How to detect Citrix NetScaler compromise

In short: review httpd.conf for PHP handler and AliasMatch changes, look for PHP files in VPN script and media directories, check /bin/sh for setuid, and correlate DTLSv1.0 handshake failures with NSPPE crashes. Sources: GTIG/Mandiant, CERT-EU and GreyNoise, as of 30 September 2026. [25][19]

A clean scan does not clear a host. A checker can miss a planted webshell, especially when logs have rotated or permissions were changed.

CERT-EU hunting patterns Passive

  • base64 strings in the User-Agent header that start with INDEX:.
  • PPE missed too many heartbeats entries in authentication logs.
  • Check that httpd.conf is intact, for example by looking for the AliasMatch in the IoC table.

Source: CERT-EU writeup

CIRCL TR-100 Config check

For each CVE, CIRCL gives CLI commands that check whether your appliance's configuration exposes it. Run them on appliances you administer.

Source: CIRCL TR-100

Citrix Console IoC checker Limits per Beaumont Validated

  • Available only through support or under NDA. [45]
  • Incomplete: it does not check for suid on /bin/sh. [48]
  • Citrix's own documentation says the IoC information "might be of limited forensic value and might fail to identify actual compromises", and advises retaining experienced forensic investigators. [4]
  • In the field, the Console scanner has flagged base64 content referencing the .ctxs.receiver webshell, "Certificate digest verification failed" (possibly tampered certificate or key files) and "Binary Fingerprinting detected", according to one practitioner's notes. [72]
  • Misses earlier semi-successful attempts once logs have rotated. [46]

The missing suid check and the log-rotation gap were validated independently on 29 September. The NDA point has not been verified.

Beaumont also says Some really big orgs are backdoored after patching still. That claim is not independently verified. He has asked national CSIRTs (NCSCs) to publish a detection script. [48]

GTIG/Mandiant artefacts and YARA Passive

Successful CVE-2026-88772 exploitation left two log artefacts:

  • In syslog, an SSL_HANDSHAKE_FAILURE with ClientVersion DTLSv1.0 and Reason "Handshake failure-Internal Error".
  • In /var/log/messages, an NSPPE termination logged by pitboss, the watchdog daemon that restarts crashed processes.

Also look for httpd.conf changes that make the web server treat other file types as PHP, such as AddHandler application/x-httpd-php .deb.

GTIG publishes five YARA rules: G_APT_Backdoorwebshell_WHIPSHOT_1, G_APT_Tunneler_SLAPSHOT_1, G_Hunting_Backdoorwebshell_NetScaler_C2Headers_1, G_Hunting_Config_NetScaler_PHP_1 and G_Hunting_Script_NetScaler_Persistence_1. This page links to them rather than copying them.

Source: GTIG/Mandiant advisory

Nextron THOR Scanner rules

As of 29 September, Nextron has three rules in the THOR Preview channel:

  • LOG_SUSP_EXPL_CVE_2026_88771_Sep26
  • WEBSHELL_CSS_PassThrough_Sep26, which detects the webshell's behaviour, not only its filename
  • EXPL_CVE_2026_88772_POC_Sep26, which detects PoC artefacts, not attacks on an appliance

Nextron also published a YAML filesystem IoC set derived from Citrix's scanner script. It covers 12 of the script's checks, consolidated into four file rules. It leaves out the 22 checks that depend on logs, configuration or runtime state.

Preview-channel rules have not finished manual QA, so expect more false positives than with stable rules. A match is a lead for investigation, not proof of compromise.

Source: Nextron Systems

Community detection rules Rules

  • Elastic: "Potential NetScaler Log Poisoning Command Injection Attempt", an EQL rule on Citrix ADC logs. Merged on 28 September.
  • Sigma pull request #6352: shell metacharacters sent to the NetScaler authentication endpoint. Not yet merged.
  • Corelight: Zeek hunting queries, including a search for the reverse-shell IP in the IoC table.
  • Nuclei pull request #17336: an active injection probe, not a version check. It writes to the target's logs, so run it only on systems you own or administer. Not yet merged.
  • Lupovis suggests two hunts: POST /nf/auth/doAuthentication.do requests whose body contains pitboss PPE unexpectedly died NSPPE, and DNS lookups from a NetScaler ending in instances.httpworkbench.com. [65]

Beazley Security Labs checks Passive

Beazley's BSL-A1216 advisory lists read-only shell checks. It splits them into those to run before patching (the web-server config, /bin/sh permissions and NX-CVE-OK test markers, which a reboot rebuilds) and those that persist across upgrades (hidden files under /var/netscaler/logon). It also recommends comparing /etc/httpd.conf with a clean appliance on the same build.

