Mandiant researchers have disclosed that dozens of organizations have been compromised by attackers exploiting an unpatched vulnerability in Citrix NetScaler — and the intrusion activity ran undetected for at least three weeks before defenders caught on. The attacks are attributed to advanced, suspected state-sponsored threat groups, and Mandiant's assessment is blunt: more attacks are coming.
If you operate NetScaler ADC (formerly Citrix ADC) or NetScaler Gateway in your environment, treat this as an active incident until proven otherwise. Edge appliances like NetScaler sit at the most privileged position in your network — they terminate TLS, broker authentication, and front-end your most sensitive applications. A compromise here isn't a foothold; it's a skeleton key. Three weeks of undetected dwell time is enough for a patient actor to harvest credentials, establish redundant persistence, and stage for lateral movement deep into the environment.
This post breaks down what we know, how the attack pattern typically unfolds against NetScaler appliances, and — most importantly — the specific hunting queries, detection rules, and hardening steps your team should execute today.
Technical Analysis
What We Know
Per Mandiant's reporting via CyberScoop:
- Affected product: Citrix NetScaler ADC / NetScaler Gateway appliances running an unpatched software build.
- Attribution: Advanced threat actors with suspected state sponsorship. Mandiant has observed dozens of impacted organizations across multiple sectors.
- Dwell time: A minimum of three weeks between initial exploitation and detection. That is the critical number in this story — not the vulnerability itself, but the observability gap that allowed it to burn silently.
- Outlook: Mandiant explicitly expects additional exploitation, which is consistent with every prior NetScaler edge-device campaign: once exploitation is understood by multiple actors, unpatched appliances get swept indiscriminately.
Why NetScaler Is a Repeat Target
This is not the first time NetScaler has been the beachhead for state-sponsored intrusions, and the reasons are structural:
- Internet-facing by design. The management interface and gateway virtual servers are exposed to the internet in most deployments.
- Limited telemetry. NetScaler runs a hardened FreeBSD-based OS. Traditional EDR cannot be installed on the appliance. Most organizations forward little or no NetScaler logging to their SIEM, which is precisely how three weeks of activity went unnoticed.
- High-value post-exploitation position. Successful exploitation yields the ability to hijack authenticated sessions, capture credentials in transit, modify authentication flows, and pivot to internal systems — often without touching a single endpoint that has an EDR agent.
Typical Post-Exploitation Pattern on NetScaler
Based on prior NetScaler campaigns Mandiant and other responders have documented, post-exploitation activity against these appliances follows a recognizable shape:
- Webshell or malicious module deployment into the NetScaler web directories (
/netscaler/ns_gui/,/var/vpn/, or CGI paths) to maintain access across reboots. - Execution via the
nobodyorrootweb process context — shell commands spawned as children of the webserver process (httpd/nshttpdor NSPPE packet engine processes). - Credential harvesting by hooking or replacing authentication components (e.g., tampered
epascripts, modified login pages, or log scraping of/var/log/ns.logand authentication logs). - Anomalous outbound connections from the appliance — NetScaler should have a tightly bounded egress profile. New outbound destinations are high-fidelity indicators.
- Persistence via cron, rc scripts, or injected configuration that survives firmware upgrades in some cases — a technique seen in earlier NetScaler campaigns where webshells persisted across patching.
Exploitation Status
- Confirmed active in-the-wild exploitation — Mandiant has attributed dozens of breaches.
- Attribution: Suspected state-sponsored advanced threat groups.
- Scope: Dozens of organizations confirmed impacted; Mandiant expects the victim count to grow.
Defenders should check the Citrix security bulletin page and CISA's Known Exploited Vulnerabilities catalog for the formal advisory and CVE assignment as they are published, and subscribe to Citrix security notifications immediately if you have not already.
Detection & Response
The three-week detection gap is the real lesson here. NetScaler appliances emit rich logs — ns.log, httaccess.log, bash.log, notice.log, and shell history — but in most environments none of it reaches the SIEM. The detections below assume you are (or will be, after reading this) forwarding NetScaler Syslog to Microsoft Sentinel via a Syslog/CEF collector, and running endpoint visibility on the surrounding infrastructure.
Sigma Rules
These rules target the highest-fidelity behavioral indicators associated with NetScaler appliance compromise. The first two are written against Syslog ingestion from the appliance itself; the third covers downstream Windows endpoint behavior consistent with post-compromise lateral movement using harvested credentials.
