NetScaler hackers plant a hidden admin and a web shell

Published

Attackers breaking into Citrix NetScaler appliances through CVE-2026-88771 are not stopping once they prove they can run code. Payloads recovered by LevelBlue's Threat Hunt Operations and Research (THOR) team add a hidden superuser account called sec_monitor, copy the appliance's configuration off the box, install a PHP web shell disguised as a stylesheet and, in a separate script, open a reverse shell back to the attacker.

The findings come from the original report by LevelBlue SpiderLabs' Sean Shirley, with contributions from James Rodriguez, Gus Stamatinos and Timmy Lister, published September 30 after THOR hunted across multiple customer environments. Peru's National Digital Security Center (CNSD) relayed the findings to Peruvian organizations in alert 189-2026 on October 1.

The Perl script Sygnia saw, now taken apart

CVE-2026-88771 is a critical pre-authentication command injection flaw in NetScaler ADC and NetScaler Gateway, scored 9.5. Citrix fixed it on September 27 alongside CVE-2026-88772, and CISA added both to its Known Exploited Vulnerabilities catalog the same day, as IntelFusions reported. Earlier this week Sygnia documented a new form of the exploit string and an attempt to download a Perl script named update_c08937.pl. LevelBlue's analysis shows what that script does once it runs.

Usernames that carry shell commands

Every attempt THOR found arrived as a NetScaler authentication event whose attacker-controlled username contained variations of "pitboss" and "NSPPE" followed by shell commands. Some only ran whoami to confirm execution. Others used curl or wget to fetch second-stage payloads, copied the ns.conf configuration file into the web directory as insight-new.js, or archived the whole /flash/nsconfig directory into a file named xua.html. Some commands used ${IFS} in place of spaces, which LevelBlue flags as a search term in its own right.

A superuser, a stolen config and a fake stylesheet

update_c08937.pl is fetched from 64[.]94[.]85[.]67 on port 443 and piped straight into Perl, so it never sits at a fixed path on disk. It edits /flash/nsconfig/ns.conf to add sec_monitor with the superuser role, compresses the configuration directory into /tmp/update_result_3567cs.tgz, tries to upload it to the same server, then deletes the archive and itself. It also sets /bin/sh to mode 6555, drops a PHP web shell at /var/netscaler/logon/LogonPoint/.local_journal, and edits /etc/httpd.conf so the shell answers on URLs that resemble NetScaler's own CSS files. Because of that cleanup, LevelBlue warns that a missing archive does not mean the payload failed.

The second payload, main.py, overwrites /var/python/bin/customsnmpd with Python code that connects to 45[.]141[.]21[.]130 on port 443 and hands over an interactive shell.

Patch to 14.1-73.37 or 13.1-64.23, then hunt

The fixed releases are 14.1-73.37 and 13.1-64.23 or later, with matching FIPS and NDcPP builds. Patching closes the hole but removes nothing already planted. LevelBlue recommends searching authentication logs for pitboss, NSPPE, "unexpectedly died" or ${IFS} next to commands such as curl, wget, perl or tar; checking ns.conf for a sec_monitor superuser; looking for .local_journal, insight-new.js or xua.html under /var/netscaler/logon/; reviewing httpd.conf for new PHP directives; and investigating any change to /bin/sh permissions or to customsnmpd. CNSD adds that a compromised device should be isolated with its logs preserved before anything is changed.

Selected indicators (defanged): 64[.]94[.]85[.]67 (payloads and exfiltration), 45[.]141[.]21[.]130 (reverse shell), 23[.]27[.]143[.]20, 31[.]56[.]197[.]72 and 62[.]133[.]62[.]80 (payload hosts); SHA-256 974b69782fdf5d67b97cfd508465939e44ee10798dbcc1e82b92d78776bad938 (update_c08937.pl) and e9fe43968c6c0955300e3bc4d7fb0b05a18570b4733aaf4f5c6f7f09be5a242c (main.py). LevelBlue says the list is not exhaustive and that behaviour is a more durable signal than infrastructure.

An intruder who writes a superuser into the configuration file and dresses a web shell up as a stylesheet is planning to come back. For any NetScaler that sat unpatched last week, the update is the start of the job, not the end.

This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.

Read the full analysis on IntelFusions