Source: Beazley Security Labs BSL-A1216

watchTowr Detection Artefact Generators Active tests

These tools send traffic to an appliance. Run them only against systems you own or administer. This page links to the repositories. It does not reproduce their code or payloads.

Beaumont describes the other GitHub "PoCs" he has seen as fake AI slop. That is his characterisation. [52]

Related pages

References

#SourceTypeURL
1Citrix - CTX697096 security bulletin (Sep 27)Primary official advisorieshttps://support.citrix.com/external/article/CTX697096/citrix-netscaler-adc-and-citrix-netscale.html
2Citrix community blog - Security Bulletin for CVE-2026-88771 through CVE-2026-88778 (incl. IoC section) verification pendingPrimary official advisorieshttps://community.citrix.com/techzone-blogs/110_security-updates/netscaler-adc-and-netscaler-gateway-security-bulletin-for-cve-2026-88771-through-cve-2026-88778/
3Citrix (CTX-Michael) on r/Citrix, Sep 27 - CRITICAL UPDATE announcementPrimary official advisorieshttps://www.reddit.com/r/Citrix/comments/1wro1yf/critical_update_citrix_netscaler_adc_and_citrix/
4NetScaler Console documentation - Indicators of Compromise detection (incl. Citrix disclaimer on limits)Primary official advisorieshttps://docs.netscaler.com/en-us/netscaler-console-service/instance-advisory/ioc
5CISA alert - Critical zero-day vulnerabilities exploited in Citrix NetScaler ADC/Gateway (Sep 27)Primary official advisorieshttps://www.cisa.gov/news-events/alerts/2026/09/27/critical-zero-day-vulnerabilities-exploited-citrix-netscaler-adc-gateway
6NCSC-NL advisory NCSC-2026-0394 (probability high, damage high; per-CVE scores and preconditions)Primary official advisorieshttps://advisories.ncsc.nl/
7NCSC-UK - Exploitation of vulnerabilities affecting Citrix NetScaler ADC and GatewayPrimary official advisorieshttps://www.ncsc.gov.uk/news/exploitation-of-vulnerabilities-affecting-citrix-netscaler-adc-and-citrix-netscaler-gateway
8CSA Singapore - AL-2026-129Primary official advisorieshttps://www.csa.gov.sg/alerts-and-advisories/alerts/al-2026-129/
9Canadian Centre for Cyber Security - AL26-024Primary official advisorieshttps://www.cyber.gc.ca/en/alerts-advisories/al26-024-critical-vulnerabilities-affecting-citrix-netscaler-adc-netscaler-gateway-cve-2026-88771-cve-2026-88772
10HKCERT - Citrix Products Multiple Vulnerabilities (Sep 28)Primary official advisorieshttps://www.hkcert.org/security-bulletin/citrix-products-multiple-vulnerabilities_20260928
11ACSC (Australia) - Critical vulnerabilities in Citrix NetScaler ADC and NetScaler GatewayPrimary official advisorieshttps://www.cyber.gov.au/about-us/view-all-content/alerts-and-advisories/critical-vulnerabilities-in-citrix-netscaler-adc-and-citrix-netscaler-gateway-products
12CISA Known Exploited Vulnerabilities catalog (both CVEs added Sep 27, due Sep 30)Primary official advisorieshttps://www.cisa.gov/known-exploited-vulnerabilities-catalog
13CERT-EU Security Advisory 2026-014 - Critical Vulnerabilities in Citrix NetScaler ADC and Gateway (Sep 27)Primary official advisorieshttps://cert.europa.eu/publications/security-advisories/2026-014/
14DKCERT (CERT for Danish universities and research) - To kritiske NetScaler 0-dage udnyttes aktivt før patch (Sep 29)Primary official advisorieshttps://cert.dk/node/639
15NHS England Digital cyber alert CC-4858 (Sep 28) - Exploitation of zero-day vulnerabilities affecting Citrix NetScalerPrimary official advisorieshttps://digital.nhs.uk/cyber-alerts/2026/cc-4858
16CIRCL TR-100 - per-CVE configuration-check CLI commandsPrimary official advisorieshttps://www.circl.lu/pub/tr-100/
