LevelBlue Maps Post-Exploitation Payloads Tied to Citrix NetScaler CVE-2026-88771
Researchers at LevelBlue's Threat Hunt Operations & Research (THOR) team have published a detailed breakdown of the second-stage payloads attackers are dropping after exploiting CVE-2026-88771, a critical pre-authentication command injection vulnerability (CVSS 9.5) in Citrix NetScaler ADC and NetScaler Gateway. Analyzing exploitation activity across multiple customer environments, LevelBlue found that attacker-controlled authentication data containing variations of the strings "pitboss" and "NSPPE" was the most consistent indicator tied to CVE-2026-88771 abuse. Once inside, attackers deployed a Python reverse shell (main.py) and a Perl script (update_c08937.pl) that creates a hidden superuser account, archives the appliance's configuration for exfiltration, and rewrites NetScaler's web server configuration to disguise a PHP web shell as a CSS stylesheet request — a technique engineered to blend malicious traffic into an appliance's normal web logs. The findings, reported by The Hacker News on October 1, 2026, add granular indicators of compromise to a vulnerability that CISA added to its Known Exploited Vulnerabilities catalog after the Dutch NCSC-NL pre-notified organizations in the Netherlands to shut down exposed appliances.
Incident Details
| Attribute | Value |
|---|---|
| CVE ID | CVE-2026-88771 |
| CVSS score | 9.5 (Critical) |
| Vulnerability type | Pre-authentication command injection / improper input validation (CWE-20) |
| Affected products | Citrix NetScaler ADC and NetScaler Gateway, default configuration |
| Companion flaw | CVE-2026-88772 (memory overflow, DTLS), disclosed the same day |
| Disclosed | September 27, 2026 — Citrix bulletin CTX697096 |
| Discovered/analyzed by | LevelBlue Threat Hunt Operations & Research (THOR) team |
| Earliest known exploitation | September 24, 2026 (GreyNoise sensor telemetry, three days pre-disclosure) |
| Pre-disclosure warning | Dutch NCSC-NL pre-notification urging Dutch organizations to shut down affected appliances |
| CISA KEV status | Added to the Known Exploited Vulnerabilities catalog; federal remediation due September 30, 2026 |
| Key auth-field indicator | Variations of pitboss and NSPPE strings in attacker-controlled authentication data |
| Second-stage payloads | main.py (Python reverse shell), update_c08937.pl (Perl post-exploitation script) |
| Persistence account | sec_monitor, added with superuser role |
| Attribution | Not established; investigation ongoing |
How the Attack Chain Worked
The "pitboss" / NSPPE Fingerprint
LevelBlue's THOR team said the single most consistent artifact across the customer environments it examined was attacker-controlled authentication data containing variations of the strings pitboss and NSPPE — a reference to NetScaler's internal Packet Processing Engine. Analysts used this pattern, alongside command-injection telltales like ${IFS} whitespace substitution in authentication fields, to distinguish genuine CVE-2026-88771 exploitation attempts (ranging from basic whoami command testing to full payload staging) from unrelated log noise.
Reverse Shell via main.py
The first second-stage payload LevelBlue documented is main.py, a Python script that overwrites the legitimate /var/python/bin/customsnmpd binary path with attacker code to establish a reverse shell connection to 45.141.21[.]130 over TCP port 443. Before establishing its own foothold, the script actively searches for and kill -9s any running process named /var/python/bin/customsnmpd — removing a legitimate NetScaler SNMP daemon process, likely to free the path for its own persistence and avoid conflicting with the genuine service.
The update_c08937.pl Superuser and Exfiltration Payload
The second payload, update_c08937.pl, is a more comprehensive Perl post-exploitation script retrieved via curl and piped directly into Perl for execution. According to LevelBlue's analysis, it:
- Modifies
/flash/nsconfig/ns.confto create a local account named sec_monitor and assigns it the superuser role, giving attackers a durable, credential-based backdoor independent of the original exploit chain. - Archives the entire
/flash/nsconfigdirectory into/tmp/update_result_3567cs.tgz, then uploads that archive to attacker infrastructure — an attempt to exfiltrate the appliance's full configuration, including certificates and stored credentials. - Deletes the staged archive and the script itself after execution, a deliberate anti-forensics step intended to minimize artifacts left behind for incident responders.
Disguising the Web Shell as a CSS File
The most distinctive element of the campaign is how attackers hide their persistence mechanism. The Perl payload modifies NetScaler's HTTP configuration (/etc/httpd.conf) to expose a hidden file — .local_journal, planted under the appliance's logon customization path — as a PHP web shell, then maps requests for it through AliasMatch directives tied to CSS-like URLs resembling legitimate NetScaler assets (patterns similar to receiver.min.[hash].css or LogonUISimple.html.style.min.css). Because the AliasMatch pattern accepts varying hash-like characters in the URL, a wide range of superficially different, CSS-looking requests all route to the same web shell — letting malicious traffic hide in plain sight among an appliance's normal static-asset requests and web server access logs.
