Back to Intelligence

CVE-2026-88771 Citrix NetScaler Pre-Auth Command Injection: pitboss/NSPPE Web Shell and Credential-Theft Hunt Pack

SA
Security Arsenal Team
October 1, 2026
10 min read

Live OTX pulse data from AlienVault and LevelBlue THOR indicates active exploitation of CVE-2026-88771, a critical pre-authentication command-injection flaw affecting Citrix NetScaler ADC and NetScaler Gateway. The activity is clustered around edge identity infrastructure rather than endpoint malware: attackers are landing on internet-facing gateways, executing commands before authentication, creating attacker-controlled access, and pulling second-stage tooling such as main.py and update_c08937.pl. The pulse tags point to a full intrusion chain: configuration-exfiltration, credential-creation, web-shell, reverse-shell and command-injection.

The most telling artifacts are malicious authentication events containing usernames with pitboss and NSPPE strings. NSPPE is a strong NetScaler-specific breadcrumb because it references the NetScaler packet processing engine context; pitboss appears to be an operator handle or toolkit marker. Observed infrastructure includes multiple IPv4 addresses and a staging URL, http://64.94.85.67:443/update_c08937.pl, which is consistent with Perl-based payload retrieval over an HTTP URL using a TLS-associated port but plain HTTP scheme. That mismatch is useful for detection because it can indicate improvised tooling, misconfigured redirectors, or deliberately noisy staging.

The collective assessment is an opportunistic-to-targeted edge-device intrusion campaign focused on stealing NetScaler configuration, harvesting credentials and session material, and establishing durable access into environments that rely on NetScaler for VPN, ICA proxy, AAA or load-balanced application delivery. Even where the actor is unknown, the objective is clear: convert edge-device command execution into identity dominance by capturing gateway configs, ns.conf secrets, LDAP bind credentials, session cookies, local accounts and network trust paths.

Threat Actor / Malware Profile

Attribution is currently unknown, and the OTX pulse does not name a mature malware family beyond two file artifacts: main.py and update_c08937.pl. Treat these as operator tooling rather than a single branded infostealer. The profile is consistent with hands-on-keyboard exploitation of an edge appliance followed by lightweight script staging.

Distribution method: exploitation of internet-exposed NetScaler ADC/Gateway management or gateway virtual servers vulnerable to CVE-2026-88771. The pre-authentication nature means valid credentials are not required for initial command execution, making exposed appliances, forgotten test gateways and unmanaged ADC pairs high-risk.

Payload behavior: the Perl script update_c08937.pl likely acts as a fetcher, implant or persistence helper retrieved from port 443 over HTTP. main.py suggests a Python stage for parsing configuration, extracting secrets, automating reverse-shell setup or credential dumping. The pulse explicitly associates the activity with web-shell deployment, credential creation and reverse-shell behavior, so defenders should expect post-exploitation commands to add local users, write files under NetScaler filesystem paths, modify rc or startup scripts, and open outbound connections to attacker-controlled IPs.

C2 communication: the IOC set is IPv4-heavy with one URL staging point. The use of 64.94.85.67:443 over http is suspicious and should be treated as a high-confidence hunting pivot. Additional IPv4 indicators 45.141.21.130, 173.40.135.209, 47.230.224.154, 62.133.62.80, 70.172.58.168 and 31.56.197.72 should be considered potential scan, exploit, staging or reverse-shell infrastructure until disproven.

Persistence mechanism: likely creation of unauthorized local or AAA-linked accounts, especially usernames containing pitboss or NSPPE; modification of NetScaler configuration; web shells placed in web-accessible directories; startup hooks via rc.conf, cron, nsapimgr or custom scripts; and possible SSH keys if shell access is enabled. On NetScaler, persistence can survive simple credential resets if configuration is rewritten or malicious commands are injected into boot-time execution paths.

Anti-analysis techniques: no packing or sandbox evasion is reported, but edge-device intrusions are inherently telemetry-poor. Expect log tampering on the appliance, use of legitimate admin channels after credential creation, deletion of staged scripts after execution, and living-off-the-land utilities such as perl, python, curl, wget, nc, bash and openssl rather than a conspicuous binary payload.

