Citrix NetScaler Post-Exploitation Payload Creates Superuser, Maps Web Shell to CSS-Like URLs
AI Summary
Threat actors are actively exploiting CVE-2026-88771, a critical pre-authentication command injection vulnerability in Citrix NetScaler ADC and Gateway, to execute arbitrary commands and deploy post-exploitation payloads. The attackers use malicious authentication attempts with usernames containing 'pitboss' and 'NSPPE' strings to trigger the vulnerability and drop web shells. Second-stage payloads include a Perl script that creates a privileged account, exfiltrates configuration data, and deploys a PHP web shell mapped to CSS-like URLs, as well as a Python script that establishes a reverse shell and kills specific processes. These actions enable persistent access, remote command execution, and data theft, with infrastructure tied to multiple malicious IPs.
AI-extracted · verify before operational use