Threat actors are actively exploiting a critical pre-authentication command injection vulnerability in Citrix NetScaler ADC and NetScaler Gateway, and the post-exploitation tradecraft observed by LevelBlue's Threat Hunting Operations & Research (THOR) team should concern every organization with a NetScaler sitting on its perimeter. Attackers are dropping web shells mapped to CSS-like URLs to blend into legitimate static content traffic, creating superuser accounts for durable access, and attempting to steal NetScaler configuration data — which frequently contains LDAP bind credentials, SAML/OAuth secrets, and network topology that enables deeper compromise.
If you run NetScaler ADC or Gateway — especially as a VPN, ICA proxy, or AAA virtual server — treat this as an active intrusion scenario, not a patch ticket. Patching alone does not evict an attacker who already has a web shell and a rogue nsroot-equivalent account.
What Happened
Across multiple customer environments, LevelBlue THOR analysts identified a consistent post-exploitation pattern following exploitation of a pre-authentication command injection in NetScaler ADC/Gateway:
- Initial access: Unauthenticated command injection against the internet-facing NetScaler management or gateway interface.
- Web shell deployment: Malicious payloads written to the NetScaler web content directories, then mapped to URLs that look like ordinary CSS (stylesheet) requests — an evasion technique designed to defeat both log review (CSS requests are ubiquitous and rarely scrutinized) and naive file-extension-based detections.
- Privilege entrenchment: Creation of superuser-level accounts on the appliance, giving the actor persistent administrative access that survives reboots and survives removal of the original web shell.
- Objective execution: Attempted theft of NetScaler configuration data. The
ns.confand associated configuration stores are a goldmine: they can contain directory service credentials, certificate private key references, session policies, and internal addressing — everything an actor needs to pivot from the edge into the identity layer.
This is the classic NetScaler playbook we've watched evolve since the CitrixBleed era: edge device → credential harvest → identity compromise → lateral movement. The CSS-URL masquerading is the noteworthy refinement — it directly targets the blind spots in how most teams monitor web traffic to appliances.
Technical Analysis
Affected Products
- Citrix NetScaler ADC (formerly Citrix ADC)
- Citrix NetScaler Gateway (formerly Citrix Gateway)
Any internet-exposed instance — particularly those configured as a Gateway (VPN, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server — should be considered at risk. Consult the Citrix Security Bulletin applicable to your release train and confirm you are on a patched build. Note that the news reporting focuses on the post-exploitation activity, meaning organizations that patched late or never patched may already be compromised.
Attack Chain (Defender's View)
| Stage | Observable Behavior |
|---|---|
| Exploitation | Abnormal HTTP requests to the appliance immediately preceding process or file artifacts; requests with injected shell metacharacters |
| Web shell install | New files appearing under NetScaler web-served paths (e.g., /netscaler/ns_gui/, /var/netscaler/gui/, VPN portal content directories); nshttpd/web server processes spawning shells or interpreters |
| CSS-URL masquerading | HTTP requests to *.css-looking paths that return non-CSS content, accept POST bodies, or correlate with command execution |
| Persistence | New entries in the NetScaler user configuration (add system user, bind system user ... superuser equivalent), unexpected admin accounts visible via show system user |
| Collection/exfil | Reads of ns.conf, /flash/nsconfig/, outbound connections from the appliance to unfamiliar destinations |
Exploitation Status
Confirmed active in-the-wild exploitation across multiple customer environments per LevelBlue THOR's telemetry. This is not theoretical. Assume that any unpatched, internet-facing NetScaler has already been probed and that successful exploitation may have occurred weeks before detection.
Detection & Response
The highest-fidelity signals for this campaign are: (1) web server processes on the appliance spawning command interpreters, (2) new or modified files in web-served directories, (3) creation of privileged system users, and (4) anomalous requests to static-looking resources. The detections below target exactly those behaviors.
---
title: NetScaler Web Server Process Spawning Shell or Interpreter
id: 3f8c2a91-7b4e-4d2a-9c61-8e5f0a1b2c3d
status: experimental
description: Detects NetScaler web server processes (nshttpd, httpd, nginx, php) spawning command interpreters or scripting engines — a strong indicator of web shell execution on the appliance following command injection.
references:
- https://thehackernews.com/2026/10/citrix-netscaler-post-exploitation.html
- https://attack.mitre.org/techniques/T1505/003/
- https://attack.mitre.org/techniques/T1059/004/
author: Security Arsenal
date: 2026/10/20
tags:
- attack.persistence
- attack.t1505.003
- attack.execution
- attack.t1059.004
logsource:
category: process_creation
product: linux
detection:
selection_parent:
ParentImage|endswith:
- '/nshttpd'
- '/httpd'
- '/nginx'
- '/php'
- '/php-cgi'
selection_child:
Image|endswith:
- '/sh'
- '/bash'
- '/dash'
- '/python'
- '/python3'
- '/perl'
- '/php'
- '/curl'
- '/wget'
- '/nc'
- '/nsenter'
condition: selection_parent and selection_child
falsepositives:
- Rare; legitimate NetScaler maintenance scripts are typically spawned by cron or CLI sessions, not the web server process
level: critical
---
title: NetScaler Suspicious File Written to Web-Served Directory
id: 8a1d4e52-3c9f-4b7a-a5d2-6f0e1c8b9a4d
status: experimental
description: Detects creation of new files in NetScaler web content directories, including files with CSS-style names that may be web shells masquerading as static assets, as observed in this campaign.