IOC Analysis

The indicator set contains one CVE, seven IPv4 addresses and one URL. CVE-2026-88771 is the exposure pivot: identify every NetScaler ADC/Gateway build, confirm firmware level, disable unnecessary management exposure, and check whether authentication logs contain anomalous pre-auth or shell-adjacent commands. The IPv4 addresses should be operationalized at multiple layers: block at egress proxy and firewall, alert in DNS and NetFlow if historically observed, enrich against ASN and hosting provider, and retrohunt proxy, VPN, EDR network events, Zeek/Suricata and cloud firewall logs for at least 90 days.

The URL http://64.94.85.67:443/update_c08937.pl is the highest-value detection artifact because it combines protocol, port, host and filename. SOC teams should decode it into atomic indicators: host 64.94.85.67, tcp/443, uri /update_c08937.pl, filename update_c08937.pl and scheme http. Tooling that helps includes Zeek http.log and conn.log for URI and port anomalies, Suricata Emerging Threats and custom rules for the URI, Sigma for process and command-line telemetry, Microsoft Sentinel or Splunk for joins across CommonSecurityLog, DeviceNetworkEvents and firewall logs, and NetScaler syslog/AppFlow for authentication and command execution context. Because hashes are not provided in the pulse sample, prioritize behavior and network indicators over hash-only blocking.

Detection Engineering

The following Sigma YAML packages three behavior-led detections for edge exploitation, suspicious authentication artifacts and script staging activity.

YAML
---
title: Citrix NetScaler CVE-2026-88771 Exploitation Authentication Artifacts
id: 8b6f2d24-9e5b-4f64-b0b5-cve20268877101
status: experimental
description: Detects suspicious NetScaler authentication or shell context artifacts containing pitboss or NSPPE strings associated with CVE-2026-88771 exploitation.
author: Security Arsenal
date: 2026/10/01
references:
  - https://www.levelblue.com/blogs/spiderlabs-blog/citrix-netscaler-cve-2026-88771-observed-exploitation-artifacts-and-hunt-indicators
logsource:
  product: citrix
  service: netscaler
detection:
  selection_user:
    - User|contains: pitboss
    - User|contains: NSPPE
    - Message|contains: pitboss
    - Message|contains: NSPPE
  selection_context:
    - EventType|contains: login
    - EventType|contains: auth
    - Message|contains: shell
    - Message|contains: command
  condition: selection_user and selection_context
falsepositives:
  - Legitimate administrative usernames containing NSPPE are unlikely but possible in lab naming conventions.
level: critical
tags:
  - attack.t1190
  - attack.t1136
  - attack.t1078
---
title: Script Staging or Execution of update_c08937.pl or main.py
id: 7a4c9d10-31f7-4f27-a0bb-cve20268877102
status: experimental
description: Detects process execution or command lines referencing update_c08937.pl or main.py, including fetch-and-execute patterns using perl, python, curl or wget.
author: Security Arsenal
date: 2026/10/01
references:
  - https://www.levelblue.com/blogs/spiderlabs-blog/citrix-netscaler-cve-2026-88771-observed-exploitation-artifacts-and-hunt-indicators
logsource:
  category: process_creation
detection:
  selection_img:
    Image|endswith:
      - perl
      - perl.exe
      - python
      - python3
      - python.exe
      - curl
      - curl.exe
      - wget
      - wget.exe
      - sh
      - bash
  selection_cli:
    CommandLine|contains:
      - update_c08937.pl
      - main.py
      - 64.94.85.67
      - http://64.94.85.67:443/update_c08937.pl
  condition: selection_img and selection_cli
falsepositives:
  - Rare administrative scripts named main.py; validate path, parent process and remote destination.
level: high
tags:
  - attack.t1059
  - attack.t1105
  - attack.t1059.006
---
title: Outbound Connection to CVE-2026-88771 Observed Exploitation Infrastructure
id: 1d9f44de-0d94-4f1b-9b7e-cve20268877103
status: experimental
description: Detects network connections to IPv4 indicators reported for active Citrix NetScaler exploitation, staging and possible reverse-shell activity.
author: Security Arsenal
date: 2026/10/01
references:
  - https://www.levelblue.com/blogs/spiderlabs-blog/citrix-netscaler-cve-2026-88771-observed-exploitation-artifacts-and-hunt-indicators
logsource:
  category: network_connection
detection:
  selection_ip:
    DestinationIp:
      - 45.141.21.130
      - 173.40.135.209
      - 47.230.224.154
      - 62.133.62.80
      - 70.172.58.168
      - 31.56.197.72
      - 64.94.85.67
  filter_tls_normal:
    DestinationPort:
      - 443
    Initiated: true
  condition: selection_ip and not filter_tls_normal
falsepositives:
  - Threat intel enrichment systems and sandbox detonation may intentionally contact indicators.
level: critical
tags:
  - attack.t1071.001
  - attack.t1571
  - attack.t1105

Use this Sentinel hunt to correlate endpoint network telemetry, process launches and firewall or syslog events against the reported indicators and filenames.

