P.K. SHARMA

Cyber security intelligence, AI governance, practitioner analysis

LevelBlue adds a fourth NetScaler web shell disguise. Citrix says an update is not a cleanup

LevelBlue's 30 September report on CVE-2026-88771 names a hidden PHP file, a superuser account and a stylesheet lookalike URL, but gives no dates and no victim count. Citrix's own page now says an update does not remove compromise artifacts.

By Parminder Kumar Sharma · · 18 min read

A racked network appliance in a dark equipment room, with an investigator's laptop in front of it showing a list of blank rows, one of them drawn as a faint dotted amber outline to suggest a hidden file.

Six reports, four disguises

Six vendor reports now describe web shells on NetScaler appliances attacked through the two zero-days that Citrix fixed on 27 September. Sorted by what the request looks like and where the hidden file sits, they describe four different disguises: a package file, an icon and two stylesheets. The newest, in a report LevelBlue published on 30 September, is a hidden file called .local_journal that is served at URLs resembling a NetScaler stylesheet. Not one file name in any of the four will help you find another.

What that does not establish. It does not say how many appliances carry any of them. It does not say whether six reports mean six operators or one. LevelBlue gives no date for anything it saw and no count of the customer environments it came from, and it describes the web shell and the account without saying on how many appliances either was found. And it does not say what an update does to a web shell already in place. On that, Citrix's own page, last updated on 30 September, is the clearest source: an update "does not remove potential compromise artifacts".

This briefing covers only what LevelBlue's report adds. The timeline and the federal clock are in the earlier briefing on the 22 days before the patch, and the eight-flaw bulletin is in the briefing on the three-day clock. It stays at defender level: it names the artefacts vendors publish for hunting, and gives no commands, no payload content and no exploit steps.

What LevelBlue published, and what it left out

The post comes from LevelBlue's Threat Hunt Operations and Research team and is by analyst Sean Shirley with three contributors. It concerns CVE-2026-88771, the flaw Citrix describes as improper input validation that lets an unauthenticated attacker run arbitrary commands on every NetScaler ADC and Gateway in its default configuration. Citrix scores it 9.5 on CVSS 4.0, and NVD scores it 9.8 on CVSS 3.1. The post does not mention CVE-2026-88772, the flaw behind Mandiant's report.

In the order the post gives them, it reports login events whose username field carries attacker-controlled text, built around the watchdog-message words pitboss and NSPPE. It reports variants that only test a command, that fetch a script with curl or wget, or that copy or archive the configuration into a web directory. It analyses two second-stage payloads, a Python script and a Perl script. And it lists 23 indicators.

What LevelBlue's post states and does not state. Read in full on 1 October 2026; wording in quotation marks is the post's own.

TopicStatedNot stated
Which flawCVE-2026-88771, a "critical pre-authentication command-injection vulnerability".Any link to CVE-2026-88772 or to the activity in Mandiant's report.
WhereActivity found while hunting "across multiple customer environments".How many environments or appliances, or in which countries or sectors.
WhenNothing. The post is dated 30 September.A first or last sighting. A LevelBlue post of 29 September, by a different author, says only that unconfirmed reports suggest exploitation "as early as Sept 24th".
OutcomeIts introduction says observed activity "included" payload retrieval, configuration staging, reverse shells, persistence and web-shell installation; its takeaways say others "attempted" to create privileged accounts and deploy web shells. A failed authentication event is not evidence that the attempt failed.How many attempts worked. On how many appliances the account, the web shell or the archive was found. Whether any upload completed.
WhoNothing.An actor, a motive, or whether this is the activity Mandiant describes.
FixPatch affected appliances, and review historical telemetry for exploitation that may predate remediation.Fixed builds. Whether patching removes the account, the shell or the configuration edits.
Indicators23: 11 IPv4 addresses, 5 URLs, 4 file paths, 2 SHA-256 hashes and 1 account. LevelBlue says they are not exhaustive.A hash of the web shell itself: both hashes are of downloaded scripts. The text of the web server change. Any log pattern for requests to the stylesheet lookalikes.

