NetScaler attacks create superuser accounts and hide web shells

Threat actors are exploiting CVE-2026-88771, a critical pre-authentication command injection vulnerability in Citrix NetScaler ADC and NetScaler Gateway, to deploy web shells and attempt to steal configuration data. The flaw has a CVSS score of 9.5 and can let an unauthenticated attacker execute arbitrary commands.
LevelBlue’s Threat Hunt Operations & Research team identified the activity across multiple customer environments. Its investigation found malicious NetScaler authentication events in which attacker-controlled usernames carried variations of the strings pitboss and NSPPE, both associated with exploitation of the vulnerability.
Exploitation moves beyond proof of access
The observed commands were not limited to simple checks such as whoami. LevelBlue reported attempts to use curl or wget to retrieve additional payloads, execute them, collect NetScaler configuration data and stage that material for removal from the appliance.
One identified payload, a Python script named main.py, establishes a reverse shell to 45.141.21[.]130 over TCP port 443. It also looks for processes associated with /var/python/bin/customsnmpd and forcibly terminates them using kill -9.
A separate Perl payload, update_c08937.pl, modifies /flash/nsconfig/ns.conf to create a local account named sec_monitor and assign it the superuser role. The script archives the /flash/nsconfig directory into /tmp/update_result_3567cs.tgz, uploads the archive to 64.94.85[.]67 over port 443, and then deletes both the archive and itself.
Web shell disguised through server configuration
The Perl script also changes permissions on /bin/sh to 6555 and places a PHP web shell at /var/netscaler/logon/LogonPoint/.local_journal. The shell supports remote command execution as well as file upload and download.
To make that access more usable, the payload modifies /etc/httpd.conf to enable PHP execution and map the web shell to URLs resembling legitimate NetScaler CSS resources. This behavior corroborates activity observed by GreyNoise and shows that the operation includes persistence and concealment measures after initial exploitation.
Related NetScaler exploitation activity
CVE-2026-88771 and CVE-2026-88772 were disclosed after reports that the Dutch National Cyber Security Centre had sent a pre-notification to organizations in the Netherlands urging them to shut down affected appliances because of active exploitation. The identity of the actors behind the activity described by LevelBlue was not known at the time of its report.
Mandiant Consulting and Google Threat Intelligence Group also said that attacks exploiting CVE-2026-88772 had affected dozens of organizations, delivering PHP web shells including WHIPSHOT and a Python tunneler called SLAPSHOT. For businesses operating NetScaler ADC or Gateway, the reported behavior makes remediation only one part of the response: teams should also investigate for unexpected privileged accounts, modified appliance and web-server configuration, suspicious files, and unusual outbound connections.

