Citrix NetScaler Attacks Target ADC and Gateway Appliances
Detection stack
- AIDR
- Alert
- ETL
- Query
Summary
Threat actors are actively exploiting two zero-day vulnerabilities in Citrix NetScaler appliances to obtain root-level access. The campaign involves deploying custom PHP web shells such as WHIPSHOT and a Python-based tunneling tool known as SLAPSHOT. These utilities allow attackers to perform internal reconnaissance and steal credentials by proxying traffic into protected network environments.
Investigation
Mandiant and Google Threat Intelligence Group identified exploitation of CVE-2026-88772 and CVE-2026-88771 in late September 2026. Researchers found that attackers use malformed DTLS record headers to trigger heap memory corruption in the NetScaler Packet Processing Engine. Forensic evidence also revealed modified httpd.conf files used for persistence and SUID permissions applied to /bin/sh to retain root privileges.
Mitigation
Organizations should prioritize installing the latest Citrix builds for supported NetScaler 14.1 and 13.1 release tracks. If immediate patching is not possible, defenders should disable DTLS where feasible and restrict inbound UDP/443 traffic at the upstream perimeter. Strict egress filtering and rotation of all credentials stored on affected appliances are also strongly recommended.
Response
When compromise is suspected, organizations should isolate affected NetScaler nodes and suspend High Availability (HA) synchronization to prevent replication of malicious configuration changes. Responders should revoke active administrative and VPN sessions and rotate appliance secrets, including SSH keys and TLS certificates. Credentials used by integrated services such as LDAP and RADIUS should also be comprehensively rotated.
Attack Flow
Detections
Possible CVE-2026-88772 (Citrix NetScaler Memory Overflow In DTLS Protocol Handling) Exploitation Attempt (via syslog)
Hidden File Was Created On Linux Host (via file_event)
Nohup Usage (via cmdline)
Possible Defense Evasion by Use of Base64 Command (via cmdline)
Cron File Was Created (via file_event)
IOCs (SourceIP) to detect: Defending Against Active Exploitation of Citrix NetScaler ADC and Gateway Appliances
IOCs (DestinationIP) to detect: Defending Against Active Exploitation of Citrix NetScaler ADC and Gateway Appliances
Detected Potential Exploitation of Citrix NetScaler Appliances [Linux Process Creation]
Persistence and C2 Activities on Citrix NetScaler Appliances via HTTP Headers and File Masquerading [Webserver]
## Simulation Execution
-
Attack Narrative & Commands: The adversary aims to establish long-term persistence and a covert C2 channel on the Citrix NetScaler appliance. First, they modify the web server configuration to treat
.debfiles as PHP scripts, allowing them to upload and execute web shells disguised as Linux package files. Second, they useAliasMatchto masquerade a malicious script as a harmless.icoicon file. Finally, to avoid detection by traditional NIDS, they communicate with their C2 server using custom HTTP headers (HTTP_X_UXandHTTP_NSC_LDAP) embedded within standard web requests. -
Regression Test Script: This script simulates the generation of the logs that the detection rule expects to see. Since we are testing a detection rule, we will simulate the log entries themselves as if they were generated by the appliance.
#!/bin/bash # Simulation script to generate logs matching the detection logic # 1. Simulate Configuration Change: AddingHandler for .deb files echo "$(date) NetScaler-Config: AddHandler application/x-httpd-php .deb" >> /var/log/netscaler_config.log # 2. Simulate Configuration Change: AliasMatch for masquerading echo "$(date) NetScaler-Config: AliasMatch ^/vpn/media/(.+).ico$ /var/netscaler/gui/vpn/scripts/linux/$1.sig" >> /var/log/netscaler_config.log # 3. Simulate C2 Traffic: HTTP Header Injection (using curl to mimic web traffic) # We use -H to inject the specific headers identified in the rule curl -H "HTTP_X_UX: true" -H "HTTP_NSC_LDAP: active" http://localhost/index.php # 4. Simulate C2 Traffic: Numeric UX Header curl -H "HTTP_X_UX_99: payload" http://localhost/index.php -
Cleanup Commands:
# Remove simulated log entries (if they were written to a local file for testing) sed -i '/AddHandler application/x-httpd-php .deb/d' /var/log/netscaler_config.log sed -i '/AliasMatch ^/vpn/media/(.+).ico$/d' /var/log/netscaler_config.log