Counts from elsewhere. No count of victims comes from LevelBlue. Rapid7 reported on 30 September that it had identified two organisations compromised through CVE-2026-88771. Help Net Security quotes researcher Kevin Beaumont as tracking over 100 victim organisations; we did not find his own post. Neither number says how many appliances carry the files LevelBlue names.

Commercial interest. LevelBlue sells managed detection, threat hunting and incident response, and its page carries a demonstration offer beside the research. That is not a reason to doubt what its hunters saw. It is a reason to read the post as one vendor's observations of its own customers, which is why the table above matters more than the headline.

The payload, and where it sits in the week

The Perl script, update_c08937.pl, is the part of the post that matters for detection. LevelBlue says the injected command fetched it and piped it straight into Perl, so it ran without first being saved to a fixed place on disk. The diagram shows what LevelBlue's analysis says the script does and what each change leaves behind.

Flow from an attacker-controlled login username to a curl command that pipes a Perl script into Perl, then six effects and what each leaves: a sec_monitor superuser account in the saved configuration; a configuration archive the script tries to upload to 64.94.85.67 port 443, then deletes; /bin/sh mode 6555; a PHP web shell called .local_journal in the logon directory; PHP and stylesheet-like URLs set in httpd.conf; and a separate Python script overwriting customsnmpd with a reverse shell.
Drawn from LevelBlue SpiderLabs, 30 September 2026. The octal conversion is ours. The post does not say on how many appliances these were found.

Three details are worth stating plainly. First, the account, the permission change, the web shell and the web server edit are changes to things that persist; LevelBlue lists them as the artefacts that show whether the payload ran. Second, the script deletes itself and the configuration archive, so finding neither proves nothing. Third, the archive holds the whole configuration directory. Rapid7's post says that directory contains the device configuration with encrypted administrator passwords, the LDAP, RADIUS and TACACS bind passwords, and TLS certificates with their private keys.

Dated observations on the NetScaler web shells, and where LevelBlue's report sits. Days are calendar days to 30 September, derived by us.

DateReported byWhat it reportsDays before LevelBlue
21 AugUnit 42Probing of a Gateway and more than 100 other systems: version fingerprinting, not exploitation.40
4 SepUnit 42Requests begin to the folder that held web shells, for the DTLS flaw (CVE-2026-88772).26
5 SepeSentireA CVE-2026-88771 web shell operated at one victim.25
20 SepRapid7First injected login attempt it saw, logged as a failed login. Rapid7 says its first compromise involved this command.10
21 SepUnit 42A web shell dropped in three stages at a US target, CVE-2026-88771.9
24 SepGreyNoise, Rapid7A failed attempt on a GreyNoise sensor. Rapid7 sees a web shell at a compromised organisation.6
27 SepCitrix, CISABulletin, fixed builds and KEV listing, due 30 September.3
29 SepMandiant and GTIGReport on CVE-2026-88772, with two web shell disguises of its own.1
30 SepLevelBlueIts report, on the federal due date. It gives no date for its own observations.0

Counted from today, 1 October, the fix is 4 days old and the federal due date is 1 day behind us. LevelBlue's report arrived 3 days after the fix and on the due date itself. Unit 42's update also moves the earliest web shell activity it reports to 4 September, a day before the date used in the earlier briefing; it dates only probing to 21 August.

Four disguises, one playbook

Read across the six reports and the pattern is plain. Each shell is a PHP file that is not named like one, reached through a URL that looks like something a Gateway serves anyway: an installer, an icon, a stylesheet. GreyNoise describes the first stylesheet disguise as an attempt on a sensor, and Rapid7 and Unit 42 report the same hidden file, .ctxs.receiver, on compromised appliances. LevelBlue's differs in file name, in stylesheet name and in where it sits, the logon folder itself rather than its custom subfolder, but it asks the same things of the appliance.