17Dutch government letter to parliament - Kwetsbaarheden Citrix Netscaler (2026D47262, Sep 29)Primary official advisorieshttps://www.tweedekamer.nl/kamerstukken/brieven_regering/detail?id=2026D47262&did=2026D47262
18CVE.org - CVE-2026-88771 record (reserved Sep 10 07:14 UTC by NetScaler; published Sep 27 16:02 UTC)Primary official advisorieshttps://www.cve.org/CVERecord?id=CVE-2026-88771
19CERT-EU - Taking "execute logging" a bit too literally - CVE-2026-88771 (Sep 28)Technical researchhttps://www.cert.europa.eu/blog/taking-execute-logging-a-bit-too-literally-cve-2026-88771
20watchTowr Labs part 1 - Oh Look, the Foot Gun Went Off Again (CVE-2026-88771) (Sep 28)Technical researchhttps://labs.watchtowr.com/oh-look-the-foot-gun-went-off-again-citrix-netscaler-preauth-command-injection-cve-2026-88771/
21watchTowr Detection Artefact Generator - CVE-2026-88771 (GitHub)Technical researchhttps://github.com/watchtowrlabs/watchTowr-vs-Citrix-Netscaler-CVE-2026-88771
22watchTowr Labs part 2 - Here We Go Again (CVE-2026-88772), Sina Kheirkhah (Sep 29)Technical researchhttps://labs.watchtowr.com/here-we-go-again-citrix-netscaler-dtls-preauth-memory-overflow-cve-2026-88772/
23watchTowr Detection Artefact Generator - CVE-2026-88772 (GitHub)Technical researchhttps://github.com/watchtowrlabs/watchTowr-vs-Citrix-Netscaler-CVE-2026-88772
24Truesec - Multiple Critical Vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway (Sep 28)Technical researchhttps://www.truesec.com/hub/blog/multiple-critical-vulnerabilities-in-citrix-netscaler-adc-and-netscaler-gateway
25Google GTIG / Mandiant - Defending Against Active Exploitation of Citrix NetScaler ADC and Gateway Appliances (Sep 29)Technical researchhttps://cloud.google.com/blog/topics/threat-intelligence/defending-against-active-exploitation-of-citrix-netscaler-adc-and-gateway-appliances
26Nextron Systems (Florian Roth) - New THOR Detection Coverage for CVE-2026-88771 and CVE-2026-88772 (Sep 29)Technical researchhttps://www.nextron-systems.com/2026/09/29/new-thor-detection-coverage-for-citrix-netscaler-cve-2026-88771-and-cve-2026-88772/
27Beazley Security advisory (updated Sep 29) - IoC table incl. Lupovis honeypot IPsTechnical researchhttps://beazley.security/alerts-advisories/critical-vulnerability-in-citrix-netscaler-zero-day-prompts-emergency-shutdowns-cve-2026-88771-cve-2026-88772
28Corelight - Hunting Citrix NetScaler zero-days (Zeek queries, Sep 28)Technical researchhttps://corelight.com/blog/hunting-citrix-netscaler-zero-days-corelight
29Elastic detection rule - Potential NetScaler Log Poisoning Command Injection Attempt (merged Sep 28)Technical researchhttps://github.com/elastic/detection-rules/blob/main/rules/network/initial_access_netscaler_log_poisoning_command_injection.toml
30SigmaHQ pull request #6352 - NetScaler auth endpoint shell metacharacters (open, Sep 29)Technical researchhttps://github.com/SigmaHQ/sigma/pull/6352
31Nuclei templates pull request #17336 - CVE-2026-88771 active probe (open, Sep 28)Technical researchhttps://github.com/projectdiscovery/nuclei-templates/pull/17336
32eSentire TRU - Update: ongoing exploitation of NetScaler CVE-2026-88771 / -88772 (first-hand IR, Sep 29)Technical researchhttps://www.esentire.com/security-advisories/update-ongoing-exploitation-of-citrix-netscaler-adc-and-netscaler-gateway-vulnerabilities-cve-2026-88771-cve-2026-88772
33Beazley Security Labs - BSL-A1216 advisory (updates 3-4, Sep 29): consolidated IoCs and hunting commandsTechnical researchhttps://labs.beazley.security/advisories/BSL-A1216