---
title: NetScaler Web Process Spawning Shell or Command Execution
id: 3c8e2a41-7b5d-4f19-9c2a-6e1d8f3a5b7c
status: experimental
description: Detects shell or command execution spawned by the NetScaler webserver process, a hallmark of webshell activity following edge appliance exploitation.
references:
- https://cyberscoop.com/citrix-netscaler-zero-day-attacks-three-weeks-undetected/
- https://attack.mitre.org/techniques/T1505/003/
author: Security Arsenal
date: 2026/01/15
tags:
- attack.persistence
- attack.t1505.003
- attack.execution
logsource:
product: linux
service: syslog
detection:
selection_host:
Host|contains:
- 'netscaler'
- 'ns'
- 'adc'
selection_exec:
Message|contains:
- '/bin/sh'
- '/bin/bash'
- '/usr/bin/curl'
- '/usr/bin/wget'
- 'python'
- 'perl '
- 'nsapimgr'
filter_known_good:
Message|contains:
- 'nsconmsg'
- 'collect.cgi'
condition: selection_host and selection_exec and not filter_known_good
falsepositives:
- Legitimate NetScaler administrative scripts and health-check CGI execution
level: high
---
title: File Writes to NetScaler Web Interface Directories
id: 9f4d1b72-3a8c-4e56-b1d7-2c9e6a4f8d3b
status: experimental
description: Detects creation or modification of files in NetScaler web GUI and VPN portal directories, consistent with webshell or malicious CGI deployment observed in prior NetScaler campaigns.
references:
- https://cyberscoop.com/citrix-netscaler-zero-day-attacks-three-weeks-undetected/
- https://attack.mitre.org/techniques/T1505/003/
author: Security Arsenal
date: 2026/01/15
tags:
- attack.persistence
- attack.t1505.003
logsource:
product: linux
category: file_event
detection:
selection:
TargetFilename|contains:
- '/netscaler/ns_gui/'
- '/var/vpn/'
- '/var/netscaler/gui/'
- '/netscaler/portal/'
selection_ext:
TargetFilename|endswith:
- '.php'
- '.pl'
- '.cgi'
- '.sh'
condition: selection and selection_ext
falsepositives:
- Legitimate Citrix firmware updates and custom portal theme deployments (verify against change windows)
level: critical
---
title: Suspicious Authentication Anomaly Following NetScaler Session
id: 6b2e7c93-1d4f-4a28-8e6b-5f3a9c2d7e41
status: experimental
description: Detects impossible-travel or anomalous logon patterns against internal resources shortly after NetScaler Gateway sessions, indicative of session hijacking or credential theft from a compromised appliance.
references:
- https://cyberscoop.com/citrix-netscaler-zero-day-attacks-three-weeks-undetected/
- https://attack.mitre.org/techniques/T1078/
author: Security Arsenal
date: 2026/01/15
tags:
- attack.initial_access
- attack.t1078
- attack.t1550
logsource:
product: windows
service: security
detection:
selection:
LogonType:
- 3
- 10
IpAddress|contains:
- '10.'
- '172.16.'
- '192.168.'
selection_suspicious:
AuthenticationPackageName: 'NTLM'
condition: selection and selection_suspicious
falsepositives:
- Legacy applications using NTLM internally; tune to known NetScaler gateway source IPs and alert on first-seen account-to-host combinations
level: medium
KQL Hunt — Microsoft Sentinel
This query hunts NetScaler Syslog (ingested via a Syslog collector into the Syslog table) for webshell-consistent process execution, unusual outbound connections from the appliance, and writes to web directories. Run it over at least a 30-day lookback — given the confirmed three-week dwell time, a 7-day window is insufficient.