Four disguises for a NetScaler web shell: a package file run as PHP (Mandiant, eSentire, Unit 42); an icon request routed to a .sig file (Mandiant, eSentire); a stylesheet request routed to hidden file .ctxs.receiver in the logon custom folder (GreyNoise, Rapid7, Unit 42); and, newest, a stylesheet request routed to hidden file .local_journal in the logon folder (LevelBlue). Beneath all four: PHP enabled, a public URL mapped, special bits on /bin/sh.
Drawn from the six reports named in the diagram, read on 1 October 2026. Rapid7 gives the file path only. The grouping into four disguises is ours.

The three steps underneath. Five of the six reports describe all three: PHP execution switched on or granted to a non-script file in the web server's configuration, a public URL mapped to the file, and special permission bits on /bin/sh. Rapid7 gives only the file path. Unit 42 notes that the appliance's web server ships with PHP switched off, so an "on" is a finding in itself. Two reports, LevelBlue's and Unit 42's, give the identical permission value, 6555, for the shell, across two different file names. That fits shared tooling or copying, and no source says which.

The indicator lists overlap less than the behaviour. Across the five reports that publish hashes in the open, nine SHA-256 values appear, and all nine are different, so no hash from one report finds anything in another. Mandiant's post lists no hashes in the open; its fuller indicator set is in a collection for registered users. Four of LevelBlue's eleven IPv4 addresses, the four it describes as hosting its payloads, also appear in eSentire's list of 29 September, where each is labelled a payload host. Two of eSentire's other addresses appear in Unit 42's list, and GreyNoise's single address appears in eSentire's. None of LevelBlue's appears in the lists of Mandiant, GreyNoise or Unit 42, or in Rapid7's sample. Shared infrastructure can mean one operator, shared hosting or copied tooling. None of the reports says which, and LevelBlue does not say that its activity is the one Mandiant describes.

Two gaps that appear when the lists are laid side by side. These are our comparisons of published material, not statements by any vendor.

  • The file sweeps in Mandiant's post, and eSentire's file indicators, sit in the VPN client, media and theme folders. LevelBlue, GreyNoise, Rapid7 and Unit 42 report their shells under the logon directory, which Unit 42 calls the Gateway web interface root and whose custom subfolder it says is web-accessible by design and often not monitored. Mandiant's sweeps do not name that tree. Its checks of the web server configuration would still see an edit, though LevelBlue does not publish the text of the directive it adds, so we cannot say they would match it.
  • Mandiant's check on the system shell describes the listing for a single permission bit. LevelBlue's 6555 sets both the setuid and setgid bits and removes owner write, which converts to a listing that reads differently. Check for either special bit, not for one string.

The lesson is the one the table of names teaches. A hunt built from one vendor's file names finds that vendor's shell. A hunt built from behaviour finds all four: a PHP switch that was off, a handler or alias that was not there, a permission bit that should not be set, a hidden file in a directory of static assets. Behaviour needs a known-good baseline to compare against, and that is a job done before an incident, not during one. The point about baselines is our reading.

Does an update remove it? What each source says

This is the question a response plan turns on. Every source that addresses it says no or is silent. None reports a test of updating an appliance that was already compromised.

What the sources say about updating an appliance that may already be compromised. Read between 28 September and 1 October 2026.

SourceSaysDoes not say
Citrix, community blog, marked updated 30 SepAn update "does not remove potential compromise artifacts" or prove that nothing happened before it. If compromise is suspected or confirmed, deploy a new, updated instance instead of treating the update as a cleanup.Which artefacts. Any test on a compromised appliance.
eSentire, 29 SepPatches do not remove deployed payloads or persistence mechanisms. Treat an internet-facing appliance that was unpatched in early September as compromised until an integrity assessment shows otherwise.How it knows. No test is described.
Unit 42, updated 30 SepUpdating "will not remove access for attackers" who have already established persistence.The basis for the statement.
CISA (27 to 28 Sep), NCSC and NHS England Digital (28 Sep)CISA: preserve forensic evidence before updating, as updates may lose forensic visibility. NCSC: isolate and replace, investigate, then update. NHS England: assess before patching, as patching may delete evidence.Whether an update removes anything. They address the order of work.
Mandiant, 29 SepUpgrading is its recommended option. Isolate appliances where indicators are found. Rotate credentials after patching.Whether upgrading removes a shell.
LevelBlue, 30 SepPatch affected appliances and review historical telemetry for exploitation before remediation.Anything about removal.

