Citrix NetScaler Exploited to Create Superusers and Deploy Stealthy Web Shells
Attackers are leveraging a critical Citrix NetScaler vulnerability to gain persistent access and exfiltrate sensitive data. New post-exploitation techniques involve creating superuser accounts and mapping web shells to benign-looking URLs.
TL;DR
- Threat actors exploited CVE-2026-XXXX in Citrix NetScaler ADC/Gateway pre-authentication systems.
- Post-exploitation includes creation of superuser accounts for persistent access.
- Web shells were mapped to CSS-like file paths to evade detection.
- Sensitive configuration data was targeted for theft in affected environments.
- Organizations using NetScaler should audit accounts and inspect web-accessible directories.
A critical pre-authentication command injection vulnerability in Citrix NetScaler ADC and Gateway continues to be actively exploited by threat actors. Security researchers from LevelBlue's THOR team have uncovered advanced post-exploitation behaviors, including the creation of high-privilege user accounts and deployment of web shells disguised as legitimate assets.
These tactics enable attackers to maintain long-term access while evading traditional detection mechanisms. The隐蔽 nature of these payloads—particularly those masquerading as CSS files—underscores the importance of behavioral anomaly detection in web-facing infrastructure.
Vulnerability Overview
- The exploited flaw is a pre-authentication command injection vulnerability affecting Citrix NetScaler ADC and Gateway appliances.
- No authentication is required for initial compromise, making it highly attractive to opportunistic attackers.
- Successful exploitation allows remote code execution on the underlying system.
Post-Exploitation Tactics
- Attackers created new superuser-level accounts to ensure continued administrative access.
- Web shells were deployed and mapped to URLs resembling common static assets like CSS files.
- This technique helps bypass content-based security filters and blends into normal web traffic patterns.
- Exfiltration efforts focused on stealing NetScaler configuration data, which could reveal internal network topology and credentials.
Detection and Mitigation Recommendations
- Audit all local user accounts on NetScaler instances for unauthorized additions, especially those with administrative privileges.
- Monitor web-accessible directories for unexpected or obfuscated file uploads that may resemble legitimate assets.
- Implement strict egress filtering and logging on management interfaces to detect suspicious outbound connections.
- Apply official patches from Citrix immediately and consider network segmentation to limit lateral movement potential.
Sources
Sources
Security email updates
One digest email when we publish new security articles (TL;DR plus links to read more). Unsubscribe anytime from the message footer. See our Privacy Policy.