34watchTowr (@watchtowrcyber) on X, Sep 26 - "Unpatched, 0days. Exploited in-the-wild - discovered during forensics."Technical researchhttps://x.com/watchtowrcyber/status/2103972792043479307
35CyberMaxx - Patches required: Citrix NetScaler vulns exploited in the wild (IoC notes)Technical researchhttps://www.cybermaxx.com/resources/patches-required-citrix-netscaler-vulns-exploited-in-the-wild-cve-2026-88771-and-cve-2026-88772/
36GreyNoise - Swarming Against Citrix 0-Day Exploitation (TLP:CLEAR IoCs, Sep 28)Telemetry and IoCshttps://greynoise.io/blog/swarming-against-citrix-0-day-exploitation
37GreyNoise Chronicle - GNTL-20260928 CVE-2026-88771 timelineTelemetry and IoCshttps://www.greynoise.io/chronicle/gntl-20260928-citrix-cve-2026-88771
38GreyNoise Visualizer - IP 149.104.78.141Telemetry and IoCshttps://viz.greynoise.io/ip/149.104.78.141
39GreyNoise tag - Citrix NetScaler CVE-2026-88771 Login Command Injection RCE AttemptTelemetry and IoCshttps://viz.greynoise.io/tag/citrix-netscaler-cve-2026-88771-login-command-injection-rce-attempt
40IFIN - Multiple Citrix Netscaler 0-Days Exploited (tracking thread, from Sep 26; observables "shared without restriction")Telemetry and IoCshttps://ifin.network/t/multiple-citrix-netscaler-0-days-exploited/867
41Censys advisory - NetScaler exposure (42,735 hosts, Sep 28)Telemetry and IoCshttps://censys.com/advisory/cve-2026-10747-2/
42Defused (@DefusedCyber) on X, Sep 29 - decoy hits across multiple CVE-2026-88771 pathsTelemetry and IoCshttps://x.com/DefusedCyber/status/2104888497693708505
43Lupovis (@LupovisDefence) on X, Sep 28 - decoys catch CVE-2026-88771 exploitation hours after the PoCTelemetry and IoCshttps://x.com/lupovisdefence/status/2104595071362326680
44Beaumont, Sep 27 - chained CVEs, webshells all September, "Probably nation state aligned"Kevin Beaumonthttps://cyberplace.social/@GossiTheDog/117343729453093307
45Beaumont, Sep 27 - patches live; detection script behind NDA; patching does not remove backdoorsKevin Beaumonthttps://cyberplace.social/@GossiTheDog/117343821114841048
46Beaumont, Sep 27 - Console check misses attempts when logs have rotatedKevin Beaumonthttps://cyberplace.social/@GossiTheDog/117345540231975640
47Beaumont, Sep 28 22:49 UTC - names "PitScaler", >100 victim orgs (his claim)Kevin Beaumonthttps://cyberplace.social/@GossiTheDog/117351107654208046
48Beaumont, Sep 28 23:02 UTC - Citrix checker incomplete (suid /bin/sh)Kevin Beaumonthttps://cyberplace.social/@GossiTheDog/117351155381900219
49Beaumont, Sep 29 04:39 UTC - mass exploitation, <10% patched (his claim)Kevin Beaumonthttps://cyberplace.social/@GossiTheDog/117352481501981552
50Beaumont, Sep 29 06:18 UTC - public message to the NSA (his unverified claim)Kevin Beaumonthttps://cyberplace.social/@GossiTheDog/117352869498139711
51Beaumont, Sep 29 16:12 UTC - IR vendors publishing victim-unique webshell namesKevin Beaumonthttps://cyberplace.social/@GossiTheDog/117355208096613386
52Beaumont, Sep 28 15:13 UTC - GitHub "PoCs" for the new Citrix vulns are "fake AI slop"Kevin Beaumonthttps://cyberplace.social/@GossiTheDog/117349313638958333
53Beaumont, Sep 29 18:32 UTC - Dutch government shuts down all Citrix NetScalers (relaying @bert_hubert)Kevin Beaumonthttps://cyberplace.social/@GossiTheDog/117355758746619146
54BleepingComputer (Sep 29) - Hackers exploit Citrix NetScaler zero-day to deploy web shellsPress and vendor coveragehttps://www.bleepingcomputer.com/news/security/hackers-exploit-citrix-netscaler-zero-day-to-deploy-web-shells/