Our inference, which no source tests. LevelBlue's payload edits the saved configuration, the web server configuration, the permission bits of a system binary and a directory of web files. We found no source that says an in-place update reverts any of them, and Citrix says not to rely on one. Citrix's rebuild guidance adds a caution that bites here: restore a configuration backup only if it predates the compromise. Because the payload writes its account into the saved configuration, a backup taken after it ran may bring the account back. That last step is ours, not Citrix's or LevelBlue's.

Four labels that do the attacker's work

  • "Patched." Citrix's own page says an update does not remove compromise artifacts or show that nothing happened before it. A closed ticket records the update, not the state of the appliance.
  • "Failed login." LevelBlue says failed authentication events are not evidence that the attempt failed. Rapid7's sample for 20 September carries the result FAILED_BAD_LOGIN, and Rapid7 says its first compromise involved that command. eSentire says exploitation does not depend on the login succeeding. A rule that drops failed logins as noise drops the event that matters.
  • "A stylesheet." A URL ending in .css is a claim about a file, not a property of it. What decides it is what the web server does with the request, and that lives in its configuration, not in the name. LevelBlue names one lookalike and says hexadecimal variants exist. GreyNoise's published pattern accepts any hexadecimal suffix on another.
  • "sec_monitor." The account the payload creates is named like security tooling. That is our reading of the name, but an account list skimmed for things that look wrong would pass it. It is found by comparison with a list from before September, not by reading.

Fixed builds, and two traps in them

The builds below are from Citrix's bulletin and its community blog. Both flaws are fixed by the same builds.

Fixed builds for CVE-2026-88771 and CVE-2026-88772, from Citrix bulletin CTX697096 and its blog, last updated 30 September 2026.

Build trackFixed inNote
ADC and Gateway 14.114.1-73.37 and laterNone in the bulletin.
ADC and Gateway 13.113.1-64.23 and later 13.1Citrix: a known issue can cause a cyclic reboot on upgrade for some configurations. If the command it names lists variables, plan for 13.1-64.24.
ADC 14.1-FIPS14.1-73.37 FIPS and laterNone.
ADC 13.1-FIPS and 13.1-NDcPP13.1.37.279 and laterNCSC and NHS England Digital write 13.1-37.279. Citrix writes 13.1.37.279; follow Citrix.
VPX 15.1 Technology PreviewNo fix yetCitrix says it is also vulnerable, that a fix is coming "shortly", and that it is not for production use.
12.1 and 13.0End of lifeNHS England Digital says they are likely vulnerable and must be migrated.

What to hunt and harden, in the order worth doing

The UK record. The NCSC alert of 28 September says the NCSC is working to understand the impact on UK organisations. We found no UK count. NHS England Digital's alert of the same day assesses further exploitation as almost certain. Both put assessing for compromise ahead of updating. Specific strings and paths are in the vendors' own posts; this list gives the order and the reason.

