443. Its programmed cleanup sequence deletes the archive and removes the Perl script itself, reducing the file-based evidence available to investigators if those steps complete.

Additional capabilities include changing /bin/sh permissions to 6555 and placing a PHP web shell at:

/var/netscaler/logon/LogonPoint/.local_journal

The shell supports remote command execution and file transfers. The payload can also alter /etc/httpd.conf to enable PHP execution and map the shell to URLs that resemble legitimate NetScaler CSS resources. LevelBlue said this mapping behavior corroborated activity observed by GreyNoise.

That technique goes beyond choosing an inconspicuous filename. By changing the web-server configuration, the payload can make requests to the shell look like requests for static style-sheet content in URL records.

Another resource location associated with the observed activity was:

31.56.197[.]72:9090/lula

Both flaws affect multiple NetScaler branches

CVE-2026-88771 is classified as CWE-20, Improper Input Validation. It can allow an unauthenticated attacker to execute arbitrary commands on a vulnerable appliance.

The primary article assigns the flaw a CVSS score of 9.5. The NVD record instead lists CVSS v3.1 9.8 with the following vector:

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

The affected versions identified in the NVD description are:

  • NetScaler ADC before 14.1-73.37
  • NetScaler ADC before 13.1-64.23
  • NetScaler ADC FIPS before 14.1-73.37
  • NetScaler ADC FIPS and NDcPP before 13.1.37.279
  • NetScaler Gateway before 14.1-73.37
  • NetScaler Gateway before 13.1-64.23

CVE-2026-88772 is a separate vulnerability classified as CWE-119, Improper Restriction of Operations within the Bounds of a Memory Buffer. It can lead to remote code execution or denial of service.

Its NVD CVSS v3.1 score is 8.1:

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

The same NetScaler product branches and version thresholds are listed for CVE-2026-88772.

Mandiant Consulting and Google Threat Intelligence Group separately reported that dozens of organizations had been affected by attacks exploiting CVE-2026-88772. Those operations delivered PHP web shells including WHIPSHOT and a Python tunneler called SLAPSHOT.

Available reporting does not establish that those incidents and the CVE-2026-88771 activity investigated by LevelBlue involved the same operator.

CISA’s federal remediation deadline has expired

CISA added both vulnerabilities to the KEV catalog on September 27, 2026, confirming that they are exploited vulnerabilities rather than merely theoretical risks. The federal remediation deadline was September 30, 2026.

For both entries, CISA directs stakeholders to apply vendor mitigations and comply with BOD 26-04, “Prioritizing Security Updates Based on Risk,” and its “Forensics Triage Requirements.” Organizations must evaluate each asset’s internet exposure and follow the applicable BOD 26-04 patching guidance.

For cloud services, CISA directs stakeholders to follow the relevant BOD 26-04 guidance or discontinue use of the product if mitigations are unavailable. The supplied information does not provide a product-specific installation procedure, so operators should follow Citrix’s instructions for their exact branch and deployment type.

These are not Citrix’s only recent KEV entries. CVE-2026-19490 was added on September 9, 2026, and CVE-2026-8452 entered the catalog on August 26, 2026.

What NetScaler defenders should investigate

Administrators should identify affected ADC and Gateway systems, including FIPS and NDcPP deployments, and apply the vendor’s prescribed remediation. Because exploitation has already been observed, installing updates or mitigations should be accompanied by a review for earlier compromise.

Relevant evidence includes:

  • Authentication records containing unexpected usernames or variants of pitboss and NSPPE
  • Abnormal execution of whoami, curl or wget through authentication events
  • A local sec_monitor account assigned the superuser role
  • Unauthorized changes to /flash/nsconfig/ns.conf
  • The file /var/netscaler/logon/LogonPoint/.local_journal
  • Changes to /etc/httpd.conf, particularly mappings that make PHP content resemble CSS resources
  • /bin/sh permissions set to 6555
  • Evidence that /tmp/update_result_3567cs.tgz was created or handled
  • Retrieval of main.py, update_c08937.pl or the resource named lula
  • Connections involving 64.94.85[.]67, 31.56.197[.]72, 23.27.143[.]20 or 45.141.21[.]130
  • Unexpected termination of processes associated with /var/python/bin/customsnmpd

The Perl payload’s cleanup capabilities mean missing files alone cannot exclude execution. Account records, configuration changes, web-server mappings, process telemetry and network logs may retain evidence after the staged archive or script has been removed.

Read next

Sources

This article is an original reworking based on the sources below.

CVEs covered in this article

Back to home

Latest Cybersecurity News

All cybersecurity news →