55BleepingComputer (Sep 27) - Citrix admins warned to shut down NetScalersPress and vendor coveragehttps://www.bleepingcomputer.com/news/security/citrix-admins-warned-to-shut-down-netscalers-over-2-exploited-zero-days/
56SecurityWeek (Sep 28) - Citrix confirms 2 NetScaler zero-daysPress and vendor coveragehttps://www.securityweek.com/citrix-confirms-2-netscaler-zero-days-after-admins-pulled-the-plug/
57The Record (Sep 28) - US, UK warn of Citrix NetScaler zero-day bugPress and vendor coveragehttps://therecord.media/us-uk-warn-of-citrix-netscaler-zero-day-bug
58CyberScoop (Sep 28) - delayed-disclosure anglePress and vendor coveragehttps://cyberscoop.com/citrix-zero-days-delayed-disclosure/
59Sophos CTU (Sep 28) - CVE-2026-88771 / -88772 in active exploitationPress and vendor coveragehttps://www.sophos.com/en-us/blog/citrix-netscaler-cve-2026-88771-cve-2026-88772-in-active-exploitation
60Rapid7 ETR (Sep 28)Press and vendor coveragehttps://www.rapid7.com/blog/post/etr-zero-day-exploitation-of-citrix-netscaler-adc-and-gateway-cve-2026-88771-and-cve-2026-88772/
61watchTowr FAQ (Sep 27-28)Press and vendor coveragehttps://watchtowr.com/intelligence/citrix-netscaler-zero-day-vulnerabilities-faq/
62The Register (Sep 29) - Custom malware used in Citrix 0-day attacks targeting govt, banks, professional servicesPress and vendor coveragehttps://www.theregister.com/security/2026/09/29/custom-malware-used-in-citrix-0-day-attacks-targeting-govt-banks-professional-services/5299867
63Unit 42 (Palo Alto Networks) - NetScaler zero-days threat brief (Sep 27, updated Sep 28)Press and vendor coveragehttps://unit42.paloaltonetworks.com/netscaler-zero-days-exploited/
64Cybersecurity Dive (Sep 28) - Shadowserver: more than 20,000 instances exposedPress and vendor coveragehttps://www.cybersecuritydive.com/news/citrix-upgrades-netscaler-exploitation/831502/
65Help Net Security (Sep 29) - NetScaler zero-day exploitation escalates into mass attacks (Lupovis, Censys)Press and vendor coveragehttps://www.helpnetsecurity.com/2026/09/29/netscaler-zero-day-exploitation-escalates-into-mass-attacks-cve-2026-88771/
66Ingeniøren (Sep 30) - Alvorlige huller i kendt software: PET, Forsvaret og Politiet hastelukker systemerPress and vendor coveragehttps://ing.dk/artikel/alvorlige-huller-i-kendt-software-pet-forsvaret-og-politiet-hastelukker-systemer
67SDxCentral (Sep 29) - NetScaler bugs bring critical sectors down in Europe (citing Techzine)Press and vendor coveragehttps://www.sdxcentral.com/news/netscaler-bugs-bring-critical-sectors-down-in-europe/
68Cybersecurity Dive (Sep 29) - Citrix NetScaler exploitation began days before public notificationPress and vendor coveragehttps://www.cybersecuritydive.com/news/citrix-netscaler-exploitation-days-before-notification/831634/
69heise online (Sep 27) - New zero-day exploits in Citrix NetScalerPress and vendor coveragehttps://www.heise.de/en/news/Security-researchers-warn-New-zero-day-exploits-in-Citrix-Netscaler-11467269.html
70Dark Reading (Sep 29) - Dual NetScaler Zero-Days Trigger Chaos for Citrix CustomersPress and vendor coveragehttps://www.darkreading.com/vulnerabilities-threats/netscaler-zero-days-chaos-citrix
71Omroep Brabant (Sep 27) - Storing bij ziekenhuizen door kritieke kwetsbaarheden in systeem (Amphia, ETZ, Z-CERT)Press and vendor coveragehttps://www.omroepbrabant.nl/nieuws/6028828/storing-bij-ziekenhuizen-door-kritieke-kwetsbaarheden-in-systeem
72Maurice_Sec on X - notes from the field on NetScaler Console IoC scanner findingsCommunityhttps://x.com/Maurice_Sec/status/2104541998858240487
73r/Citrix - "Netscaler leak?" thread (~Sep 26)Communityhttps://www.reddit.com/r/Citrix/comments/1wqjk9a/netscaler_leak/