LevelBlue Details CVE-2026-88771 Exploitation Activity Targeting NetScaler Appliances

· Original article ↗

Summary

LevelBlue observed attackers exploiting CVE-2026-88771 against NetScaler appliances, with commands and payloads targeting configuration data, privileged access, reverse shells, and web shells. It provides behavioral indicators for investigation.

Key points

  • LevelBlue’s threat-hunting team found malicious NetScaler authentication events containing attacker-controlled usernames designed to exploit the critical pre-authentication command-injection vulnerability.
  • Observed commands tested execution and attempted to retrieve payloads, collect or stage NetScaler configuration data, and deploy reverse shells and web shells.
  • A Python payload targeted /var/python/bin/customsnmpd to establish a reverse shell; a Perl payload could create a privileged sec_monitor account, expose a PHP web shell, and attempt to exfiltrate configuration data.
  • Hunt indicators include shell commands in authentication fields, unexpected access to /flash/nsconfig, web-directory artifacts, changes to appliance configuration or /bin/sh permissions, and related network connections.
  • The report cautions that indicators are not exhaustive and that deleted payloads or archives do not prove execution failed; defenders should investigate beyond the initial authentication event.
  • Organizations should patch affected NetScaler appliances and review historical telemetry for signs of exploitation before remediation.

Article Details

Attack Vectors
  • Pre-authentication command injection through attacker-controlled NetScaler authentication usernames containing pitboss and NSPPE strings.
  • Injected commands tested execution, retrieved second-stage payloads with curl or wget, and copied or archived NetScaler configuration data.
  • The main.py payload overwrote /var/python/bin/customsnmpd with code that establishes a reverse shell.
  • The update_c08937.pl payload attempted configuration exfiltration, created a privileged local account, and installed a PHP web shell.
Defensive Notes
  • Patch affected NetScaler appliances and review historical authentication telemetry, including failed authentication events, for shell commands embedded in authentication fields.
  • Investigate unexpected access to /flash/nsconfig, creation of files in NetScaler web directories, and network connections following command-injection attempts.
  • Check for the sec_monitor account, modifications to /var/python/bin/customsnmpd or /etc/httpd.conf, the .local_journal web shell, and /bin/sh permissions changed to 6555.
  • Absence of the configuration archive or Perl payload does not rule out execution: the analyzed payload deletes both.

Indicators of compromise

TypeIndicatorContext
IPV4162[.]243[.]36[.]88Exploitation-related IP listed in the investigation's IOC table; its specific role is not stated.
IPV4173[.]40[.]135[.]209Exploitation-related IP listed in the investigation's IOC table; its specific role is not stated.
IPV423[.]27[.]143[.]20Exploit source and host of the main.py reverse-shell payload.
IPV431[.]56[.]197[.]72Host of the lula payload referenced in injected retrieval commands.
IPV445[.]141[.]21[.]130Reverse-shell C2 address contacted by the modified customsnmpd.
IPV447[.]230[.]224[.]154Exploitation-related IP listed in the investigation's IOC table; its specific role is not stated.
IPV462[.]133[.]62[.]80Payload-hosting infrastructure.
IPV464[.]94[.]85[.]67Exploit and payload infrastructure used for attempted configuration exfiltration.
IPV470[.]172[.]58[.]168Source of observed NetScaler exploitation attempts.
IPV487[.]224[.]84[.]82Source of a configuration-staging attempt.
IPV492[.]118[.]204[.]229Source of command-execution testing.
SHA256974b69782fdf5d67b97cfd508465939e44ee10798dbcc1e82b92d78776bad938Hash of the update_c08937.pl payload.
SHA256e9fe43968c6c0955300e3bc4d7fb0b05a18570b4733aaf4f5c6f7f09be5a242cHash of the main.py payload.
URLhxxp[:]//23[.]27[.]143[.]20:9000/main[.]pyURL hosting the analyzed Python reverse-shell payload.
URLhxxp[:]//31[.]56[.]197[.]72:9090/lulaPayload URL referenced in injected wget and curl commands.
URLhxxp[:]//62[.]133[.]62[.]80/xd7h/xPayload download URL.
URLhxxp[:]//64[.]94[.]85[.]67:443/update_c08937[.]plURL hosting the analyzed Perl post-exploitation payload.
URLhxxp[:]//64[.]94[.]85[.]67:443/update_result_3567cs[.]tgzIdentified NetScaler configuration exfiltration endpoint.

MITRE ATT&CK

CVE

People

Vendors

Products

Related Articles