references:
- https://thehackernews.com/2026/10/citrix-netscaler-post-exploitation.html
- https://attack.mitre.org/techniques/T1505/003/
- https://attack.mitre.org/techniques/T1036/
author: Security Arsenal
date: 2026/10/20
tags:
- attack.persistence
- attack.t1505.003
- attack.defense_evasion
- attack.t1036
logsource:
category: file_event
product: linux
detection:
selection_paths:
TargetFilename|contains:
- '/netscaler/ns_gui/'
- '/var/netscaler/gui/'
- '/netscaler/portal/'
- '/var/vpn/'
- '/vpn/'
filter_known_static:
TargetFilename|contains:
- '/netscaler/ns_gui/eb/'
- '.log'
condition: selection_paths and not filter_known_static
falsepositives:
- Firmware upgrades and customization packages legitimately write to these paths; correlate against change windows and recent builds
level: high
---
title: NetScaler Privileged System User Creation
id: 5c7e9b13-2d4a-4f8c-b1e7-9a3d5f6c8e2b
status: experimental
description: Detects creation or privilege binding of system users on NetScaler appliances via audit log patterns — attackers in this campaign created superuser accounts for persistent administrative access.
references:
- https://thehackernews.com/2026/10/citrix-netscaler-post-exploitation.html
- https://attack.mitre.org/techniques/T1136/
- https://attack.mitre.org/techniques/T1098/
author: Security Arsenal
date: 2026/10/20
tags:
- attack.persistence
- attack.t1136
- attack.privilege_escalation
- attack.t1098
logsource:
category: process_creation
product: linux
detection:
selection:
CommandLine|contains:
- 'add system user'
- 'bind system user'
- 'set system user'
- 'add ns user'
condition: selection
falsepositives:
- Legitimate administrator provisioning; alert on any execution outside documented change windows or from unexpected source sessions
level: high
// Hunt for NetScaler post-exploitation: shell execution, web shell file writes, and rogue user creation
// Ingest NetScaler syslog/audit logs into Sentinel via CEF or Syslog connector
let Lookback = 14d;
union isfuzzy=true
// 1) Command injection / shell execution patterns in NetScaler syslog
(Syslog
| where TimeGenerated > ago(Lookback)
| where Computer has_any ("netscaler", "ns", "adc") or ProcessName has_any ("nshttpd", "httpd")
| where SyslogMessage has_any ("/bin/sh", "/bin/bash", "python", "perl", "curl http", "wget http", "chmod +x", "/tmp/", "/var/tmp/")
| project TimeGenerated, Computer, ProcessName, SyslogMessage, HostIP),
// 2) Rogue system user creation and privilege binding from NetScaler audit messages
(CommonSecurityLog
| where TimeGenerated > ago(Lookback)
| where DeviceVendor == "Citrix" or DeviceProduct has "NetScaler"
| where Message has_any ("add system user", "bind system user", "superuser", "add ns user", "CMD_EXECUTED")
| project TimeGenerated, DeviceName, SourceIP, SourceUserName, Message),
// 3) Anomalous requests to CSS-looking URLs carrying POST bodies or shell indicators
(CommonSecurityLog
| where TimeGenerated > ago(Lookback)
| where DeviceVendor == "Citrix" or DeviceProduct has "NetScaler"
| where RequestURL endswith ".css" or RequestURL contains ".css?"
| where RequestMethod == "POST"
or RequestURL has_any ("cmd=", "exec", "shell", "%3B", "%24%28", "${", "|base64")
| project TimeGenerated, DeviceName, SourceIP, RequestMethod, RequestURL, RequestPayload)
| order by TimeGenerated desc
-- Velociraptor hunt: NetScaler web shell artifacts and rogue superuser accounts
-- Targets: unexpected files in web-served directories, modified ns.conf users, and suspicious processes
-- 1) Recently modified files in NetScaler web content directories (potential CSS-masqueraded shells)
SELECT FullPath, Size, Mtime, Ctime,
parse_string_with_regex(string=FullPath, regex='\.(?P<Ext>[^.]+)$').Ext AS Extension
FROM glob(globs=['/netscaler/ns_gui/**/*.css', '/netscaler/ns_gui/**/*.php',
'/var/netscaler/gui/**/*.css', '/var/netscaler/gui/**/*.php',
'/var/vpn/**/*.php', '/netscaler/portal/**/*.css'])
WHERE Mtime > now() - 60*60*24*30
ORDER BY Mtime DESC
-- 2) Shells or interpreters running with web server parentage
SELECT Pid, Ppid, Name, Exe, CommandLine, Username, CreateTime
FROM pslist()
WHERE Name =~ '^(sh|bash|dash|python|perl|php|nc)$'
OR CommandLine =~ 'cmd=|/bin/sh|base64 -d|curl http|wget http'
-- 3) Enumerate configured system users from ns.conf for rogue superuser review
SELECT FullPath, Size, Mtime,
read_file(filename=FullPath) AS ConfigContent
FROM glob(globs=['/flash/nsconfig/ns.conf'])
