← Back to blog

Citrix NetScaler Exploited to Create Superusers and Deploy Stealthy Web Shells

Attackers are leveraging a critical Citrix NetScaler vulnerability to gain persistent access and exfiltrate sensitive data. New post-exploitation techniques involve creating superuser accounts and mapping web shells to benign-looking URLs.

TL;DR

  • Threat actors exploited CVE-2026-XXXX in Citrix NetScaler ADC/Gateway pre-authentication systems.
  • Post-exploitation includes creation of superuser accounts for persistent access.
  • Web shells were mapped to CSS-like file paths to evade detection.
  • Sensitive configuration data was targeted for theft in affected environments.
  • Organizations using NetScaler should audit accounts and inspect web-accessible directories.

A critical pre-authentication command injection vulnerability in Citrix NetScaler ADC and Gateway continues to be actively exploited by threat actors. Security researchers from LevelBlue's THOR team have uncovered advanced post-exploitation behaviors, including the creation of high-privilege user accounts and deployment of web shells disguised as legitimate assets.

These tactics enable attackers to maintain long-term access while evading traditional detection mechanisms. The隐蔽 nature of these payloads—particularly those masquerading as CSS files—underscores the importance of behavioral anomaly detection in web-facing infrastructure.

Vulnerability Overview

  • The exploited flaw is a pre-authentication command injection vulnerability affecting Citrix NetScaler ADC and Gateway appliances.
  • No authentication is required for initial compromise, making it highly attractive to opportunistic attackers.
  • Successful exploitation allows remote code execution on the underlying system.

Post-Exploitation Tactics

  • Attackers created new superuser-level accounts to ensure continued administrative access.
  • Web shells were deployed and mapped to URLs resembling common static assets like CSS files.
  • This technique helps bypass content-based security filters and blends into normal web traffic patterns.
  • Exfiltration efforts focused on stealing NetScaler configuration data, which could reveal internal network topology and credentials.

Detection and Mitigation Recommendations

  • Audit all local user accounts on NetScaler instances for unauthorized additions, especially those with administrative privileges.
  • Monitor web-accessible directories for unexpected or obfuscated file uploads that may resemble legitimate assets.
  • Implement strict egress filtering and logging on management interfaces to detect suspicious outbound connections.
  • Apply official patches from Citrix immediately and consider network segmentation to limit lateral movement potential.

Sources

Sources

Security email updates

One digest email when we publish new security articles (TL;DR plus links to read more). Unsubscribe anytime from the message footer. See our Privacy Policy.