Root Shell and Cookie-Authenticated Access
Related analysis from GreyNoise, corroborating LevelBlue's findings, described attackers separately setting the setuid and setgid bits on /bin/sh — changing its permissions to 6555 — so that any process later invoking a shell inherits root privileges regardless of the calling account. GreyNoise also documented a password-protected web shell variant at a similar NetScaler logon path that authenticates via a hard-coded cookie value (observed as a CsrfToken cookie) and accepts commands through a second cookie (NSC_TASS) — cookie names deliberately chosen to mimic NetScaler's own NSC_* session-cookie namespace. Google's Threat Intelligence Group (GTIG/Mandiant) has separately tracked related web shell tooling in this campaign under the name WHIPSHOT. Researchers emphasize that patching CVE-2026-88771 alone does not remove any of these artifacts — fixed builds close the vulnerable code path but do not scan for planted files, restore httpd.conf, reset /bin/sh permissions, or delete unauthorized accounts, and high-availability configuration sync has been observed copying web shells to secondary nodes.
Impact Assessment
| Impact Area | Description |
|---|---|
| Authentication bypass | CVE-2026-88771 requires no valid credentials, giving unauthenticated attackers direct command execution on internet-facing appliances |
| Persistent backdoor access | The sec_monitor superuser account survives independently of the original exploit and of a routine patch |
| Configuration and credential exposure | Archiving and exfiltrating /flash/nsconfig risks exposure of certificates, stored secrets, and the appliance's full configuration |
| Stealth and log evasion | CSS-disguised web shell URLs and cookie-based command channels are designed to blend into normal appliance web traffic, complicating detection |
| Anti-forensic behavior | Self-deleting payloads and archive cleanup reduce the artifacts available for incident response and root-cause analysis |
| Patch insufficiency | Updating to fixed NetScaler builds does not remove previously planted accounts, web shells, or modified file permissions |
| Scale of exposure | CISA KEV listing and NCSC-NL's pre-notification indicate exploitation was active and widespread before and immediately after public disclosure |
Recommendations
For NetScaler Administrators
- Apply the fixed builds referenced in Citrix bulletin CTX697096 immediately if not already patched, and treat every internet-facing NetScaler ADC/Gateway appliance that was exposed before patching as potentially compromised.
- Before or alongside patching, check
/flash/nsconfig/ns.conffor an unexpected local account named sec_monitor (or any unrecognized superuser account) and remove it. - Inspect
/etc/httpd.conffor injectedAliasorAliasMatchdirectives routing CSS-like URLs to unexpected PHP files, and check the logon customization path for a hidden file such as.local_journal. - Verify
/bin/shpermissions have not been changed to 6555 (setuid/setgid root); reset immediately if found. - Check high-availability secondary nodes separately — configuration sync can propagate a web shell from a compromised primary node.
For Security Operations and Threat Hunters
- Hunt NetScaler authentication logs for strings containing pitboss or NSPPE variations, and for
${IFS}whitespace substitution patterns, both strong indicators of CVE-2026-88771 exploitation attempts. - Add detection coverage for outbound connections to known second-stage infrastructure, including
45.141.21[.]130:443,64.94.85[.]67:443,23.27.143[.]20:9000, and31.56.197[.]72:9090. - Alert on unexpected processes replacing or impersonating
/var/python/bin/customsnmpd, and onkill -9activity targeting that path. - Flag HTTP requests carrying NetScaler-style cookies (for example, unusual
CsrfTokenorNSC_TASSvalues) against logon customization paths that should not normally accept command-bearing cookies.
For Incident Responders and Leadership
- Preserve appliance memory, support bundles, and logs covering at minimum the period since September 24, 2026 before rebuilding or re-imaging any suspected-compromised device.
- Rotate all credentials and certificates that transited an appliance with confirmed or suspected exploitation, since archived configuration data (
/flash/nsconfig) may already have been exfiltrated. - Engage dedicated incident response support rather than relying on patching alone — the persistence mechanisms documented here are explicitly designed to survive a routine update.
Key Takeaways
- CVE-2026-88771 (CVSS 9.5) is a critical pre-authentication command injection flaw in Citrix NetScaler ADC and NetScaler Gateway, disclosed September 27, 2026 alongside companion flaw CVE-2026-88772.
- LevelBlue's THOR team identified attacker-controlled authentication data containing "pitboss" and "NSPPE" strings as the most consistent indicator of CVE-2026-88771 exploitation across multiple customer environments.
- Two second-stage payloads were documented: main.py, a Python reverse shell to
45.141.21[.]130:443that kills legitimatecustomsnmpdprocesses, and update_c08937.pl, a Perl script that creates a sec_monitor superuser account and exfiltrates/flash/nsconfig. - The Perl payload disguises a PHP web shell (planted as .local_journal) behind CSS-like URLs using
AliasMatchdirectives, deliberately blending malicious traffic into normal appliance web logs. - Related GreyNoise findings describe attackers setting setuid/setgid 6555 on
/bin/shfor guaranteed root access and installing a cookie-authenticated web shell variant, tracked by Google's GTIG/Mandiant under the name WHIPSHOT. - Patching alone does not remove these implants — defenders must independently check for the
sec_monitoraccount, modifiedhttpd.conf, altered/bin/shpermissions, and planted web shell files, including on HA secondary nodes.
Sources
- Citrix NetScaler Post-Exploitation Payload Creates Superuser, Maps Web Shell to CSS-Like URLs — The Hacker News
- Citrix NetScaler CVE-2026-88771: Observed Exploitation Artifacts and Hunt Indicators — LevelBlue SpiderLabs
- Hackers exploit Citrix NetScaler zero-day to deploy web shells — BleepingComputer / GreyNoise
- Critical Zero-Day Vulnerabilities Exploited in Citrix NetScaler ADC, Gateway — CISA