FOUR attacker clusters exploited CVE-2026-88771 in Citrix NetScaler before and after Citrix’s public disclosure, planting web shells and achieving highly privileged access. At least eight eSentire customers were affected across the post-disclosure activity, with rapid progression after the flaw’s September 2026 bulletin.
The campaigns used four distinct approaches: a PHP web shell delivered as a server package; a legitimate fleet tool (Platypus) to gain a shell and data capabilities; backdoor accounts and config theft; and a Python reverse-shell drop. Evidence from eSentire, Mandiant and Google Threat Intelligence Group indicates exploitation began as early as the start of September 2026, intensifying within 24–36 hours of the disclosure and continuing into late September.
Cluster A deployed a PHP web shell masquerading as a .deb package, altering Apache PHP handling and setting the SUID bit on the system shell for root access, then erasing traces from crontab. Cluster B used Platypus to provide command and control and file management capabilities, effectively repurposing a legitimate tool for remote access.
Cluster C introduced a hidden superuser account, archived NetScaler configs and deployed a password‑protected web shell disguised as a CSS file, with indications of AI‑generated code. Cluster D delivered a Python reverse shell that connected back to an attacker server, with each cluster establishing its own command-and-control channel.
Defence guidance emphasises applying fixed builds, auditing for unusual PHP handlers, SUID bits, unknown superuser accounts, and Platypus presence, while treating any web shell as evidence of exposed credentials and configurations.