// Hunt: NetScaler appliance compromise indicators via Syslog ingestion
// Lookback: 30 days minimum given confirmed 3-week dwell time
let Lookback = 30d;
let NetScalerHosts = (
Syslog
| where TimeGenerated > ago(Lookback)
| where Computer has_any ("netscaler", "ns", "adc")
| summarize by Computer
);
// 1. Shell or tool execution observed in appliance logs
let SuspiciousExec =
Syslog
| where TimeGenerated > ago(Lookback)
| where Computer in (NetScalerHosts)
| where SyslogMessage has_any ("/bin/sh", "/bin/bash", "curl", "wget", "python", "perl", "base64", "nsapimgr")
| project TimeGenerated, Computer, ProcessName, SyslogMessage
| extend Indicator = "Shell/Tool Execution on Appliance";
// 2. Outbound connections to rare external destinations from the appliance
let SuspiciousEgress =
CommonSecurityLog
| where TimeGenerated > ago(Lookback)
| where DeviceProduct has_any ("NetScaler", "Citrix")
| where Direction == "Outbound" or isnull(Direction)
| summarize ConnectionCount = count(), FirstSeen = min(TimeGenerated), LastSeen = max(TimeGenerated)
by SourceIP, DestinationIP, DestinationPort
| where ConnectionCount < 50 // rare egress is more interesting than bulk replication traffic
| extend Indicator = "Rare Outbound Connection from Appliance";
// 3. Process execution on downstream hosts originating from gateway-adjacent systems
let DownstreamExec =
DeviceProcessEvents
| where TimeGenerated > ago(Lookback)
| where InitiatingProcessCommandLine has_any ("nsvpn", "netscaler", "citrix")
or FileName in~ ("powershell.exe", "cmd.exe", "wscript.exe", "rundll32.exe")
| where InitiatingProcessFileName has_any ("httpd", "nshttpd", "nsppe")
| project TimeGenerated, DeviceName, FileName, ProcessCommandLine, InitiatingProcessFileName
| extend Indicator = "Web Process Child Execution";
union SuspiciousExec, SuspiciousEgress, DownstreamExec
| order by TimeGenerated desc
Velociraptor VQL — Endpoint Hunt
NetScaler itself cannot run Velociraptor, but post-compromise activity lands on endpoints: harvested credentials get replayed, and gateway-adjacent jump boxes and session hosts are the first lateral targets. This artifact hunts Windows endpoints for persistence and execution artifacts consistent with an actor working outward from a compromised gateway.
-- Hunt: Post-NetScaler-compromise lateral movement artifacts on Windows endpoints
-- Focus: unusual service installs, Run-key persistence, and script interpreters
-- executed by accounts that authenticate through the gateway.
SELECT Pid, Ppid, Name, Exe, CommandLine, Username, CreateTime
FROM pslist()
WHERE (
-- Script interpreters launched with encoded or remote-fetch arguments
(Name =~ '(?i)powershell|pwsh|wscript|cscript|mshta|rundll32'
AND CommandLine =~ '(?i)(-enc|-ec\s|frombase64string|downloadstring|iex|invoke-expression|http[s]?://)')
-- Processes running from user-writable temp/public paths
OR Exe =~ '(?i)\\\\(users\\\\[^\\]+\\\\appdata|programdata|windows\\\\temp)\\\\'
)
AND NOT CommandLine =~ '(?i)(microsoft|sccm|intune|defender)'
ORDER BY CreateTime DESC
-- Hunt: Persistence mechanisms consistent with appliance-originated intrusion
-- Check Run keys and recently created services across the fleet.
SELECT Key.FullPath AS KeyPath,
Key.Name AS ValueName,
KeyData.value AS ValueData,
Key.Mtime AS ModifiedTime
FROM glob(globs='HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run*\\**',
accessor='registry')
WHERE ModifiedTime > now() - 60*60*24*30 -- keys modified in last 30 days
ORDER BY ModifiedTime DESC
Remediation Script
This Bash script runs on the NetScaler appliance (via SSH as nsroot) to perform an initial compromise assessment: enumerate web directory contents for unexpected scripts, check for rogue cron entries, review recent authentication log anomalies, and dump listening ports for comparison against a known-good baseline. This is a triage script, not a substitute for a forensic image — if anything fires, engage your IR retainer before remediation destroys evidence.