Take this with you

In the order worth doing

  • List every NetScaler you run, its build, and whether it was reachable from the internet at any point since 21 August. The earliest dates reported are 21 August for probing and 4 and 5 September for web shell activity.
  • Before you update or reboot an exposed appliance, preserve evidence: a snapshot with memory for a virtual appliance, a support bundle, and logs already forwarded off the box. CISA, NHS England Digital and Citrix ask for evidence first, and the NCSC puts investigation before updating.
  • Find out how far back your NetScaler logs reach. If they start after early September, a search that finds nothing is not a clean result, and your report should say so.
  • Search authentication logs for the marker words LevelBlue lists (pitboss, NSPPE, unexpectedly died), or for shell punctuation or the shell's IFS variable in the username field, whatever the login result. Include failed logins. Other vendors' samples use a different watchdog phrase, so key on the word pitboss plus shell characters, not on one phrase.
  • Compare each appliance's local account list and roles with a list you held before September, or with a freshly built appliance of the same build. Investigate sec_monitor, any account no person or system can explain, and any change to the saved configuration since your last approved change.
  • Check the web server configuration for PHP execution that was not there and for any handler or alias that sends a public path to a script. Check the system shell for the setuid or the setgid bit, not for one permission string. Do not rely on file names from any one report.
  • Sweep for hidden files, and for text or PHP files, wherever static files belong: the logon directory tree including its custom subfolder, and the VPN client script, media and theme folders. Treat .local_journal, insight-new.js, xua.html, .ctxs.receiver, .sig and .deb files as leads, not as the whole test.
  • Look for outbound connections from the appliance to anything outside an allow-list, including the LevelBlue addresses 64.94.85[.]67 and 45.141.21[.]130, and for changes to the customsnmpd file. LevelBlue's upload URL uses plain HTTP on port 443, so a port rule is not a protocol rule.
  • If anything is found, rebuild from a known-good state and do not update in place and carry on. NCSC advises isolating the appliance and replacing it with a new, fully up-to-date system. Citrix advises replacing a virtual instance, restoring a backup that predates the compromise, and monitoring the rebuilt system for at least 90 days. In a high availability pair, assess both nodes and keep configuration sync off until both are validated, as Mandiant advises.
  • If you find signs that the payload ran, treat what the configuration held as exposed. Rapid7 lists administrator password hashes, LDAP, RADIUS and TACACS bind credentials, TLS certificates with private keys and SSH host keys in the directory LevelBlue's payload archives. The payload deletes its archive, so only egress records can show that an upload did not happen. After the rebuild, rotate all of it, revoke Gateway and VPN sessions, and reset the passwords of users who authenticated through the appliance.
  • Look past the appliance, as Mandiant advises: StoreFront, delivery controllers, virtual desktop hosts, privileged access management and domain controllers, for unusual interactive logons and credential dumping. LevelBlue says nothing about movement beyond the appliance.
  • If you are in the UK and think you were compromised, report it to the NCSC. NHS organisations should also report to the NHS England National CSOC. The NCSC Early Warning service is free.
  • Harden what is left: management interfaces off the internet, default-deny outbound rules, logs forwarded to a system the appliance cannot alter, and after any rebuild a recorded baseline of the account list, the web server configuration and the web directories, so that the next comparison is possible.

What we could not verify

The question this leaves

Every vendor named above has published the names of the files it found. That is four disguises and nine hashes with nothing in common, and nothing says the next intrusion will not bring a fifth. So the question for your own process: what do you hold today that would show a file you have never heard of does not belong on your NetScaler? A record, taken before September, of its accounts, its web server configuration and its web directories would answer it. A list of bad names would not.

