hacker-news · Crawled Oct 1, 2026

Citrix NetScaler Post-Exploitation Payload Creates Superuser, Maps Web Shell to CSS-Like URLs

6 IoCs
Read original article ↗

AI Summary

Threat actors are actively exploiting CVE-2026-88771, a critical pre-authentication command injection vulnerability in Citrix NetScaler ADC and Gateway, to execute arbitrary commands and deploy post-exploitation payloads. The attackers use malicious authentication attempts with usernames containing 'pitboss' and 'NSPPE' strings to trigger the vulnerability and drop web shells. Second-stage payloads include a Perl script that creates a privileged account, exfiltrates configuration data, and deploys a PHP web shell mapped to CSS-like URLs, as well as a Python script that establishes a reverse shell and kills specific processes. These actions enable persistent access, remote command execution, and data theft, with infrastructure tied to multiple malicious IPs.

AI-extracted · verify before operational use

Indicators of Compromise 6 extracted

Type Value Detail
IP 64[.]94[.]85[.]67 Details →
IP 31[.]56[.]197[.]72 Details →
IP 23[.]27[.]143[.]20 Details →
IP 45[.]141[.]21[.]130 Details →
Filename update_c08937.pl Details →
Filename /var/netscaler/logon/LogonPoint/.local_journal Details →