← Blog · · df00tech

Citrix NetScaler Exploitation Chain Adds Superuser Backdoor and CSS-Disguised Web Shell

security-news technique

What happened

LevelBlue's Threat Hunt Operations & Research (THOR) team reports that threat actors are exploiting a critical pre-authentication command injection vulnerability in Citrix NetScaler ADC and NetScaler Gateway. According to LevelBlue, the activity has been observed across multiple customer environments and involves attackers dropping web shells and attempting to exfiltrate NetScaler configuration data. Per the report's summary, the post-exploitation payload is also said to create a superuser account and map the web shell to a URL styled to resemble a CSS file, apparently to blend into normal web traffic and evade cursory review.

Why it matters

NetScaler ADC and Gateway appliances sit at the network edge and often broker authentication and remote access, so a pre-auth command injection flaw gives attackers a foothold without needing valid credentials. A web shell combined with a newly created superuser account gives an attacker persistent, privileged access even if the initial exploit is later patched, and theft of NetScaler configuration data can expose secrets, certificates, or routing information useful for deeper compromise. Any organization running affected NetScaler ADC/Gateway appliances should treat this as relevant, pending confirmation of exact affected versions from Citrix or LevelBlue's full report.

What defenders should watch for

  • Review NetScaler systems for unexpected local/superuser accounts created outside normal change-management processes.
  • Audit web-accessible files and URL mappings on NetScaler appliances for entries disguised with .css-like extensions or paths that don't correspond to legitimate static assets.
  • Inspect NetScaler configuration export/backup activity and outbound data transfers for signs of configuration theft.
  • Check NetScaler access and command logs for anomalous pre-authentication requests or command-injection patterns.
  • Confirm NetScaler ADC/Gateway firmware is current and monitor Citrix advisories for a CVE identifier and patch guidance tied to this activity.
  • Consider restricting management-plane and Gateway exposure to trusted networks where feasible while patch details are confirmed.

Developing story

This item is based on a single vendor report (LevelBlue THOR) and details such as the specific CVE, affected firmware versions, and attribution are not yet fully confirmed in the information available. Treat this as early, developing intelligence and watch for follow-up advisories from Citrix. Original reporting: The Hacker News.

Get new detections in your inbox

New ATT&CK coverage plus CISA KEV / CVE detection rules, roughly weekly. No spam, unsubscribe anytime.