Ptechhub
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs
No Result
View All Result
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs
No Result
View All Result
PtechHub
No Result
View All Result

Citrix NetScaler Post-Exploitation Payload Creates Superuser, Maps Web Shell to CSS-Like URLs

The Hacker News by The Hacker News
October 1, 2026
Home Cybersecurity
Share on FacebookShare on Twitter


Ravie LakshmananOct 01, 2026Vulnerability / Web Security

Threat actors have been observed exploiting a critical pre-authentication command injection vulnerability in Citrix NetScaler ADC and NetScaler Gateway to drop web shells and attempt theft of configuration data.

LevelBlue’s Threat Hunt Operations & Research (THOR) team, which analyzed the exploitation activity across multiple customer environments, said it identified malicious NetScaler authentication events containing attacker-controlled usernames designed to weaponize CVE-2026-88771.

CVE-2026-88771 (CVSS score: 9.5) is an improper input validation vulnerability that could allow an unauthenticated attacker to execute arbitrary commands. 

The security flaw, along with CVE-2026-88772, was disclosed last week after reports that the Dutch National Cyber Security Centre (NCSC-NL) reportedly sent a pre-notification to organizations in the Netherlands that urged organizations to shut their appliances down, citing active exploitation. As of writing, there are currently no details about who is behind these efforts.

“One of the most consistent characteristics across the identified events was attacker-controlled authentication data containing variations of the pitboss and NSPPE strings associated with exploitation of CVE-2026-88771,” LevelBlue said.

Other attempts have been observed using curl or wget to fetch additional payloads from external servers, or extract NetScaler configuration data –

  • 64.94.85[.]67:443/update_c08937.pl
  • 31.56.197[.]72:9090/lula
  • 31.56.197[.]72:9090/lula
  • 23.27.143[.]20:9000/main.py

“Taken together, the observed commands demonstrate activity extending beyond basic vulnerability validation,” LevelBlue said. “The attempts included payload retrieval and execution as well as collection and staging of NetScaler configuration data.”

Notable among the second-stage payloads is a Python script (“main.py”) that’s designed to establish a reverse shell to “45.141.21[.]130” over TCP port 443. It also searches for running processes associated with “/var/python/bin/customsnmpd” and forcefully terminates them by issuing a “kill -9” command.

Another second-stage payload, “update_c08937.pl,” is a Perl script with several post-exploitation capabilities –

  • Modify “/flash/nsconfig/ns.conf” to create a local account named sec_monitor and assign it the superuser role.
  • Archive the “/flash/nsconfig” directory into “/tmp/update_result_3567cs.tgz” and upload the resulting archive containing NetScaler configuration data to “64.94.85[.]67:443.” The script then deletes the archive and erases itself to reduce the forensic footprint on disk.
  • Change the permissions of “/bin/sh” to 6555 and deploy a PHP web shell at “/var/netscaler/logon/LogonPoint/.local_journal” for remote command execution and file upload and download.
  • Modify “/etc/httpd.conf” to enable PHP execution and map the web shell to URLs resembling legitimate NetScaler CSS resources, corroborating activity observed by GreyNoise.

“While some attempts used commands such as whoami to test command execution, others attempted to retrieve additional payloads, collect NetScaler configuration data, establish reverse shells, create privileged accounts, and deploy web shells,” LevelBlue said.

The disclosure comes a day after Mandiant Consulting and Google Threat Intelligence Group (GTIG) said dozens of organizations have been impacted by attacks exploiting CVE-2026-88772 to deliver PHP web shells, like WHIPSHOT, and a Python tunneler dubbed SLAPSHOT.



Source link

The Hacker News

The Hacker News

Next Post

IGEL Brings Now & Next® Workspace & Endpoint Security Summit to Dubai

Recommended.

Nvidia Bets Big on Synthetic Data

Nvidia Bets Big on Synthetic Data

March 19, 2025
Lytx is Launching Two New Features to Expand Safety Recognition Tools and Highlight Driver Achievements

Lytx is Launching Two New Features to Expand Safety Recognition Tools and Highlight Driver Achievements

February 5, 2025

Trending.

AWS, Google, Oracle, Microsoft Top Gartner’s Cloud AI Infrastructure List For 2026

AWS, Google, Oracle, Microsoft Top Gartner’s Cloud AI Infrastructure List For 2026

July 29, 2026
IDCA datacentres report: Global concentration and the Goldilocks zone | Computer Weekly

IDCA datacentres report: Global concentration and the Goldilocks zone | Computer Weekly

May 12, 2026
Cloud Market Share Q1 2026: AWS, Microsoft, Google Battling In AI Era

Cloud Market Share Q1 2026: AWS, Microsoft, Google Battling In AI Era

May 4, 2026

AWS Pours $6B Into New US Data Center As Amazon’s $220B Spending Goal Unfolds

August 20, 2026
CES 2026: 15 New Laptops That Deliver Cutting-Edge AI, Innovative Form Factors

CES 2026: 15 New Laptops That Deliver Cutting-Edge AI, Innovative Form Factors

January 8, 2026

PTechHub

A tech news platform delivering fresh perspectives, critical insights, and in-depth reporting — beyond the buzz. We cover innovation, policy, and digital culture with clarity, independence, and a sharp editorial edge.

Follow Us

Industries

  • AI & ML
  • Cybersecurity
  • Enterprise IT
  • Finance
  • Telco

Navigation

  • About
  • Advertise
  • Privacy & Policy
  • Contact

Subscribe to Our Newsletter

  • About
  • Advertise
  • Privacy & Policy
  • Contact

Copyright © 2025 | Powered By Porpholio

No Result
View All Result
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs

Copyright © 2025 | Powered By Porpholio