KQL — Microsoft Sentinel / Defender
let Lookback = 90d;
let IPs = dynamic(["45.141.21.130","173.40.135.209","47.230.224.154","62.133.62.80","70.172.58.168","31.56.197.72","64.94.85.67"]);
let Names = dynamic(["update_c08937.pl","main.py","pitboss","NSPPE","CVE-2026-88771"]);
union isfuzzy=true
(
  DeviceNetworkEvents
  | where TimeGenerated > ago(Lookback)
  | where RemoteIP in (IPs) or RemoteUrl has_any (Names)
  | project TimeGenerated, DeviceName, InitiatingProcessAccountName, InitiatingProcessFileName, InitiatingProcessCommandLine, LocalIP, LocalPort, RemoteIP, RemotePort, RemoteUrl, Protocol, ActionType
  | extend Source = "DeviceNetworkEvents"
),
(
  DeviceProcessEvents
  | where TimeGenerated > ago(Lookback)
  | where ProcessCommandLine has_any (Names) or FileName has_any (dynamic(["perl","python","python3","curl","wget","nc","bash","sh"]))
  | project TimeGenerated, DeviceName, AccountName, FileName, ProcessCommandLine, FolderPath, SHA256, InitiatingProcessFileName, InitiatingProcessCommandLine
  | extend Source = "DeviceProcessEvents"
),
(
  CommonSecurityLog
  | where TimeGenerated > ago(Lookback)
  | where SourceIP in (IPs) or DestinationIP in (IPs) or Message has_any (Names) or SourceUserName has_any (dynamic(["pitboss","NSPPE"])) or DestinationUserName has_any (dynamic(["pitboss","NSPPE"]))
  | project TimeGenerated, DeviceVendor, DeviceProduct, Activity, SourceIP, DestinationIP, DestinationPort, SourceUserName, DestinationUserName, Message, AdditionalExtensions
  | extend Source = "CommonSecurityLog"
),
(
  SecurityEvent
  | where TimeGenerated > ago(Lookback)
  | where EventID in (4624,4625,4720,4722,4724,4732,4756)
  | where Account has_any (dynamic(["pitboss","NSPPE"])) or SubjectAccount has_any (dynamic(["pitboss","NSPPE"])) or TargetAccount has_any (dynamic(["pitboss","NSPPE"]))
  | project TimeGenerated, Computer, EventID, Activity, Account, SubjectAccount, TargetAccount, IpAddress, LogonType, Status
  | extend Source = "SecurityEvent"
)
| sort by TimeGenerated desc

Run this read-only PowerShell hunt from an elevated management host to check endpoints, jump boxes and any Windows-based NetScaler administration systems for indicator contact, suspicious local identities, staged files and persistence hooks.

PowerShell
$ErrorActionPreference = 'SilentlyContinue'
$IOCIPs = @('45.141.21.130','173.40.135.209','47.230.224.154','62.133.62.80','70.172.58.168','31.56.197.72','64.94.85.67')
$Names = @('update_c08937.pl','main.py','pitboss','NSPPE','CVE-2026-88771')
$Report = [System.Collections.Generic.List[object]]::new()

Get-NetTCPConnection | Where-Object { $IOCIPs -contains $_.RemoteAddress } | ForEach-Object {
  $p = Get-Process -Id $_.OwningProcess
  $Report.Add([pscustomobject]@{Type='NetworkConnection'; Host=$env:COMPUTERNAME; Detail=($_.LocalAddress + ':' + $_.LocalPort + ' -> ' + $_.RemoteAddress + ':' + $_.RemotePort); Process=$p.ProcessName; Path=$p.Path; Time=Get-Date})
}

