INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Citrix NetScaler Flaw Exploited to Deploy Web Shells and Steal

| 2026-10-08 12:56 CRITICAL HIGH EXPLOITED VULNERABILITY PHISHING & SOCIAL ENGINEERING
Executive Summary
AI-generated
Hackers are exploiting CVE-2026-88771, a critical Citrix NetScaler vulnerability, to run commands, install web shells, and collect appliance configuration data. The identified entity behind the attack is LevelBlue's Threat Hunt Operations & Research (THOR) team, although no specific organisation has been attributed in either source. This attack affects approximately 45 IP addresses associated with compromised systems. The attackers exploit a pre-authentication command-injection vulnerability affecting Citrix NetScaler ADC and NetScaler Gateway to execute malicious scripts designed to maintain access and send stolen files to attacker infrastructure.
Technical Mitigations AI-generated
• Apply the vendor fix for CVE-2026-4368, CVE-2026-19490 and treat internet-facing systems that were not patched in time as potentially compromised until verified.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected

Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.

ww•••••.io
do•••••.do
ww•••••.com
ct•••••.receiver
47.230.•••.•••
143.198.•••.•••
23.27.•••.•••
87.224.•••.•••
re•••••.css
ma•••••.py
hxxp://••••••••••••••••••••
hxxp://••••••••••••••••••••
hxxp://••••••••••••••••••••
hxxp://••••••••••••••••••••
6f5a2a••••••••••••••••••••••••••••••••••••••••••••••••••••••••••
e9fe43••••••••••••••••••••••••••••••••••••••••••••••••••••••••••
974b69••••••••••••••••••••••••••••••••••••••••••••••••••••••••••
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2026-4368CVE-2026-4368 CVE-2026-19490CVE-2026-19490 CVE-2026-88772CVE-2026-88772 CVE-2026-88778CVE-2026-88778 CVE-2026-3055CVE-2026-3055 CVE-2026-88771CVE-2026-88771 CVE-2026-88773CVE-2026-88773
Target & Sectors
NORTH_AMERICA NORTH_AMERICA EUROPE EUROPE BENELUX BENELUX technologytechnology financefinance legallegal governmentgovernment educationeducation
Incident Timeline
‎late 2021
Threat actors used spear-phishing to exploit Citrix NetScaler vulnerabilities, which the vendor had previously identified as being exploited multiple times.
general_metric 26 times
‎November 2021
Threat actors used spear-phishing to exploit Citrix vulnerabilities, which were previously flagged by CISA as actively exploited since November 2021.
general_metric 26 times
tactic Ransomware
‎September 24, 2026
A malicious cyber actor exploited a Citrix NetScaler Gateway zero-day vulnerability on September 24, 2026.
‎2026/09/24
The Dutch National Cyber Security Centre (NCSC-NL) reportedly sent a pre-notification to organizations in the Netherlands warning of active exploitation of Citrix NetScaler via CVE-2026-88772.
vulnerability CVE-2026-88772
target_region Netherlands
organisation the Dutch National Cyber Security Centre
organisation NCSC-NL
‎September 24
Threat actors used zero-day attacks to exploit Citrix NetScaler Gateway CVE-2026-88771 and CVE-2026-88772 three days before the vulnerabilities were publicly disclosed.
vulnerability CVE-2026-88771
vulnerability CVE-2026-88772
organisation GreyNoise
general_metric 88772 CVE-2026
organisation a Citrix NetScaler Gateway
‎Sept. 24
GreyNoise observed an unsuccessful exploitation attempt against a Citrix NetScaler Gateway on September 24.
organisation GreyNoise
‎September 27, 2026
Threat actors used spear-phishing to target Citrix users, resulting in the exploitation of eight vulnerabilities affecting NetScaler Application Delivery Controller (ADC) and NetScaler Gateway.
organisation NetScaler Gateway
organisation NetScaler Application
‎September 27
Threat actors used spear-phishing to exploit previously disclosed vulnerabilities in unpatched Citrix NetScaler deployments.
tactic T1588.006 - Vulnerabilities
attribution NetScaler
attribution Known Exploited
attribution KEV
‎September 30
The US government mandated FCEB agencies to secure all vulnerable Citrix appliances by September 30, following the addition of CVE-2026-88771 and CVE-2026-88772 to its KEV Catalog.
vulnerability CVE-2026-88771
vulnerability CVE-2026-88772
tactic T1588.006 - Vulnerabilities
attribution Known Exploited
attribution KEV
general_metric 26 times
attribution Federal Civilian Executive Branch
attribution FCEB
‎Oct 01, 2026
Threat actors have been observed exploiting a critical pre-authentication command injection vulnerability in Citrix NetScaler ADC and NetScaler Gateway to drop web shells.
organisation NetScaler Gateway
organisation Citrix NetScaler ADC
organisation Vulnerability / Web Security
‎2026/10/08
Threat actors are actively exploiting two critical Citrix NetScaler zero-day vulnerabilities, CVE-2026-88771 and CVE-2026-88772, to gain root access, install stealthy web shells, and move into victim networks.
organisation CVE-2026
organisation Citrix NetScaler
organisation NetScaler CVE-2026
organisation NetScaler Gateway
organisation Citrix NetScaler ADC
organisation NetScaler
organisation LevelBlue
organisation Threat Hunt Operations & Research
organisation THOR
organisation NSPPE
organisation NetScaler ADC
organisation DTLS
organisation Palo Alto Networks
organisation Counter Threat Unit
organisation Cyber Security News
organisation Mandiant Consulting
organisation Google
organisation NCSC-NL
organisation the Dutch National Cyber Security Center
organisation IP
infrastructure 23,000 IP addresses
organisation PHP
organisation CSS
organisation /etc/httpd.conf
infrastructure 64.94.85
infrastructure 31.56.197
infrastructure 23.27.143
organisation Citrix NetScaler Gateway
organisation Mandiant
organisation the NetScaler Packet Processing Engine
organisation CVSS
organisation TCP
organisation Modify
organisation NetScaler CSS
organisation GreyNoise
organisation AliasMatch
organisation /bin/sh
organisation EDR
organisation NFL
organisation CHANEL
organisation CyberScoop
organisation NetScaler Console
Tactical Metrics
Metrics
infrastructure
‎64.94.85
Software Version
Metrics
infrastructure
‎31.56.197
Software Version
Metrics
infrastructure
‎23.27.143
Software Version
Metrics
infrastructure
23,000
Ip Addresses