#!/bin/bash
# NetScaler compromise assessment & hardening verification script
# Run via shell access on the appliance (drop to shell from the CLI)
# Review output off-box; do not pipe anything to sh on the appliance itself.
echo "===== [1] Current build — verify against Citrix Security Bulletin ====="
cat /flash/nsconfig/.build_version 2>/dev/null
nsversion 2>/dev/null || echo "Run 'show ns version' from the NetScaler CLI"
echo "===== [2] Recently modified files in web-served directories (last 30 days) ====="
find /netscaler/ns_gui /var/netscaler/gui /var/vpn /netscaler/portal \
-type f \( -name '*.css' -o -name '*.php' -o -name '*.js' -o -name '*.xml' \) \
-mtime -30 -exec ls -la {} \; 2>/dev/null
echo "===== [3] Files with CSS names containing non-CSS content (shell masquerade check) ====="
for f in $(find /netscaler/ns_gui /var/netscaler/gui -name '*.css' -type f 2>/dev/null); do
if head -c 512 "$f" | grep -qiE '<\?php|eval\(|system\(|/bin/sh|passthru|shell_exec|exec\('; then
echo "SUSPICIOUS: $f"
head -c 256 "$f"; echo
fi
done
echo "===== [4] Configured system users — look for accounts you did not provision ====="
grep -E 'add system user|bind system user' /flash/nsconfig/ns.conf 2>/dev/null
echo "===== [5] Processes spawned by web server (web shell activity) ====="
ps aux | grep -E 'nshttpd|httpd' | grep -v grep
ps aux | awk '$3 ~ /sh|bash|python|perl/ {print}' 2>/dev/null
echo "===== [6] Outbound connections from the appliance (exfil/C2 review) ====="
netstat -an 2>/dev/null | grep ESTABLISHED | grep -vE '127\.0\.0\.1|::1'
echo "===== [7] New or unexpected files in /tmp and /var/tmp (last 14 days) ====="
find /tmp /var/tmp -type f -mtime -14 -exec ls -la {} \; 2>/dev/null
echo "===== [8] Recent authentication log review (unexpected admin logins) ====="
grep -iE 'login|authentication' /var/log/ns.log 2>/dev/null | tail -n 50
echo ""
echo "NEXT STEPS: (a) If any suspicious artifacts found, preserve /flash/nsconfig and logs before remediation."
echo "(b) Upgrade to the fixed build per the Citrix Security Bulletin for your release train."
echo "(c) After patching: delete rogue system users, rotate ALL credentials referenced in ns.conf"
echo " (LDAP bind accounts, service accounts), revoke and reissue certificates, and invalidate sessions."
echo "(d) Restrict management interface (NSIP) exposure to a dedicated management network / jump host."
Remediation
-
Patch immediately. Identify your NetScaler ADC/Gateway release train and build, then upgrade to the fixed build specified in the applicable Citrix Security Bulletin. Do not treat "EOL" builds as a reason to delay — unsupported builds must be upgraded to a supported release. If CISA adds the underlying vulnerability to the Known Exploited Vulnerabilities catalog, federal deadlines apply, but every sector should treat this as patch-now given confirmed in-the-wild exploitation.
-
Assume breach — hunt before and after patching. Patching closes the door; it does not remove web shells or rogue accounts already inside. Run the assessment script above, review
ns.conffor unauthorizedsystem userentries and policy changes, and inspect web content directories for files whose content doesn't match their extension. -
Evict persistence. Delete any system users that cannot be tied to a documented change record. Check for unauthorized command policies, responder/rewrite policies, and custom portal themes — all historically abused as NetScaler persistence mechanisms.
-
Rotate everything the config touched. If configuration data was accessed, assume compromise of: LDAP/AD bind account credentials, RADIUS/TACACS shared secrets, SAML/OAuth client secrets, and TLS private keys. Rotate credentials, reissue certificates, and force re-authentication of all gateway sessions.
-
Reduce the attack surface. The NetScaler management interface (NSIP) must never be internet-reachable. Restrict it to a dedicated management VLAN with jump-host access, enforce MFA on all administrative access, and disable the management GUI on SNIPs.
-
Forward telemetry. Ship NetScaler syslog, audit (
ns.log), and web access logs to your SIEM so the KQL and Sigma detections above have data to work with. Appliance-local logs are the first thing a competent attacker clears. -
Rebuild if compromised. If you confirm web shell presence or rogue superuser accounts on an appliance that handles authentication, the conservative and defensible answer is a clean rebuild from a known-good backup taken before the exposure window — followed by full credential rotation. NetScaler configurations are highly scriptable; use the incident as the forcing function for config-as-code.
Related Resources
Security Arsenal Penetration Testing Services AlertMonitor Platform Book a SOC Assessment vulnerability-management Intel Hub
Is your security operations ready?
Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.