Get-CimInstance Win32_Process | Where-Object { $cmd = $_.CommandLine; $Names | Where-Object { $cmd -like ('*' + $_ + '*') } } | ForEach-Object {
  $Report.Add([pscustomobject]@{Type='ProcessCommandLine'; Host=$env:COMPUTERNAME; Detail=$_.CommandLine; Process=$_.Name; Path=$_.ExecutablePath; Time=Get-Date})
}

Get-ChildItem -Path 'C:\','D:\' -Recurse -Force -ErrorAction SilentlyContinue | Where-Object { $Names | Where-Object { $PSItem.Name -like ('*' + $_ + '*') -or $PSItem.FullName -like ('*' + $_ + '*') } } | Select-Object -First 200 | ForEach-Object {
  $Report.Add([pscustomobject]@{Type='FileArtifact'; Host=$env:COMPUTERNAME; Detail=$_.FullName; Process=''; Path=$_.DirectoryName; Time=$_.LastWriteTime})
}

Get-LocalUser | Where-Object { $_.Name -match 'pitboss|NSPPE' } | ForEach-Object {
  $Report.Add([pscustomobject]@{Type='LocalUser'; Host=$env:COMPUTERNAME; Detail=('User=' + $_.Name + ' Enabled=' + $_.Enabled); Process=''; Path=''; Time=Get-Date})
}

Get-ChildItem 'HKLM:\SOFTWARE\Microsoft\Windows\CurrentVersion\Run','HKCU:\SOFTWARE\Microsoft\Windows\CurrentVersion\Run' | ForEach-Object {
  $key = $_.PSPath; $_.Property | ForEach-Object { $v = (Get-ItemProperty -Path $key -Name $_).$_; if ($Names | Where-Object { $v -like ('*' + $_ + '*') }) { $Report.Add([pscustomobject]@{Type='RunKey'; Host=$env:COMPUTERNAME; Detail=($key + ' ' + $_ + '=' + $v); Process=''; Path=$key; Time=Get-Date}) } }
}

Get-ScheduledTask | ForEach-Object { $t=$_; $txt = ($t.Actions | Out-String) + ' ' + ($t.Triggers | Out-String); if ($Names | Where-Object { $txt -like ('*' + $_ + '*') }) { $Report.Add([pscustomobject]@{Type='ScheduledTask'; Host=$env:COMPUTERNAME; Detail=$t.TaskName; Process=''; Path=$t.TaskPath; Time=Get-Date}) } }

$Report | Sort-Object Type, Detail | Format-List
if ($Report.Count -gt 0) { $Report | Export-Csv -NoTypeInformation -Path ('.\netscaler_cve_2026_88771_hunt_' + $env:COMPUTERNAME + '.csv') }

Response Priorities

Immediate: isolate or restrict management access to NetScaler ADC/Gateway interfaces; verify firmware against the vendor advisory for CVE-2026-88771; block all listed IPv4 indicators and the URL at egress proxy, firewall, DNS sinkhole and EDR network controls; hunt for pitboss and NSPPE strings in authentication, AAA, VPN and syslog data; search for update_c08937.pl, main.py and fetch-and-execute command lines; capture appliance memory, configuration, ns.conf backups, auth logs and shell history before rebooting; rotate any credentials stored in or reachable from NetScaler, including LDAP bind accounts and RADIUS shared secrets.

24 hours: perform identity verification for every administrative and VPN authentication path touching NetScaler. Reset local NetScaler accounts, AAA service accounts, AD admin accounts used from gateway jumps, API tokens and SSH keys. Review new local users, group membership changes, impossible travel, MFA fatigue prompts and session cookie reuse. Force reauthentication for NetScaler Gateway and ICA sessions, revoke refresh tokens where possible, and compare current ns.conf against a known-good backup for unauthorized vserver, policy, user, route or certificate changes.

1 week: harden architecture based on the edge-injection vector. Put NetScaler management behind a dedicated admin plane with allowlisting, remove gateway management from the public internet, enforce phishing-resistant MFA for admin access, centralize immutable syslog off the appliance, enable AppFlow/telemetry into the SIEM, deploy canary credentials in gateway configs, add egress controls so appliances cannot initiate arbitrary outbound HTTP, automate configuration drift detection for ns.conf and startup scripts, and create a repeatable emergency patch pipeline for ADC and Gateway images with pre-staged forensic snapshots.

Related Resources

Security Arsenal Incident Response Managed SOC & MDR Services AlertMonitor Threat Detection From The Dark Side Intel Hub

Is your security operations ready?

Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.