#!/bin/bash
# NetScaler ADC/Gateway Compromise Triage — run via SSH as nsroot
# Output: timestamped tarball for IR handoff
OUT="/var/tmp/ns_triage_$(date +%Y%m%d_%H%M%S)"
mkdir -p "$OUT"
# 1. Inventory executable content in web-served directories
find /netscaler/ns_gui /var/vpn /var/netscaler/gui /netscaler/portal \
-type f \( -name '*.php' -o -name '*.pl' -o -name '*.cgi' -o -name '*.sh' -o -name '*.py' \) \
-newermt '60 days ago' -exec ls -la {} \; > "$OUT/webdir_recent_scripts.txt" 2>/dev/null
# 2. Full web directory manifest with hashes for baseline diffing
find /netscaler/ns_gui /var/vpn -type f -exec md5 {} \; > "$OUT/webdir_hashes.txt" 2>/dev/null
# 3. Cron and startup persistence
crontab -l > "$OUT/crontab.txt" 2>/dev/null
ls -la /var/cron/tabs/ > "$OUT/cron_tabs.txt" 2>/dev/null
cat /etc/rc.conf > "$OUT/rc_conf.txt" 2>/dev/null
find /etc/rc.d /usr/local/etc/rc.d -type f -newermt '60 days ago' -exec ls -la {} \; > "$OUT/rc_recent.txt" 2>/dev/null
# 4. Authentication anomalies: failed logins, new admin accounts, shell access
zgrep -i 'login' /var/log/ns.log* | tail -5000 > "$OUT/ns_auth_events.txt" 2>/dev/null
grep -i 'user' /var/log/notice.log | tail -1000 > "$OUT/user_events.txt" 2>/dev/null
show ns aaauser 2>/dev/null > "$OUT/aaa_users.txt" || \
echo 'show ns aaauser' | nscli -U :localhost:nsroot > "$OUT/aaa_users.txt" 2>/dev/null
# 5. Network state: listening ports and established sessions
netstat -an > "$OUT/netstat.txt" 2>/dev/null
sockstat -l > "$OUT/listeners.txt" 2>/dev/null
# 6. Recent shell history and modified system files
find / -name '.bash_history' -o -name '.sh_history' 2>/dev/null | while read h; do
cp "$h" "$OUT/$(echo $h | tr '/' '_')" 2>/dev/null
done
# 7. Package and version inventory for patch-state verification
uname -a > "$OUT/version.txt"
cat /etc/version > "$OUT/ns_version.txt" 2>/dev/null
tar -czf "${OUT}.tar.gz" -C /var/tmp "$(basename $OUT)" && rm -rf "$OUT"
echo "[+] Triage bundle written to ${OUT}.tar.gz — preserve for IR before any cleanup."
Remediation
Act on this in the following order. Speed matters more than sequence elegance here — Mandiant expects the campaign to widen.
- Verify your build and patch immediately. Check your NetScaler ADC/Gateway build against the current Citrix security bulletin at https://support.citrix.com/support-home/knowledge-center-search and the Citrix Security Bulletins page. Apply the fixed build per the advisory. Do not assume that because you patched a prior NetScaler CVE you are covered — confirm the specific build number in the current bulletin.
- Patching is not eradication. Prior NetScaler campaigns demonstrated persistence that survived firmware updates. After patching, run the triage script above and diff web directory hashes against a known-good appliance or a fresh deployment. If you find webshells, rogue users, or unexpected cron entries, treat the appliance as compromised: rebuild from a clean image rather than cleaning in place.
- Rotate every credential the appliance touched. This includes: the
nsrootand all appliance admin accounts, LDAP/bind service accounts configured on the appliance, TLS private keys (reissue certificates — a compromised edge appliance means private key exposure is on the table), and any domain credentials used by gateway-authenticated users during the exposure window. - Restrict management interface exposure. The NSIP and management GUI should never be reachable from the internet. Enforce this at the perimeter firewall, not just on the appliance, and require jump-host access with MFA for all administrative sessions.
- Constrain appliance egress. NetScaler needs to reach Citrix licensing and your internal backends — nothing else. Deny all other outbound traffic from the appliance subnet and alert on violations. This single control would have surfaced the C2 channel in most edge-appliance intrusions.
- Fix the telemetry gap — this is the three-week problem. Forward all NetScaler Syslog (facility
local0–local7, includingns.log,httaccess.log,bash.log, andnotice.log) to your SIEM with at least 90 days of hot retention. Enable shell command logging. If your SIEM currently ingests zero NetScaler events, that is the finding to bring to your leadership this week. - Review the CISA Known Exploited Vulnerabilities catalog for the associated entry and its federal remediation deadline — KEV deadlines are a useful forcing function for internal prioritization even in the private sector: https://www.cisa.gov/known-exploited-vulnerabilities-catalog.
- Hunt retroactively. Given the confirmed dwell time, run the detections above across a minimum 30-day window. Extend to 90 days if your retention allows — three weeks was the minimum observed, not the ceiling.
- Engage IR support if anything fires. Suspected state-sponsored actors leave layered persistence. If you confirm compromise, you need memory capture and a full appliance image before reboot or rebuild — contact your IR retainer or book a SOC assessment with Security Arsenal before taking destructive remediation steps.
The uncomfortable takeaway from Mandiant's disclosure is not that another NetScaler vulnerability exists — it is that dozens of security programs had no eyes on one of the most critical devices in their network for three weeks. Edge appliance observability is not optional in 2026. If your SIEM can't tell you what your NetScaler did last Tuesday, that is your next project.
Related Resources
Security Arsenal Penetration Testing Services AlertMonitor Platform Book a SOC Assessment vulnerability-management Intel Hub
Is your security operations ready?
Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.