Key facts

Sources

  1. PrimaryCitrix NetScaler CVE-2026-88771: Observed Exploitation Artifacts and Hunt Indicators, 30 September 2026, read in full (text; the two figures are screenshots of script samples): the payload analysis, detection table and 23 indicatorsLevelBlue SpiderLabsaccessed 2026-10-01
  2. PrimaryLevelBlue's earlier post of 29 September by a different author: read only for its statement that unconfirmed reports suggest exploitation from 24 SeptemberLevelBlue SpiderLabsaccessed 2026-10-01
  3. PrimarySecurity bulletin CTX697096 for CVE-2026-88771 to CVE-2026-88778, server-rendered copy read in full: fixed builds, preconditions, the statement that exploits have been observedCitrix, Cloud Software Groupaccessed 2026-10-01
  4. PrimaryNetScaler Cyber Threat Intelligence blog, marked last updated 30 September 2026, read in a browser: the statement that an update does not remove compromise artifacts, the 13.1-64.23 known issue, the 15.1 Technology Preview noteCitrix, Cloud Software Groupaccessed 2026-10-01
  5. PrimarySteps to take if NetScaler ADC is suspected to be compromised (CTX694799): evidence preservation, rebuild, restore a backup that predates the compromise, rotate secrets, 90-day monitoringCitrix, Cloud Software Groupaccessed 2026-10-01
  6. PrimaryKEV JSON feed, catalogue version 2026.09.30 (1,730 entries): the CVE-2026-88771 and CVE-2026-88772 records, date added 27 September, due 30 September, forensic triage requiredCybersecurity and Infrastructure Security Agencyaccessed 2026-10-01
  7. PrimaryAlert last revised 28 September 2026: check for compromise before patching, preserve forensic evidence before updatingCybersecurity and Infrastructure Security Agencyaccessed 2026-10-01
  8. PrimaryNVD record for CVE-2026-88771, pulled from the API on 1 October: CWE-20, CVSS 3.1 of 9.8 from NVD and CVSS 4.0 of 9.5 from the NetScaler assignerNational Vulnerability Databaseaccessed 2026-10-01
  9. PrimaryAlert published 28 September 2026: priority actions in order, the statement that NCSC is working to understand UK impact, reporting and the Early Warning serviceUK National Cyber Security Centreaccessed 2026-10-01
  10. PrimaryCyber alert CC-4858, 28 September 2026: further exploitation assessed as almost certain, compromise assessment before patching, reporting to the NHS England National CSOC, end-of-life versionsNHS England Digitalaccessed 2026-10-01
  11. PrimaryDefending Against Active Exploitation of Citrix NetScaler ADC and Gateway Appliances, 29 September 2026: the .deb and .sig disguises, hunting paths, setuid check, rotation after patchingGoogle Cloud, Mandiant and Google Threat Intelligence Groupaccessed 2026-10-01
  12. PrimaryUpdate advisory of 29 September 2026: web shell use from 5 September, the .ico and .deb variants, the statement that patches do not remove payloads or persistence, 14 published IPv4 addresseseSentire Threat Response Unitaccessed 2026-10-01
  13. PrimarySwarming Against Citrix 0-Day Exploitation, 28 September 2026: the 24 September sensor attempt, the .ctxs.receiver stylesheet disguise, setuid and setgidGreyNoiseaccessed 2026-10-01
  14. PrimaryEmergent threat response post, updated 30 September 2026: first attempt seen 20 September logged as a failed login, two compromised organisations, contents of the configuration directoryRapid7accessed 2026-10-01
  15. PrimaryThreat brief updated 30 September 2026: probing from 21 August, web shell requests from 4 September, a 21 September drop, the logon directory, PHP shipped off, updating does not remove persistencePalo Alto Networks Unit 42accessed 2026-10-01
  16. PrimaryCERT-EU blog of 28 September 2026: read only for the two watchdog-message phrases that the vulnerable script matches; no technical detail reproducedCERT-EUaccessed 2026-10-01
  17. Reported byCitrix NetScaler Post-Exploitation Payload Creates Superuser, Maps Web Shell to CSS-Like URLs, 1 October 2026: the pointer to LevelBlue's post; no new facts taken from itThe Hacker Newsaccessed 2026-10-01
  18. Reported byNetScaler zero-day exploitation escalates into mass attacks, 29 September 2026: Kevin Beaumont's reported count of over 100 victim organisations, not traced to his own postHelp Net Securityaccessed 2026-10-01

Share this briefing

Know someone who owns this problem? Send it to them.

Related briefings

The briefing, in your inbox

Practitioner analysis of cyber and AI security news. No vendor noise.

How often

Every new briefing in one email, at 7am, or at 7am, 12:30pm and 6pm. Nothing is sent when nothing is new. Unsubscribe any time.