socradar.io 7 Oct 2026, 11:28 UTC

Hackers Exploit NetScaler Flaw to Deploy Root-Level C2 Agents

CyberSIXT Evidence Panel Source marked as original reporting
CISA KEV Listed in KEV
Patch Patch Status Unknown

CITRIX NetScaler ADC and NetScaler Gateway were publicly disclosed as affected by CVE-2026-88771 on 27 September 2026, described as a log-injection based, unauthenticated remote code execution flaw. SOCRadar’s researchers uncovered an autonomous operation, branded NetScaler C2, which mass-scans internet-exposed NetScaler instances, fingerprints their versions, and exploits CVE-2026-88771 to deploy a lightweight polling agent that communicates with a command-and-control (C2) server.

The exploit chain begins with an injection into attacker-controlled text logged by unauthenticated HTTP endpoints, processed by the admautoregd daemon, and culminates in root-level command execution. The framework appears to be Chinese-speaking in origin, with references in code comments and UI strings, and evidence suggests AI-assisted development.

The NetScaler C2 toolkit operates as a four-component, modular pipeline: FOFA-based discovery of up to around 120,000 candidate hosts, version fingerprinting to confirm vulnerability, exploitation with multiple HTTP endpoints (including JSON and form submissions) and a DNS out-of-band beacon as a fallback, and a C2 bot that registers, polls every ~20–30 seconds, and returns hex-encoded results.

Concrete indicators include trigger strings such as pitboss NSPPE-00; and logs showing /s/<bid>|sh and ;# unexpectedly died, along with a dropped agent at /tmp/.nsagent. Affected versions align with Citrix advisories: 14.1 before 14.1-73.37, 13.1 before 13.1-64.23, 14.1-FIPS before 14.1-73.37 FIPS, and 13.1-FIPS/NDcPP before 13.1-37.279. UK organisations should isolate vulnerable systems, upgrade to fixed builds, and monitor for the identified IOCs and C2 beaconing patterns.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline